General Info

File name

BitComet_1.37_x86_setup.exe

Full analysis
https://app.any.run/tasks/53cba275-638e-4008-b081-36d84cce4475
Verdict
Malicious activity
Analysis date
2/10/2019, 18:16:33
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:

loader

Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

d40afcc9632b7351191645bc1e13c150

SHA1

1bf87d0e194901cd0dbaa7f633dc83dc42c5dc3d

SHA256

43bf8dafc7ef5193da42b45c181fddfb7cd650c08fdd38f848ff62e9768b646c

SSDEEP

196608:DgHgcreh2lB8Rms+zoNYTr0c1S+aa7s5xGYJq53/wCTdH/RME:DgHgcrcRF+zoCv0rYs5EYJqx/wCBZR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
120 seconds
Additional time used
60 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads dropped or rewritten executable
  • GoogleUpdate.exe (PID: 4008)
  • bitcomet_toolbar.exe (PID: 2408)
  • BitComet_1.37_x86_setup.exe (PID: 2460)
Application was dropped or rewritten from another process
  • GoogleUpdate.exe (PID: 4008)
  • GoogleToolbarStandaloneSetup_latest.exe (PID: 2140)
  • UPNP.exe (PID: 2808)
  • BitCometService.exe (PID: 2492)
  • updater.exe (PID: 2168)
  • BitCometService.exe (PID: 3104)
  • UPNP.exe (PID: 3952)
  • BitComet.exe (PID: 3088)
  • bitcomet_toolbar.exe (PID: 2408)
  • http_Downloader.exe (PID: 3060)
Downloads executable files from the Internet
  • updater.exe (PID: 2168)
  • http_Downloader.exe (PID: 3060)
Changes the autorun value in the registry
  • BitComet_1.37_x86_setup.exe (PID: 2460)
Executable content was dropped or overwritten
  • updater.exe (PID: 2168)
  • GoogleUpdate.exe (PID: 4008)
  • bitcomet_toolbar.exe (PID: 2408)
  • GoogleToolbarStandaloneSetup_latest.exe (PID: 2140)
  • http_Downloader.exe (PID: 3060)
  • BitComet_1.37_x86_setup.exe (PID: 2460)
Reads Internet Cache Settings
  • BitComet.exe (PID: 3088)
Reads internet explorer settings
  • BitComet.exe (PID: 3088)
Connects to unusual port
  • BitComet.exe (PID: 3088)
Creates files in the program directory
  • GoogleUpdate.exe (PID: 4008)
  • GoogleToolbarStandaloneSetup_latest.exe (PID: 2140)
  • BitComet_1.37_x86_setup.exe (PID: 2460)
Modifies the open verb of a shell class
  • BitComet.exe (PID: 3088)
  • BitComet_1.37_x86_setup.exe (PID: 2460)
Creates a software uninstall entry
  • BitComet_1.37_x86_setup.exe (PID: 2460)
Creates files in the user directory
  • BitComet.exe (PID: 3088)
  • BitComet_1.37_x86_setup.exe (PID: 2460)
Creates files in the Windows directory
  • bitcomet_toolbar.exe (PID: 2408)
Creates or modifies windows services
  • BitCometService.exe (PID: 3104)
Creates COM task schedule object
  • BitComet_1.37_x86_setup.exe (PID: 2460)
Dropped object may contain Bitcoin addresses
  • BitComet_1.37_x86_setup.exe (PID: 2460)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable MS Visual C++ (generic) (42.2%)
.exe
|   Win64 Executable (generic) (37.3%)
.dll
|   Win32 Dynamic Link Library (generic) (8.8%)
.exe
|   Win32 Executable (generic) (6%)
.exe
|   Generic Win/DOS Executable (2.7%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2012:02:24 20:19:59+01:00
PEType:
PE32
LinkerVersion:
10
CodeSize:
28672
InitializedDataSize:
54272
UninitializedDataSize:
16896
EntryPoint:
0x39e3
OSVersion:
5
ImageVersion:
6
SubsystemVersion:
5
Subsystem:
Windows GUI
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
24-Feb-2012 19:19:59
Detected languages
English - United States
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x000000D0
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
6
Time date stamp:
24-Feb-2012 19:19:59
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x00006F10 0x00007000 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.49788
.rdata 0x00008000 0x00002A92 0x00002C00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 4.39389
.data 0x0000B000 0x00067EBC 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 1.47278
.ndata 0x00073000 0x000F1000 0x00000000 IMAGE_SCN_CNT_UNINITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.rsrc 0x00164000 0x00009490 0x00009600 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 4.86699
.reloc 0x0016E000 0x00000F8A 0x00001000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_DISCARDABLE,IMAGE_SCN_MEM_READ 4.56931
Resources
1

2

3

4

5

6

7

8

102

103

104

105

106

107

110

111

202

203

204

205

206

207

211

302

303

304

305

306

307

311

402

403

404

405

406

407

411

502

503

504

505

506

507

511

Imports
    KERNEL32.dll

    USER32.dll

    GDI32.dll

    SHELL32.dll

    ADVAPI32.dll

    COMCTL32.dll

    ole32.dll

    VERSION.dll

Exports

    No exports.

Screenshots

Processes

Total processes
46
Monitored processes
12
Malicious processes
4
Suspicious processes
3

Behavior graph

+
drop and start drop and start drop and start start download and start drop and start drop and start bitcomet_1.37_x86_setup.exe no specs bitcomet_1.37_x86_setup.exe http_downloader.exe bitcomet_toolbar.exe bitcometservice.exe googletoolbarstandalonesetup_latest.exe googleupdate.exe bitcomet.exe bitcometservice.exe upnp.exe no specs upnp.exe no specs updater.exe
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3368
CMD
"C:\Users\admin\AppData\Local\Temp\BitComet_1.37_x86_setup.exe"
Path
C:\Users\admin\AppData\Local\Temp\BitComet_1.37_x86_setup.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
Description
Version
Modules
Image

PID
2460
CMD
"C:\Users\admin\AppData\Local\Temp\BitComet_1.37_x86_setup.exe"
Path
C:\Users\admin\AppData\Local\Temp\BitComet_1.37_x86_setup.exe
Indicators
Parent process
––
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\bitcomet_1.37_x86_setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll
c:\users\admin\appdata\local\temp\nsk809c.tmp\langdll.dll
c:\windows\system32\uxtheme.dll
c:\users\admin\appdata\local\temp\nsk809c.tmp\system.dll
c:\users\admin\appdata\local\temp\nsk809c.tmp\bcnsishelper.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\winspool.drv
c:\windows\system32\oledlg.dll
c:\windows\system32\userenv.dll
c:\windows\system32\riched20.dll
c:\users\admin\appdata\local\temp\nsk809c.tmp\installoptions.dll
c:\users\admin\appdata\local\temp\nsk809c.tmp\gtapi.dll
c:\users\admin\appdata\local\temp\nsk809c.tmp\gcapi.dll
c:\windows\system32\winmm.dll
c:\users\admin\appdata\local\temp\nsk809c.tmp\installoptionsex.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\asycfilt.dll
c:\windows\system32\sspicli.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\users\admin\appdata\local\temp\nsk809c.tmp\http_downloader.exe
c:\program files\bitcomet\tools\bitcometagent_1.5.4.11.dll
c:\windows\system32\firewallapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\program files\bitcomet\tools\bitcometservice.exe
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\program files\bitcomet\bitcomet.exe
c:\users\admin\appdata\local\temp\nsk809c.tmp\nsisunz.dll
c:\program files\bitcomet\tools\bitcometbho_1.5.4.11.dll
c:\windows\system32\netutils.dll

PID
3060
CMD
"C:\Users\admin\AppData\Local\Temp\nsk809C.tmp\http_Downloader.exe" /googletoolbar
Path
C:\Users\admin\AppData\Local\Temp\nsk809C.tmp\http_Downloader.exe
Indicators
Parent process
BitComet_1.37_x86_setup.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\nsk809c.tmp\http_downloader.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\version.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\propsys.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll
c:\users\admin\appdata\local\temp\bitcomet_toolbar.exe

PID
2408
CMD
"C:\Users\admin\AppData\Local\Temp\bitcomet_toolbar.exe" /r:SHA /h:set /d:set
Path
C:\Users\admin\AppData\Local\Temp\bitcomet_toolbar.exe
Indicators
Parent process
http_Downloader.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Google Inc.
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\bitcomet_toolbar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll
c:\users\admin\appdata\local\temp\nsje1e6.tmp\system.dll
c:\users\admin\appdata\local\temp\googletoolbarstandalonesetup_latest.exe

PID
3104
CMD
"C:\Program Files\BitComet\tools\BitCometService.exe" /reg
Path
C:\Program Files\BitComet\tools\BitCometService.exe
Indicators
Parent process
BitComet_1.37_x86_setup.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
www.BitComet.com
Description
BitComet disk boost service
Version
1.25
Modules
Image
c:\program files\bitcomet\tools\bitcometservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winspool.drv
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll

PID
2140
CMD
C:\Users\admin\AppData\Local\Temp\GoogleToolbarStandaloneSetup_latest.exe /install "appguid={F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}&appname=Google%20Toolbar&needsadmin=True&brand=SHAB" /silent /appargs "appguid={F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}&installerdata=gb%26h%3dset%26d%3dset"
Path
C:\Users\admin\AppData\Local\Temp\GoogleToolbarStandaloneSetup_latest.exe
Indicators
Parent process
bitcomet_toolbar.exe
User
admin
Integrity Level
HIGH
Exit code
2147747592
Version:
Company
Google Inc.
Description
Google Update Setup
Version
1.3.21.115
Modules
Image
c:\users\admin\appdata\local\temp\googletoolbarstandalonesetup_latest.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\apphelp.dll
c:\program files\gume271.tmp\googleupdate.exe

PID
4008
CMD
"C:\Program Files\GUME271.tmp\GoogleUpdate.exe" /install "appguid={F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}&appname=Google%20Toolbar&needsadmin=True&brand=SHAB" /silent /appargs "appguid={F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}&installerdata=gb%26h%3dset%26d%3dset"
Path
C:\Program Files\GUME271.tmp\GoogleUpdate.exe
Indicators
Parent process
GoogleToolbarStandaloneSetup_latest.exe
User
admin
Integrity Level
HIGH
Exit code
2147747592
Version:
Company
Google Inc.
Description
Google Installer
Version
1.3.21.103
Modules
Image
c:\windows\system32\sspicli.dll
c:\windows\system32\credssp.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\program files\gume271.tmp\googleupdate.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\program files\gume271.tmp\goopdate.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\msi.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\version.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\program files\gume271.tmp\goopdateres_en.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\propsys.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\psapi.dll

PID
3088
CMD
"C:\Program Files\BitComet\BitComet.exe"
Path
C:\Program Files\BitComet\BitComet.exe
Indicators
Parent process
BitComet_1.37_x86_setup.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
www.BitComet.com
Description
BitComet - a BitTorrent Client
Version
1.37
Modules
Image
c:\program files\bitcomet\bitcomet.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
c:\windows\system32\winspool.drv
c:\windows\system32\comdlg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\profapi.dll
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\uxtheme.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\sxs.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\firewallapi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\program files\bitcomet\tools\upnp.exe
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\mlang.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\inetcomm.dll
c:\windows\system32\msoert2.dll
c:\windows\system32\inetres.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\userenv.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\jscript.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\xmllite.dll
c:\program files\bitcomet\tools\updater.exe

PID
2492
CMD
"C:\Program Files\BitComet\tools\BitCometService.exe" -service
Path
C:\Program Files\BitComet\tools\BitCometService.exe
Indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
www.BitComet.com
Description
BitComet disk boost service
Version
1.25
Modules
Image
c:\program files\bitcomet\tools\bitcometservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winspool.drv
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
3952
CMD
"C:\Program Files\BitComet\tools\UPNP.exe" -addfw -app BitComet -tcpport 22201 -udpport 22201 -q
Path
C:\Program Files\BitComet\tools\UPNP.exe
Indicators
No indicators
Parent process
BitComet.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
www.BitComet.com
Description
UPNP config tool for BitComet
Version
1.0
Modules
Image
c:\program files\bitcomet\tools\upnp.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\winspool.drv
c:\windows\system32\oledlg.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\firewallapi.dll
c:\windows\system32\version.dll
c:\windows\system32\hnetcfg.dll
c:\windows\system32\atl.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\slc.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll

PID
2808
CMD
"C:\Program Files\BitComet\tools\UPNP.exe" -add -app BitComet -lanip 192.168.100.104 -tcpport 22201 -udpport 22201 -q
Path
C:\Program Files\BitComet\tools\UPNP.exe
Indicators
No indicators
Parent process
BitComet.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
www.BitComet.com
Description
UPNP config tool for BitComet
Version
1.0
Modules
Image
c:\program files\bitcomet\tools\upnp.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\winspool.drv
c:\windows\system32\oledlg.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\hnetcfg.dll
c:\windows\system32\atl.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\slc.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\npmproxy.dll
c:\windows\system32\upnp.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\ssdpapi.dll

PID
2168
CMD
"C:\Program Files\BitComet\tools\updater.exe" "C:\Users\admin\AppData\Local\Temp\Bit5C0.tmp"
Path
C:\Program Files\BitComet\tools\updater.exe
Indicators
Parent process
BitComet.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\program files\bitcomet\tools\updater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\version.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll

Registry activity

Total events
1762
Read events
1463
Write events
291
Delete events
8

Modification events

PID
Process
Operation
Key
Name
Value
2460
BitComet_1.37_x86_setup.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar
2460
BitComet_1.37_x86_setup.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Google\GCAPITemp
2460
BitComet_1.37_x86_setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Compatibility Assistant\Persisted
C:\Users\admin\AppData\Local\Temp\BitComet_1.37_x86_setup.exe
1
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar
test
test
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\GCAPITemp
test
te
2460
BitComet_1.37_x86_setup.exe
write
HKEY_CURRENT_USER\Software\BitComet
NeedGoogleToolBar
0
2460
BitComet_1.37_x86_setup.exe
write
HKEY_CURRENT_USER\Software\BitComet
GoogleToolBarInstalled
0
2460
BitComet_1.37_x86_setup.exe
write
HKEY_CURRENT_USER\Software\BitComet
NeedGoogleToolBar
1
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{B99B5DF3-3AD2-463F-8F8C-86787623E1D5}
BitCometAgent
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\BitCometAgent.DLL
AppID
{B99B5DF3-3AD2-463F-8F8C-86787623E1D5}
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BitCometAgent.BcAgent.1
BitComet Agent
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BitCometAgent.BcAgent.1\CLSID
{C8FF2A06-638A-4913-8403-50294CFF6608}
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BitCometAgent.BcAgent
BitComet Agent
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BitCometAgent.BcAgent\CLSID
{C8FF2A06-638A-4913-8403-50294CFF6608}
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BitCometAgent.BcAgent\CurVer
BitCometAgent.BcAgent.1
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C8FF2A06-638A-4913-8403-50294CFF6608}
BitComet Agent
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C8FF2A06-638A-4913-8403-50294CFF6608}\ProgID
BitCometAgent.BcAgent.1
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C8FF2A06-638A-4913-8403-50294CFF6608}\VersionIndependentProgID
BitCometAgent.BcAgent
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C8FF2A06-638A-4913-8403-50294CFF6608}\InprocServer32
C:\Program Files\BitComet\tools\BitCometAgent_1.5.4.11.dll
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C8FF2A06-638A-4913-8403-50294CFF6608}\InprocServer32
ThreadingModel
Apartment
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C8FF2A06-638A-4913-8403-50294CFF6608}
AppID
{B99B5DF3-3AD2-463F-8F8C-86787623E1D5}
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C8FF2A06-638A-4913-8403-50294CFF6608}\TypeLib
{2D2C1FBD-624D-4789-9AE0-F4B66F9EE6E2}
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{2D2C1FBD-624D-4789-9AE0-F4B66F9EE6E2}\1.0
BitCometAgent 1.0 ÀàÐÍ¿â
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{2D2C1FBD-624D-4789-9AE0-F4B66F9EE6E2}\1.0\FLAGS
0
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{2D2C1FBD-624D-4789-9AE0-F4B66F9EE6E2}\1.0\0\win32
C:\Program Files\BitComet\tools\BitCometAgent_1.5.4.11.dll
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{2D2C1FBD-624D-4789-9AE0-F4B66F9EE6E2}\1.0\HELPDIR
C:\Program Files\BitComet\tools
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E8A058D1-C830-437F-A029-10D777A8DD40}
IBcAgent
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E8A058D1-C830-437F-A029-10D777A8DD40}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E8A058D1-C830-437F-A029-10D777A8DD40}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E8A058D1-C830-437F-A029-10D777A8DD40}\TypeLib
{2D2C1FBD-624D-4789-9AE0-F4B66F9EE6E2}
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E8A058D1-C830-437F-A029-10D777A8DD40}\TypeLib
Version
1.0
2460
BitComet_1.37_x86_setup.exe
write
HKEY_CURRENT_USER\Software\BitComet
C:\Program Files\BitComet
2460
BitComet_1.37_x86_setup.exe
write
HKEY_CURRENT_USER\Software\BitComet
InstallSettingCaptureIEDownload
0
2460
BitComet_1.37_x86_setup.exe
write
HKEY_CURRENT_USER\Software\BitComet\BitComet
CaptureIEDownload
0
2460
BitComet_1.37_x86_setup.exe
write
HKEY_CURRENT_USER\Software\BitComet
Install Date
20190210
2460
BitComet_1.37_x86_setup.exe
write
HKEY_CURRENT_USER\Software\BitComet
NewInstall
1
2460
BitComet_1.37_x86_setup.exe
write
HKEY_CURRENT_USER\Software\BitComet
PackageName
BitComet_1.37_x86_setup.exe
2460
BitComet_1.37_x86_setup.exe
write
HKEY_CLASSES_ROOT\.torrent
bittorrent
2460
BitComet_1.37_x86_setup.exe
write
HKEY_CLASSES_ROOT\bittorrent
BitComet File
2460
BitComet_1.37_x86_setup.exe
write
HKEY_CLASSES_ROOT\bittorrent\shell\open\command
"C:\Program Files\BitComet\BitComet.exe"
2460
BitComet_1.37_x86_setup.exe
write
HKEY_CLASSES_ROOT\bittorrent\shell\open\ddeexec
[open("%1")]
2460
BitComet_1.37_x86_setup.exe
write
HKEY_CLASSES_ROOT\bittorrent\shell\open\ddeexec\Application
BitComet
2460
BitComet_1.37_x86_setup.exe
write
HKEY_CLASSES_ROOT\bittorrent\shell\open\ddeexec\Topic
TORRENT
2460
BitComet_1.37_x86_setup.exe
write
HKEY_CLASSES_ROOT\bittorrent\DefaultIcon
"C:\Program Files\BitComet\BitComet.exe",1
2460
BitComet_1.37_x86_setup.exe
write
HKEY_CLASSES_ROOT\.torrent
Content Type
application/x-bittorrent
2460
BitComet_1.37_x86_setup.exe
write
HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-bittorrent
Extension
.torrent
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\bc
URL: BitComet Transfer Protocol
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\bc
URL Protocol
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\bc\DefaultIcon
"C:\Program Files\BitComet\BitComet.exe",1
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\bc\shell\open\command
"C:\Program Files\BitComet\BitComet.exe" /url "%1"
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\magnet
URL: MAGNET-URI Protocol
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\magnet
Content Type
application/x-magnet
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\magnet
URL Protocol
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\magnet\DefaultIcon
"C:\Program Files\BitComet\BitComet.exe",1
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\magnet\shell\open\command
"C:\Program Files\BitComet\BitComet.exe" /url "%1"
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\Low Rights\DragDrop\{59CABE4F-3BB1-43bf-8AF1-D08E4C6F1660}
Policy
3
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\Low Rights\DragDrop\{59CABE4F-3BB1-43bf-8AF1-D08E4C6F1660}
AppName
BitComet.exe
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\Low Rights\DragDrop\{59CABE4F-3BB1-43bf-8AF1-D08E4C6F1660}
AppPath
C:\Program Files\BitComet
2460
BitComet_1.37_x86_setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2460
BitComet_1.37_x86_setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2460
BitComet_1.37_x86_setup.exe
write
HKEY_CURRENT_USER\Software\BitComet
DesktopShortcut
BitComet
2460
BitComet_1.37_x86_setup.exe
write
HKEY_CURRENT_USER\Software\BitComet
InstallSettingCaptureIEDownload
1
2460
BitComet_1.37_x86_setup.exe
write
HKEY_CURRENT_USER\Software\BitComet\BitComet
CaptureIEDownload
1
2460
BitComet_1.37_x86_setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer
DownloadUI
{A8DC7D60-AD8F-491E-9A84-8FF901E7556E}
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer
DownloadUI
{A8DC7D60-AD8F-491E-9A84-8FF901E7556E}
2460
BitComet_1.37_x86_setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Download link using &BitComet
res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
2460
BitComet_1.37_x86_setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Download link using &BitComet
contexts
34
2460
BitComet_1.37_x86_setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Download link using &BitComet
BitCometCreated
1
2460
BitComet_1.37_x86_setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Download all links using BitComet
res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
2460
BitComet_1.37_x86_setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Download all links using BitComet
contexts
243
2460
BitComet_1.37_x86_setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Download all links using BitComet
BitCometCreated
1
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{00980C9D-751F-4A5F-B6CE-6D81998264FD}
BitCometBHO
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\BitCometBHO.DLL
AppID
{00980C9D-751F-4A5F-B6CE-6D81998264FD}
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BitCometBHO.CIEClickCapture.1
BitComet Helper
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BitCometBHO.CIEClickCapture.1\CLSID
{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BitCometBHO.CIEClickCapture
BitComet Helper
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BitCometBHO.CIEClickCapture\CLSID
{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BitCometBHO.CIEClickCapture\CurVer
BitCometBHO.CIEClickCapture.1
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}
BitComet Helper
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}\ProgID
BitCometBHO.CIEClickCapture.1
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}\VersionIndependentProgID
BitCometBHO.CIEClickCapture
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}\InprocServer32
C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}\InprocServer32
ThreadingModel
Apartment
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}
AppID
{00980C9D-751F-4A5F-B6CE-6D81998264FD}
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}\TypeLib
{66A8414F-F2E4-4766-BE09-8F72CDDACED4}
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}
BitComet ClickCapture
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BitCometBHO.DownloadManager.1
DownloadManager Class
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BitCometBHO.DownloadManager.1\CLSID
{A8DC7D60-AD8F-491E-9A84-8FF901E7556E}
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BitCometBHO.DownloadManager
DownloadManager Class
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BitCometBHO.DownloadManager\CLSID
{A8DC7D60-AD8F-491E-9A84-8FF901E7556E}
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BitCometBHO.DownloadManager\CurVer
BitCometBHO.DownloadManager.1
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8DC7D60-AD8F-491E-9A84-8FF901E7556E}
DownloadManager Class
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8DC7D60-AD8F-491E-9A84-8FF901E7556E}\ProgID
BitCometBHO.DownloadManager.1
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8DC7D60-AD8F-491E-9A84-8FF901E7556E}\VersionIndependentProgID
BitCometBHO.DownloadManager
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8DC7D60-AD8F-491E-9A84-8FF901E7556E}\InprocServer32
C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8DC7D60-AD8F-491E-9A84-8FF901E7556E}\InprocServer32
ThreadingModel
Apartment
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8DC7D60-AD8F-491E-9A84-8FF901E7556E}
AppID
{00980C9D-751F-4A5F-B6CE-6D81998264FD}
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A8DC7D60-AD8F-491E-9A84-8FF901E7556E}\TypeLib
{66A8414F-F2E4-4766-BE09-8F72CDDACED4}
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{66A8414F-F2E4-4766-BE09-8F72CDDACED4}\1.0
BitCometBHO 1.0 ÀàÐÍ¿â
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{66A8414F-F2E4-4766-BE09-8F72CDDACED4}\1.0\FLAGS
0
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{66A8414F-F2E4-4766-BE09-8F72CDDACED4}\1.0\0\win32
C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{66A8414F-F2E4-4766-BE09-8F72CDDACED4}\1.0\HELPDIR
C:\Program Files\BitComet\tools
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F08F65A5-7F91-45D7-A119-12AC4AB3D229}
IIEClickCapture
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F08F65A5-7F91-45D7-A119-12AC4AB3D229}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F08F65A5-7F91-45D7-A119-12AC4AB3D229}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F08F65A5-7F91-45D7-A119-12AC4AB3D229}\TypeLib
{66A8414F-F2E4-4766-BE09-8F72CDDACED4}
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F08F65A5-7F91-45D7-A119-12AC4AB3D229}\TypeLib
Version
1.0
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6CFA2528-2725-491D-8E0D-E67AB5C5A17A}
IDownloadManager_Place
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6CFA2528-2725-491D-8E0D-E67AB5C5A17A}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6CFA2528-2725-491D-8E0D-E67AB5C5A17A}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6CFA2528-2725-491D-8E0D-E67AB5C5A17A}\TypeLib
{66A8414F-F2E4-4766-BE09-8F72CDDACED4}
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6CFA2528-2725-491D-8E0D-E67AB5C5A17A}\TypeLib
Version
1.0
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A}
Default Visible
YES
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A}
ButtonText
BitComet
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A}
HotIcon
C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll,203
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A}
Icon
C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll,203
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A}
CLSID
{1FBA04EE-3024-11D2-8F1F-0000F87ABD16}
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A}
Script
res://C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll/206
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\BitComet.exe
C:\Program Files\BitComet\BitComet.exe
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BitComet
DisplayName
BitComet 1.37
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BitComet
UninstallString
C:\Program Files\BitComet\uninst.exe
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BitComet
DisplayIcon
C:\Program Files\BitComet\BitComet.exe
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BitComet
DisplayVersion
1.37
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BitComet
VersionMajor
1
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BitComet
VersionMinor
37
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BitComet
InstallLocation
C:\Program Files\BitComet
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BitComet
NSIS:StartMenuDir
BitComet
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BitComet
URLInfoAbout
http://www.bitcomet.com/
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BitComet
Publisher
CometNetwork
2460
BitComet_1.37_x86_setup.exe
write
HKEY_CURRENT_USER\Software\BitComet
Installer Language
1033
2460
BitComet_1.37_x86_setup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
BitComet
C:\Program Files\BitComet\BitComet.exe /tray
2460
BitComet_1.37_x86_setup.exe
write
HKEY_CURRENT_USER\Software\BitComet
InstallSettingAutoRun
1
2460
BitComet_1.37_x86_setup.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager
PendingFileRenameOperations
\??\C:\Users\admin\AppData\Local\Temp\nsk809C.tmp\BcNsisHelper.dll
3060
http_Downloader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\http_Downloader_RASAPI32
EnableFileTracing
0
3060
http_Downloader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\http_Downloader_RASAPI32
EnableConsoleTracing
0
3060
http_Downloader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\http_Downloader_RASAPI32
FileTracingMask
4294901760
3060
http_Downloader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\http_Downloader_RASAPI32
ConsoleTracingMask
4294901760
3060
http_Downloader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\http_Downloader_RASAPI32
MaxFileSize
1048576
3060
http_Downloader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\http_Downloader_RASAPI32
FileDirectory
%windir%\tracing
3060
http_Downloader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\http_Downloader_RASMANCS
EnableFileTracing
0
3060
http_Downloader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\http_Downloader_RASMANCS
EnableConsoleTracing
0
3060
http_Downloader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\http_Downloader_RASMANCS
FileTracingMask
4294901760
3060
http_Downloader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\http_Downloader_RASMANCS
ConsoleTracingMask
4294901760
3060
http_Downloader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\http_Downloader_RASMANCS
MaxFileSize
1048576
3060
http_Downloader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\http_Downloader_RASMANCS
FileDirectory
%windir%\tracing
3060
http_Downloader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3060
http_Downloader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3060
http_Downloader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3060
http_Downloader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3104
BitCometService.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\BITCOMET_HELPER_SERVICE
Description
This service enhances disk IO performance of BitComet.
4008
GoogleUpdate.exe
write
HKEY_CURRENT_USER\Software\Google\Update\proxy
source
direct
3088
BitComet.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Download all links using BitComet
3088
BitComet.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Download link using &BitComet
3088
BitComet.exe
delete key
HKEY_CLASSES_ROOT\bittorrent\shell\open\ddeexec\Application
3088
BitComet.exe
delete key
HKEY_CLASSES_ROOT\bittorrent\shell\open\ddeexec\Topic
3088
BitComet.exe
delete key
HKEY_CLASSES_ROOT\bittorrent\shell\open\ddeexec
3088
BitComet.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3088
BitComet.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3088
BitComet.exe
write
HKEY_CURRENT_USER\Software\BitComet\BitComet
CaptureIEDownload
1
3088
BitComet.exe
write
HKEY_CURRENT_USER\Software\BitComet\BitComet
IEMoniterFileExt
.zip;.rar;.iso;.exe;.asf;.avi;.mp3;.mpg;.rm;.rmvb;.wmv;.wma;.msi
3088
BitComet.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\&D&ownload &with BitComet
res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
3088
BitComet.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\&D&ownload &with BitComet
contexts
34
3088
BitComet.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\&D&ownload &with BitComet
BitCometCreated
1
3088
BitComet.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\&D&ownload &with BitComet
MenuID
ID_DOWNLOAD_LINK
3088
BitComet.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\&D&ownload all with BitComet
res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
3088
BitComet.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\&D&ownload all with BitComet
contexts
243
3088
BitComet.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\&D&ownload all with BitComet
BitCometCreated
1
3088
BitComet.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\&D&ownload all with BitComet
MenuID
ID_DOWNLOAD_ALL_LINK
3088
BitComet.exe
write
HKEY_CURRENT_USER\Software\BitComet\BitComet\IEMenuExt\ID_EXTMENU1
Display
&D&ownload specific using BitComet
3088
BitComet.exe
write
HKEY_CURRENT_USER\Software\BitComet\BitComet\IEMenuExt\ID_EXTMENU1\ID_DOWNLOAD_VIDEO
Display
Download Videos
3088
BitComet.exe
write
HKEY_CURRENT_USER\Software\BitComet\BitComet\IEMenuExt\ID_EXTMENU1\ID_DOWNLOAD_PICTURE
Display
Download Pictures
3088
BitComet.exe
write
HKEY_CURRENT_USER\Software\BitComet\BitComet\IEMenuExt\ID_EXTMENU1\ID_DOWNLOAD_PICTURE_LINK
Display
Download Picture Links
3088
BitComet.exe
write
HKEY_CURRENT_USER\Software\BitComet\BitComet\IEMenuExt\ID_EXTMENU1\ID_DOWNLOAD_FLASH
Display
Download Flash Files
3088
BitComet.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\DragDrop\{59CABE4F-3BB1-43bf-8AF1-D08E4C6F1660}
Policy
3
3088
BitComet.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\DragDrop\{59CABE4F-3BB1-43bf-8AF1-D08E4C6F1660}
AppName
BitComet.exe
3088
BitComet.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Low Rights\DragDrop\{59CABE4F-3BB1-43bf-8AF1-D08E4C6F1660}
AppPath
C:\Program Files\BitComet
3088
BitComet.exe
write
HKEY_CLASSES_ROOT\bc
URL: BitComet Transfer Protocol
3088
BitComet.exe
write
HKEY_CLASSES_ROOT\bc
URL Protocol
3088
BitComet.exe
write
HKEY_CLASSES_ROOT\bc\DefaultIcon
"C:\Program Files\BitComet\BitComet.exe",1
3088
BitComet.exe
write
HKEY_CLASSES_ROOT\bc\shell\open\command
"C:\Program Files\BitComet\BitComet.exe" /url "%1"
3088
BitComet.exe
write
HKEY_CLASSES_ROOT\magnet
URL: Magnet URI
3088
BitComet.exe
write
HKEY_CLASSES_ROOT\magnet
URL Protocol
3088
BitComet.exe
write
HKEY_CLASSES_ROOT\magnet\DefaultIcon
"C:\Program Files\BitComet\BitComet.exe",1
3088
BitComet.exe
write
HKEY_CLASSES_ROOT\magnet\shell\open\command
"C:\Program Files\BitComet\BitComet.exe" /url "%1"
3088
BitComet.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BitComet_RASAPI32
EnableFileTracing
0
3088
BitComet.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BitComet_RASAPI32
EnableConsoleTracing
0
3088
BitComet.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BitComet_RASAPI32
FileTracingMask
4294901760
3088
BitComet.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BitComet_RASAPI32
ConsoleTracingMask
4294901760
3088
BitComet.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BitComet_RASAPI32
MaxFileSize
1048576
3088
BitComet.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BitComet_RASAPI32
FileDirectory
%windir%\tracing
3088
BitComet.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BitComet_RASMANCS
EnableFileTracing
0
3088
BitComet.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BitComet_RASMANCS
EnableConsoleTracing
0
3088
BitComet.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BitComet_RASMANCS
FileTracingMask
4294901760
3088
BitComet.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BitComet_RASMANCS
ConsoleTracingMask
4294901760
3088
BitComet.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BitComet_RASMANCS
MaxFileSize
1048576
3088
BitComet.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\BitComet_RASMANCS
FileDirectory
%windir%\tracing
3088
BitComet.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3088
BitComet.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
460000006A000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3088
BitComet.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
3088
BitComet.exe
write
HKEY_CLASSES_ROOT\.bc!
BitCometUnfinishedFile
3088
BitComet.exe
write
HKEY_CLASSES_ROOT\.torrent
Content Type
application/x-bittorrent
3088
BitComet.exe
write
HKEY_CLASSES_ROOT\bittorrent
OldDefault
BitComet File
3088
BitComet.exe
write
HKEY_CLASSES_ROOT\bittorrent\shell\open\command
OldDefault
"C:\Program Files\BitComet\BitComet.exe"
3088
BitComet.exe
write
HKEY_CLASSES_ROOT\bittorrent\DefaultIcon
OldDefault
"C:\Program Files\BitComet\BitComet.exe",1
3088
BitComet.exe
write
HKEY_CLASSES_ROOT\bittorrent
BitComet File
3088
BitComet.exe
write
HKEY_CLASSES_ROOT\bittorrent\shell\open\command
"C:\Program Files\BitComet\BitComet.exe"
3088
BitComet.exe
write
HKEY_CLASSES_ROOT\bittorrent\shell\open\ddeexec
[open("%1")]
3088
BitComet.exe
write
HKEY_CLASSES_ROOT\bittorrent\shell\open\ddeexec\Application
BitComet
3088
BitComet.exe
write
HKEY_CLASSES_ROOT\bittorrent\shell\open\ddeexec\Topic
TORRENT
3088
BitComet.exe
write
HKEY_CLASSES_ROOT\bittorrent\DefaultIcon
"C:\Program Files\BitComet\BitComet.exe",1
3088
BitComet.exe
write
HKEY_CLASSES_ROOT\BitCometUnfinishedFile
BitComet Unfinished Download File
3088
BitComet.exe
write
HKEY_CLASSES_ROOT\BitCometUnfinishedFile\shell\open\command
"C:\Program Files\BitComet\BitComet.exe"
3088
BitComet.exe
write
HKEY_CLASSES_ROOT\BitCometUnfinishedFile\shell\open\ddeexec
[openunfinish("%1")]
3088
BitComet.exe
write
HKEY_CLASSES_ROOT\BitCometUnfinishedFile\shell\open\ddeexec\Application
BitComet
3088
BitComet.exe
write
HKEY_CLASSES_ROOT\BitCometUnfinishedFile\shell\open\ddeexec\Topic
TORRENT
3088
BitComet.exe
write
HKEY_CLASSES_ROOT\MIME\Database\Content Type\application/x-bittorrent
Extension
.torrent
2168
updater.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\updater_RASAPI32
EnableFileTracing
0
2168
updater.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\updater_RASAPI32
EnableConsoleTracing
0
2168
updater.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\updater_RASAPI32
FileTracingMask
4294901760
2168
updater.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\updater_RASAPI32
ConsoleTracingMask
4294901760
2168
updater.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\updater_RASAPI32
MaxFileSize
1048576
2168
updater.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\updater_RASAPI32
FileDirectory
%windir%\tracing
2168
updater.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\updater_RASMANCS
EnableFileTracing
0
2168
updater.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\updater_RASMANCS
EnableConsoleTracing
0
2168
updater.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\updater_RASMANCS
FileTracingMask
4294901760
2168
updater.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\updater_RASMANCS
ConsoleTracingMask
4294901760
2168
updater.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\updater_RASMANCS
MaxFileSize
1048576
2168
updater.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\updater_RASMANCS
FileDirectory
%windir%\tracing
2168
updater.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2168
updater.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
460000006B000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2168
updater.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2168
updater.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1

Files activity

Executable files
95
Suspicious files
5
Text files
124
Unknown types
71

Dropped files

PID
Process
Filename
Type
2168
updater.exe
C:\Users\admin\AppData\Local\Temp\Bit1F1C.tmp.exe
executable
MD5: 42594e873b92737c9a8fceeff1617caa
SHA256: 619535c9d1f442111ddc8c311a5a1ca6df88f60a33fa6783ddde1e203e619c8b
2408
bitcomet_toolbar.exe
C:\Users\admin\AppData\Local\Temp\GoogleToolbarStandaloneSetup_latest.exe
executable
MD5: 1a33d577db4778ac22dbcecee57a2be7
SHA256: 218d95adaecbcdfd4faf5e1ef9d9dcfcbf2d83bcdf7d65fb1cd51c138edeae8b
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_el.dll
executable
MD5: 9230858a71fdf08033b16dee3da4a789
SHA256: 46a04d7af1976b1ab155ac34ae6a38f6d6afb47579c18af461ef4e38575ecd6f
2408
bitcomet_toolbar.exe
C:\Users\admin\AppData\Local\Temp\nsjE1E6.tmp\System.dll
executable
MD5: 301a9c8739ed3ed955a1bdc472d26f32
SHA256: 6ec9fde89f067b1807325b05089c3ae4822ce7640d78e6f32dbe52f582de1d92
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_de.dll
executable
MD5: c6315939d2ffd96df4d01ca752c53334
SHA256: 90c26e5b185578441ba1402dabbbbe20865b5269c16964b0cde9395fdb85ee52
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\chrome\content\BitCometLauncher.exe
executable
MD5: 0027e42c9c4124177641310403022ced
SHA256: deb21b68493fdce5d45019a0d5ab28d968392211244a918b8dae7e0dde491c0b
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_fi.dll
executable
MD5: a12437067d484ef3bdacae444e75d823
SHA256: 6d91680fcc997bcbd2b51cff959de77e587d3ca1fba36c8b94e300166242f589
2168
updater.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\bitcomet_setup[1].exe
executable
MD5: 42594e873b92737c9a8fceeff1617caa
SHA256: 619535c9d1f442111ddc8c311a5a1ca6df88f60a33fa6783ddde1e203e619c8b
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_da.dll
executable
MD5: b1d8fd2fcab8698b87ae0dbfa4787470
SHA256: 1b9eba0a4ef448ff3a612437cd2249c5d67a641d4256b60a6bd5f376e04a5645
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Local\Temp\nsk809C.tmp\nsisunz.dll
executable
MD5: bd97d86d8bd07ebdc8ec662a3f31dfd5
SHA256: c31b590cba443de87f0f4a81712f0883ac3b506f3868759d918d9a81f84ea922
4008
GoogleUpdate.exe
C:\Program Files\Google\Update\Offline\{4948BE44-D6FF-4AAD-9D54-1E7E9D9A3838}\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}\GoogleToolbarInstaller_full_signed.exe
executable
MD5: 2040b57c08f7a97e4e44acb324647cf2
SHA256: 7eca48ad6b5fecd9487297ec1aab52e7a8eb191721de758bf6379de12bf82ce2
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_fil.dll
executable
MD5: cbee2af6888ad00411cb819796b4eb86
SHA256: d7239f8e6aa8541e2d7d8f970d4fd42eb52a4377709286b2c445416a82e46664
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_lv.dll
executable
MD5: adb8db7ccd51f8fee2b4431dce0f8f90
SHA256: 41c1dae2967b2716e0f39516cc1b26c4d6ee0134ee99af967baa9889eaf43fbc
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\tools\BitCometService.exe
executable
MD5: f0879e255885374d4c4c65a2d64bed60
SHA256: a78eff9887bedf48b30a36d7db90e3a16d9925a198ac938a2a69373c828f4654
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\uninst.exe
executable
MD5: 13d953e0e5e2dfe0ab8987686e7c9f87
SHA256: 931d8d1d88eb25bc5737786b6bcfbb907bae5326e1c8b615a9d9f45dc524a3db
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_bn.dll
executable
MD5: 4ee79f5e2411169cfcb1081a8acf43da
SHA256: 35c877127487a0433b09aa2742b306ea670fb9defbf669e91b1c56ca9d58f3e1
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_id.dll
executable
MD5: c6ae667ef2f2317f5c46f792e9dcf7d7
SHA256: 981afaaf41fdf38ac2ec9fd56f8f6020a2c4820f83706b391683761b73295dd0
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Local\Temp\nsk809C.tmp\BitCometService.exe
executable
MD5: f0879e255885374d4c4c65a2d64bed60
SHA256: a78eff9887bedf48b30a36d7db90e3a16d9925a198ac938a2a69373c828f4654
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\GoogleUpdate.exe
executable
MD5: 506708142bc63daba64f2d3ad1dcd5bf
SHA256: 9c36a08d9e7932ff4da7b5f24e6b42c92f28685b8abe964c870e8d7670fd531a
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_cs.dll
executable
MD5: b955bfccccb1907903429782840c0dd9
SHA256: 35f0ce72abe2a7f9398fa80eef64db55d8e224b97757ab423fc038030b8aa2fb
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_th.dll
executable
MD5: b3e7ed0bda2a3fd0541a7d75c9dbed3a
SHA256: ea99896afe0db984337dcf323148bb4b3d57b96f29f58ba784a09bd1638fe278
3060
http_Downloader.exe
C:\Users\admin\AppData\Local\Temp\bitcomet_toolbar.exe
executable
MD5: 5c8a817aeaf6650530395c6d6e64f364
SHA256: fb73289d0032f5720e7ced972f87e5842f4f331cbc74e0b67af9a5ae389a4803
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\GoogleCrashHandler.exe
executable
MD5: 93f29e6964baef31e53d203992b0afd4
SHA256: 381529961944941060f7a60388df67da47f7ad7c633bf8dd652e95aa805a9a90
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_en.dll
executable
MD5: 85f0ccd6e2c2694793adf04b6b6658aa
SHA256: 470718c1392df70f2c24b8faa44ec9c72316edd0fdee082ed7d236a5529b749b
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_ru.dll
executable
MD5: 58ef3a13b607eb641cad7713073df8b6
SHA256: d5b31bec3651e0d3a510c27aac06bef826f9e5d9c8945dc7debaf6be670da3a5
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll
executable
MD5: 7455fe2a83979f90705062160f98a96d
SHA256: 04cf2cbb23da8fec93d9d021b4ed3168afadb4be9f47fb7e4d209a2c41dbaca5
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\GoogleUpdateHelper.msi
executable
MD5: 695d904cada5060eeeb0f12a496e7280
SHA256: d7bb1d1b8d5762e3c3edee479ffd3aa1962c87f9cfadd57ba34eca92cb6681bc
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_es-419.dll
executable
MD5: 12d2c7ce32f234da5ee401c026f24a78
SHA256: 7ef40f1ec0807c1852b5cb2151c2fe8358e7dce8134e4059828e25b9d7735843
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_pl.dll
executable
MD5: 490e914996a59e35f064975609774952
SHA256: b9d001cbe7fd81be00f3421d03185cad15b1465b59eed10cd809fad6af480007
3060
http_Downloader.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\bitcomet_toolbar[1].exe
executable
MD5: 5c8a817aeaf6650530395c6d6e64f364
SHA256: fb73289d0032f5720e7ced972f87e5842f4f331cbc74e0b67af9a5ae389a4803
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\GoogleUpdateBroker.exe
executable
MD5: 2b01ca236d4876d698fee59b91227649
SHA256: 526fbabfba04206f1dd072597b0a5fca9db6bf68e9318f5ce9a3ba976fe7edd3
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_fr.dll
executable
MD5: 7a0f1f9a1a115a72137df814f562c8e8
SHA256: 7f1b3337d333addcf2715f2de05f7db1daa3b50eb89863e7b729e674cd8011c0
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_sk.dll
executable
MD5: c3c3207663f86d43e0ac73c0e3deac1e
SHA256: 74228d2e72eeddb8f8f37a4a30e628ea4f8785da1e417f69e582883ed49ba65c
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\tools\BitCometAgent_1.5.4.11.dll
executable
MD5: 0654861d1e963724f7476976eb77c4ad
SHA256: dd0181229f9b8ef91553a30528f5cfde26cacfc71f9795d1e1d6357faf517d43
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\GoogleToolbarInstaller_full_signed.exe.{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}
executable
MD5: 2040b57c08f7a97e4e44acb324647cf2
SHA256: 7eca48ad6b5fecd9487297ec1aab52e7a8eb191721de758bf6379de12bf82ce2
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_ca.dll
executable
MD5: d696ee3ead4dc407c23e2662eab6247d
SHA256: 5d7fca5186ac36ecf15dbdef2cc4770bfbc3b38f2dde9a0ff2ca6a93219c3dca
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_is.dll
executable
MD5: cbf8541d6c59a059cfbecde2a7552859
SHA256: 87c1e341470e0fa2608134f11ea9579a975f2c192384868c8de7b975679a8dc2
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\tools\Updater.exe
executable
MD5: 310b233e73b198fcc41e462be8973aa5
SHA256: d4cbcafd79dbe0cd9467c59b17f4790f2d877c7eff5356711b47b45f76a1d7b9
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_zh-CN.dll
executable
MD5: f174e2ddf95355ebba798bfec7f3ebe0
SHA256: cf44e58afee2cb9310d46af00f3c74c70ee2803b52d00893dafe968b14c16967
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_en-GB.dll
executable
MD5: a1e716fb1d1b04901b8ae85c05f4881b
SHA256: ebb115776ff95b16778f078a722529ce8d914a54b76f0cc7efb54951ceb6270e
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_sl.dll
executable
MD5: 2e99d30504fbc9b880d197684666d75e
SHA256: dcdd30dd95cd9ba0b9d9bcccd653120bee14c2d1f1c4c0d54d07cd61356cf84a
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\tools\VideoSnapshot.exe
executable
MD5: a488135474e53e72115a0bb25e664aad
SHA256: 5d4c38a4dfb74525b0228314572daa3ae11a4639f46170514f3faa245c077bad
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\GoogleUpdateSetup.exe
executable
MD5: 1a33d577db4778ac22dbcecee57a2be7
SHA256: 218d95adaecbcdfd4faf5e1ef9d9dcfcbf2d83bcdf7d65fb1cd51c138edeae8b
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_es.dll
executable
MD5: 1651b9cc2603f2bdebb5bbc9af1d719b
SHA256: 3bac3aa3be7f35047a0ef53d2ab77a73f9af4368c325adcb474abe2ca779c6d4
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_it.dll
executable
MD5: d1ec0aa03e312e74afa83ad3803be3c1
SHA256: 6950d132f8ceed3b9215ea0b3ee6b38845fe7024c8ca671c923ca53f0bf0fef1
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\tools\UPNP.exe
executable
MD5: 83af1d82523a47b01adddba38aaba9a3
SHA256: d0899008ab17158d82ead643d788a827740f82cfe8da3a7cce5875b6d74a4649
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_vi.dll
executable
MD5: 5d50f54bb6562204d703dce8920e2aad
SHA256: 493ee1d85cd2b8afbc2178f4aafc2ae3d397da657aaef5def92ddb426f1b35bd
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_fa.dll
executable
MD5: 718f45bb7b7edd5dbd8a0157e5f3d9ca
SHA256: 56f6494d7950f7008593bd894984b61f395eade34579a8a80a7a5eb65fd47876
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_ja.dll
executable
MD5: 2748c564bbc57ce7dcea2f62f04af337
SHA256: 9c22c297b201f87d20c89887113bfeff2f762c9e17688e0ffd8c015aae5ae843
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\CrashReport.exe
executable
MD5: 69ee41e1ea0f60087dfa4979f51704ab
SHA256: 145314b6338049623fb1d0b95242a310fff3f077f466617d7cc900c937c4d231
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_ur.dll
executable
MD5: 5daf39f6d4e282b2bce2e97b7c08403b
SHA256: 2873e51abb01c9cdefe45a1ec1f93368645e44ceb7c9055cf36f81ea60d652b3
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_gu.dll
executable
MD5: e00d77465704ca6793c7755d0c92c19f
SHA256: ef3eabd829e7333d2f345a34d0572d34b112bc334749784b1774a08219637194
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_ro.dll
executable
MD5: 41e4f84c8fdc61b1ab3d236030f432a7
SHA256: 7970a8e0ca018aa0b890faa95697a16f1dd2440b91452f12434b9fbb4be8b85c
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\BitComet.exe
executable
MD5: e08c84f1375be660ad9e280d9c15db4b
SHA256: 80c0272773061020329ccf4cdc2f5838cdca0e33d48eb46ccaec1a744dc876c6
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_zh-TW.dll
executable
MD5: 2c044209018c86daece16b435136911e
SHA256: 44507d5db6d932575d90877eb5aa264fd345da55d85bedd00839cd45fb474236
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_am.dll
executable
MD5: 5a4714e0886a0c28f1c885802940551e
SHA256: d582f1adf26466d9b52c54d1927860ee01e4a2881c63868f3b1164cf45f9d4a6
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_ms.dll
executable
MD5: 089fabd1eb8af4f6ed9d5ed5334f1679
SHA256: e5500693509ca8ecfa9c99f8a65c55586bf8456c8e2c979c7026ef6d2b925bbe
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Local\Temp\nsk809C.tmp\InstallOptionsEx.dll
executable
MD5: d4aa8fe6ac59dc4ad0b84ec78cd9c875
SHA256: 35db8bec2889a7f6fb02a85cff0c2c0be775c9daa78e02358b1fe4a5557e37b1
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_pt-PT.dll
executable
MD5: 833145bf430a7f479c38bbf433a24095
SHA256: 4012065a9f55d10a3dec695691cb1a2f3c5c7043832ff00700d89e9b8c571607
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_ar.dll
executable
MD5: eecaf0739ab43afa02058279af5a521c
SHA256: acc17834f968c6ee237933c0899cc644e82be78f540f75f2e8d04b64beba4f4e
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_ml.dll
executable
MD5: c63672563a8f5792c6239ee2a011fc0c
SHA256: ce190aea9d3be002bcc2923f282dbe01ca8a809b2d11c4ad90e726cf51d42e59
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Local\Temp\nsk809C.tmp\InstallOptions.dll
executable
MD5: 89351a0a6a89519c86c5531e20dab9ea
SHA256: f530069ef87a1c163c4fd63a3d5b053420ce3d7a98739c70211b4a99f90d6277
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_hi.dll
executable
MD5: 1eac371381e11bf47dce491067193eed
SHA256: fd6ded71a8fbb90b8b91fd1a0c98df48fe26ea4739c41c17cc717bf65d44013c
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdate.dll
executable
MD5: 39c5fcf8aa3b83d79a0e853ecb38bf25
SHA256: a5cef0a709000150323a1a6021ef5d23c6ed96069d2dfff3fb9f5a56509536c4
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_iw.dll
executable
MD5: 81c9028b3302094de3f1e9f1b5b69e0f
SHA256: 438114e34025ea313b4b363c6dff675e3019e90510519366bb68202942dca264
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Local\Temp\nsk809C.tmp\BitComet_stats.exe
executable
MD5: edb96675541d0275c42096b64d794d3b
SHA256: 842df63767cacb7aedb75fb352c1505d518662e2e9dca5a297515ebdae093918
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_kn.dll
executable
MD5: 76baba62c3f4b25e7ddb3f77cc9b19ad
SHA256: 595ba2cd70b3f00c91d1ef7a650cc3eb8af048c5dd662afaa7a5115417439055
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_bg.dll
executable
MD5: 484fa8990270427fd537c2a8a087537a
SHA256: f32737c088a32db047d47ee7099425f390bb25fbef9432c7e32bc02ab4f50362
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_mr.dll
executable
MD5: 5c956f491c8f0d1f694bda0b38f5dc63
SHA256: 43721f31b88d7476df866adc56b0a249ce4502f804d3ce06c41455c78863fe24
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Local\Temp\nsk809C.tmp\System.dll
executable
MD5: bf712f32249029466fa86756f5546950
SHA256: 7851cb12fa4131f1fee5de390d650ef65cac561279f1cfe70ad16cc9780210af
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_hr.dll
executable
MD5: a35c18c43f484626f6b8316e84f328a7
SHA256: f3663f852a8a35024c95979749c0c7faff74b0fcf3fcc9b4d1d3ad849b839190
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\psuser.dll
executable
MD5: fe3d559a981db42d8d7e25a4fd7f7206
SHA256: c86fd177c5dbe3651a3d60546e1efb14628d361c739c13cb753808d4ba421b08
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_sr.dll
executable
MD5: 484601b35ac1d0e17fe0e52cb0eedbc9
SHA256: 9e5b16a37f06c42f47acefe6385e9eee1872007cc36668662e761372f16b608b
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Local\Temp\nsk809C.tmp\http_Downloader.exe
executable
MD5: b57d15325636150eb138da1ac7387524
SHA256: 45ffc3dfc4f922ac5e461b54627f1a6407ae681c545d70dbebdd18095933d886
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_sv.dll
executable
MD5: abb9816b3dd4697fa6103eb111197bbf
SHA256: c20aed5e362beae5026ee1138fa1f213bf27cb8c7227e0e8440dd53a81047adb
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\npGoogleUpdate3.dll
executable
MD5: 8f628060daecf76c537bd89a53228d3b
SHA256: 1a25cfd60a37810d0e9c134ce26281d64cac878fd8e13e19298379de6106cd3d
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_sw.dll
executable
MD5: 60cde2f3dcdd0e9e59cb3615a2718170
SHA256: 156cfcab26795c4eabe378068e2c4bfda916423009a6140334d0da5bb504c679
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Local\Temp\nsk809C.tmp\BcNsisHelper.dll
executable
MD5: c9e088189a17526b377392b4a23d6657
SHA256: b710bcf3973b2dbe9c603b08684c5705a6070964fecb3eb1b98accd37f9870ad
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_uk.dll
executable
MD5: f42fc941756812e76d1425af2d6df84d
SHA256: 3da59df7d36e098e7e538457228eb860e0f3a8459905b9b92cc3f5bd81af11c5
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\GoogleCrashHandler64.exe
executable
MD5: c282f4a84fda6ef4376996542f7a1249
SHA256: 62d19dc2f54044526478c529a5a2af6e51495b6f8eb350b355ce719c798852ce
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_te.dll
executable
MD5: bb7b4c8848ae8b54a196f05fe2f5f54f
SHA256: bd772cfaa428c032e62fda65b19c5bf0f8b51e68296d407a50740d048c816607
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Local\Temp\nsk809C.tmp\gcapi.dll
executable
MD5: d496480a00abde0655c0fdce9530b43e
SHA256: da10e8220d101c5ea98b4872879bd27884328c3794e08cf30492af2c9343005b
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_ta.dll
executable
MD5: 453555bd8daec202cf8b5f24f128309e
SHA256: 03f1767861cc6e48c139f45f0c549df469846d8695fa7c674d8ae25beae9c6db
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\GoogleUpdateOnDemand.exe
executable
MD5: c6efc2044034f25f131dcfbc3115d40a
SHA256: f537739a4e30a2f7261cd75af83cdc849793b1669d04e1a108540abb6b12c62d
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_nl.dll
executable
MD5: 727e351d36d6cf550116d5d096d30347
SHA256: e75ec0481685001482d518eb1d231a833140a90e9f1ca63a08b1bb80349d525b
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Local\Temp\nsk809C.tmp\gtapi.dll
executable
MD5: 23700aa70d1751d592d8641fc0e0660f
SHA256: 45b1a3bb2ae9622fefc1f131e7d4e6d32eb4f761dbbcccfe9e239b49f3b78521
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_pt-BR.dll
executable
MD5: d2227317c84e09a49611f31452c623f4
SHA256: 75cac06a132fb7aba4b616e6e32306d1d28de1a151acc51ce796184089f58d99
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\psmachine.dll
executable
MD5: b8d7fc13ba781104e67923b7a0a5719c
SHA256: d55f0fa56737eef6ae062fe7dca927a7893f4a74ce1d06d2d584f021b2a98aef
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_no.dll
executable
MD5: a11441c5f2497e4a486e2fc66dd7827e
SHA256: 66ee83d28d6a5d3be9eae08fdbe7db315078a2be68ce356bcd6129df063e39e3
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_lt.dll
executable
MD5: 8acc6081f3a0095aeb667489190cb614
SHA256: 3ba4f175efbf6fdb890662eae42961ac9ecfde3cd46690c5d078ba6e59e4373d
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_tr.dll
executable
MD5: 92c56c976962dd5259cc0d286ff8d5e1
SHA256: da8c46dade76d3bf86b331b07b935eb7b36ed3503d6bfdc78a2d5d435e4e503f
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Local\Temp\nsk809C.tmp\LangDLL.dll
executable
MD5: a1cd3f159ef78d9ace162f067b544fd9
SHA256: 47b9e251c9c90f43e3524965aecc07bd53c8e09c5b9f9862b44c306667e2b0b6
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_ko.dll
executable
MD5: c0f940eeede9f72ee421e1eacf93cacf
SHA256: dfb3853ef0ea9df320604876929259972f0fef198bc127dedcda97355833e062
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_hu.dll
executable
MD5: 7e5bd36cacb337cc16f33da55808b0d4
SHA256: 22a2108eb2f9b198eb399827dd58de859a20b2235daa9ce948f0096bd923b329
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\goopdateres_et.dll
executable
MD5: 669f4a7f0397a2de962e4171d5161e32
SHA256: 6b4972f005c29c40d385691ce4b886ede3faf5ce2401e9e025ed9f800ae5cc9b
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-sq.mo
gmo
MD5: 63ac5d997cd1b5c8722b063b95b0c3b3
SHA256: 76b4b445c71d746d16f6831b9771dd504c28df0bd235325d7036381e28eddbc6
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUME271.tmp\OfflineManifest.gup
xml
MD5: 2fd93770e01010902dc7fe77917592f5
SHA256: b8684a2a4f7666fc1b36e3172c8c76a0d6c5bdf2adac9585ceaf125b997441a0
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Local\Temp\nsk809C.tmp\ioSpecial.ini
––
MD5:  ––
SHA256:  ––
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Local\Temp\~DFD42D5430C95C5E08.TMP
––
MD5:  ––
SHA256:  ––
4008
GoogleUpdate.exe
C:\Program Files\Google\Update\Offline\{4948BE44-D6FF-4AAD-9D54-1E7E9D9A3838}\OfflineManifest.gup
xml
MD5: 2fd93770e01010902dc7fe77917592f5
SHA256: b8684a2a4f7666fc1b36e3172c8c76a0d6c5bdf2adac9585ceaf125b997441a0
2140
GoogleToolbarStandaloneSetup_latest.exe
C:\Program Files\GUTE272.tmp
––
MD5:  ––
SHA256:  ––
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\META-INF\zigbert.sf
text
MD5: 3ffd92098d187306bfc2b643512dff0b
SHA256: 32659f39377a12c591363d6fb58b37caca55b57a1ee6f21ea66811d364b7fe29
2408
bitcomet_toolbar.exe
C:\Windows\Temp\SHCA_log.txt
text
MD5: cb971e312750d88395c66ad8377146e6
SHA256: 3312e8e076c7c0621450b0da81a355fc70dcce357d0b08f698a1791c832228a7
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\chrome.manifest
text
MD5: d38cb4646faba182056f8f6d24210380
SHA256: 0feb5847642b9f452f5016c733238c5d45335823a00b267b078450dca9277d34
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\defaults\preferences\bc_context_menu.js
text
MD5: 1956a40c357bb8183229d424f59e0a08
SHA256: 5038ed90c9a2e9a6bf241130e6af4bdbfe812357f485c2859a52b8e34f64d71a
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\install.rdf
xml
MD5: 62b47e3375588c5fe65e4274a41e4f56
SHA256: 6b3282feeb410fe7912e56c8f80078a379da28ce7b996d79532d8f121f4e1cf5
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\readme.txt
text
MD5: e28d2fb90094d86da816d6785a80b350
SHA256: 04c4b79d9d18b366d59542ef870e02746c2a9bd3519dd5c27a71726a11ad4f4b
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\META-INF\manifest.mf
text
MD5: 258b4463a31f5e7572de535123fb26d4
SHA256: 6b9f90c89611c3065cd6e37708b15c0f56fbda7929ff632d32171b143dc792ea
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\DownloadService.js
text
MD5: aae26b30534c1a399853e854fd525106
SHA256: 916e5e2568303a81a90c9605090951ca3b3196ea0aa93367f73c45b0e806af2f
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\chrome\skin\download_media.png
image
MD5: 615cda5649dd503d0bb38373e6bd69e0
SHA256: b836d0291b2648b11da277b06cd8179c4c52b670307908a788cc02517a07f15b
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\chrome\skin\icon.png
image
MD5: b7ba099bb796495efa290ba438162c90
SHA256: cd6d9901f7ad534bad5b683c1aba445b4c78aa4d378ca67640638d26206872f4
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\chrome\locale\zh-CN\bc_media_capture.dtd
text
MD5: 0d69e217624a3dd2fae3cdbcf5b48710
SHA256: 1f39dc7a35d5bb695c1de01cd6346a207a40619e4215ded29309132bf1d418ce
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\chrome\skin\download_link.png
image
MD5: e8e231e33c4c8b67f27b6438ecf621af
SHA256: 4979159267320d57ac38438d544619b97800d4a0bf92cc6203b84d09e387f775
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\chrome\skin\download_all.png
image
MD5: e8e231e33c4c8b67f27b6438ecf621af
SHA256: 4979159267320d57ac38438d544619b97800d4a0bf92cc6203b84d09e387f775
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\chrome\locale\zh-CN\bc_media_capture.properties
text
MD5: a5c663061246e86856cd6ab0b1cd0431
SHA256: 54feb373feba9be4d9c36ddf02d233dfcdd5184ff4084314972e6936101d16e9
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\chrome\locale\zh-CN\bc_context_menu.dtd
text
MD5: 98b6c8902eac6f8fbc4f2438092286a3
SHA256: 846bb03fccc17e24ea336a300f6e4da1fce704ff4a5a489541170b90294fcc58
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\chrome\locale\en-US\bc_media_capture.properties
text
MD5: f137693bed4768d48caec88634b232c2
SHA256: 7eb27493df7a01c34d86b3db76967eeab9cd31de022fe65969fbbd27e975db0b
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\chrome\content\bc_media_capture.xul
xml
MD5: b94b8ea1ad36db8ef22734063de363b3
SHA256: 14440cd1a2cd79a7c519ec9871950e79f44e39a4104450db480f33f5de80a46a
3088
BitComet.exe
C:\Users\admin\AppData\Roaming\BitComet\cache\post_info.db-journal
––
MD5:  ––
SHA256:  ––
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\chrome\content\bc_media_capture.js
text
MD5: fadb0f99adcdcba5d1ee779736a0df0b
SHA256: 7e86e6dcd6fc95d714bf1bbb29bc792696191a76366761112da68ad1abcc4028
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\chrome\locale\en-US\bc_context_menu.dtd
text
MD5: 9c68db99302d000adbcf7dc35e763705
SHA256: fb30c7fddc0d3caed6b0f962be5f353bbce95ce6a9dd1b6c27a84844628a486e
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\chrome\locale\en-US\bc_media_capture.dtd
text
MD5: bde89897ce347ff8fbd1a0741f74a70e
SHA256: a2d76ff2ade23e473fe37cc3c7c6830b45be158b219f17bf2c4b6448040da53a
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\chrome\content\unknownContentTypeSaveAs.js
text
MD5: d11ae9a838cf1eab53b27e7a413f61d2
SHA256: cab839e8ba49cb05baaf28c8c4ca70b38386c8969c30f49eff07feb59b352591
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\chrome\content\unknownContentTypeSaveAs.xul
xml
MD5: a95b363b42b483ba845da0f95b899fd4
SHA256: 2c5279ef4e8a66f30961de0aa03a6e4c22f1e6887103bb3419c59e48fbcfc7cb
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\chrome\content\bc_context_menu.js
text
MD5: 2e910dfaf60d0d2942afd4faa6a1f449
SHA256: 93443b287b3c77165b39d0857993c37a6a5529bc7453c1a1d2bb0c62897da3db
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\chrome\content\bc_context_menu.xul
xml
MD5: c80acec2918d0c2b21bb81d5bf35591b
SHA256: c0cafbee5fd1a97293ccf4ffaa31d0c8cc6cb93aa3c28eb4d64882deeeb1027d
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\BitComet Extension.txt
text
MD5: dbdcaa94e085642322f4e1eac951af34
SHA256: 92d4ddbe5f1e1563ddeed4be62c688630661bd30fb0e58f5ba75241ae884fea3
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\META-INF\zigbert.rsa
cat
MD5: 84cdf9ce720c8cb00ebd4214c5e4f02d
SHA256: 55517ebdb4a2033fd01fb73bf3a30ac96e279e0c1be640c142a2000dff7218d0
3088
BitComet.exe
C:\Users\admin\AppData\Roaming\BitComet\BitComet.xml
xml
MD5: 0ead164b6679d8de8e17e8e9ff55bff7
SHA256: 327799f401954daf3631960564d9d6652309e6b16e14f0e4dd7374eb491fe456
2460
BitComet_1.37_x86_setup.exe
C:\Users\Public\Desktop\BitComet.lnk
lnk
MD5: 24735ebcb2ac51179ae6021fb5a83c9e
SHA256: 180ec9d616568a3e8c63dc29c284c42a16942e93b8fac7377112ed2102ea69e5
2460
BitComet_1.37_x86_setup.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BitComet\Uninstall.lnk
lnk
MD5: be13b49c6ff40c750294f9980fc30dd0
SHA256: 01603e0831438fe48eab123498fd00386eb819357581204f8fd64c48dfe0ac5c
2460
BitComet_1.37_x86_setup.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BitComet\HomePage.lnk
lnk
MD5: 6096b10edcd921a06df6345b73f36820
SHA256: be988509fa23d0e5e5a112f68726fe6801b26397163f34967e75d92eeaaf39d6
2460
BitComet_1.37_x86_setup.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BitComet\BitComet.lnk
lnk
MD5: 98b2927aa6e804f974927a3ba16cc19c
SHA256: 0f669cb5f890efc23cdfc294e13baee0496d404d1b55eaab8c5aab4ff39fa9e8
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\BitComet.url
text
MD5: db92acdd3ca34962a98787ef93ba720d
SHA256: 9c62ee59333568c5248cb620435ba08bbb2faf79d08bfd0569b7e66bcf1e62b2
3088
BitComet.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\LNZN7KH8PBJSQYH10OQD.temp
––
MD5:  ––
SHA256:  ––
3088
BitComet.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\a31ec95fdd5f350f.customDestinations-ms
binary
MD5: 9b327a85cc89d2f93e99955cd1d82098
SHA256: 37554058f7227acffbcea873190c313709efa1199704503b228f5bdc8072d8c7
3088
BitComet.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\login_4.gif
image
MD5: e46dc8ef426b058199fe411b2f7455eb
SHA256: 6e706fd03092106b9844514d664d97d7f16915168447f9883427dec16baa1b34
3088
BitComet.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\login_9.gif
image
MD5: 8a9e4e3ef7a459154eab8af797a0cf3f
SHA256: 0305b4dd59b04e59af1a48317628835eda6354b223d697c601976b8012250115
3088
BitComet.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\login_1.gif
image
MD5: 8fd2d2c77bfb8ee928f0fa727fe3b2a5
SHA256: b962dc0a6db379dff05c2886d5c10ff5479a682dc068e45fdc6c41a85a2eb472
3088
BitComet.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\login_11.gif
image
MD5: e306571097798b916e1c9139288d9be7
SHA256: 971f7cf646d424c18f50c31b1ea41c2ee372a1d80e7f1a7874241c366fcdbd8f
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\tools\bitcomet_extension_signed.xpi
compressed
MD5: 4bc8ac47a1c661f9dab2608152705fda
SHA256: 13414ffc77ea9bab8c92919772e6a6a1f8a931d2cd54ca8ab8f1f6efe67eaf20
3088
BitComet.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\login_7.gif
image
MD5: d3d7e9f65fb43d0496ad19e4cb275b7a
SHA256: 50207efa8acec9a590f7b9d8727ddb586de9e770da13d092da38d1e33ee73cb0
3088
BitComet.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\login_17.gif
image
MD5: 786a136a95b93d4b7b9298d4518200ef
SHA256: 0f01db9b6697689b0e3d5eef62f98f5d50708e5b1da7aa3943a1b65026bab604
3088
BitComet.exe
C:\Users\admin\AppData\Local\Temp\Bit5C0.tmp
binary
MD5: a1fc23c36bf813032d854b4722b85923
SHA256: 11985d7343a5aab884c576d454e614426a5ec039559175615bb2929586147b3d
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\rules\tracker.dat
binary
MD5: 9e6f009bf2ca14f75a31c2afc542042a
SHA256: b5a1a3420c18767066b51381c2eaac755e0123ac04b030784a9a6b97bac912c6
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Roaming\BitComet\fav\passport_login_en_us.mht
mht
MD5: 748f48f40919f6882ec66dffbd246ead
SHA256: 110f45f7a774f6f93593fc473014bd4ef9641ef89d596a47b74d3f4f07fdd538
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Roaming\BitComet\fav\passport_info_zh_cn.mht
mht
MD5: fc6590db6d1f50291804e70d8883c436
SHA256: 0c1b05a2b9ba99bf4e862c175c5d554e800130c254ea01947baf96911914dac4
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Roaming\BitComet\fav\fav_ja.xml
xml
MD5: 9e6267eed37e5038bf307604785500a5
SHA256: 32c30964536ecf3e5903b514b298ca05d1fa3ea916859790882a637c84426ae3
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Roaming\BitComet\fav\passport_info_zh_tw.mht
mht
MD5: 950c0f4279383a14482b113089fd9038
SHA256: 03ae11be4c370b26497aef102a2a81e6825f80be2e6cc1ced6502edc817c4d24
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Roaming\BitComet\fav\fav_zh_cn.xml
xml
MD5: 94a3e5b2bc4f8251014e5df5131dc83f
SHA256: 78fee7fb3190849f44d6cbd11fb72ac278aecb0090f7eb1c920c8c0b5e8e2bc9
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Roaming\BitComet\fav\fav_zh_tw.xml
xml
MD5: fefd5ef804b1f8ff8661b746396abf44
SHA256: bd36dc1a0956df0fb7842ab5f09d7f8926c86c8438bbcd4a6d90f69db759f970
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Roaming\BitComet\fav\passport_login_zh_tw.mht
mht
MD5: b51069f4144a57b852c24217fdd35639
SHA256: 1975be5bbcac5d452fc61c6d1da51505ca6f86da8f5311a8075e06652eeae61a
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Roaming\BitComet\fav\passport_login_zh_cn.mht
mht
MD5: 71803a5c9db3bb6e9c53ae200a9552f9
SHA256: 5f0a081bc769cc87f0db6377babb42139d0f17f0afd7b2ebc9d5a3fff3436aad
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Roaming\BitComet\fav\passport_info_en_us.mht
mht
MD5: 1522a605f1ef6ab932aa62825d55a42d
SHA256: 7874727953375a578ec58b9b02a56c4c1d6a191ccf38b4b1f22b6f8f9671e64c
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Roaming\BitComet\fav\fav_en_us.xml
xml
MD5: 2a197a5912d0b6434835e02a3950420f
SHA256: 3529715faef07f6691ae0f02297aa9eb1e14926b2be48236aecbc0f044bc0169
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\HowTo-Translate.txt
text
MD5: 0707a1610c37c7a42a227307fddc2d6c
SHA256: 366a3557cc9cee9ea19abc930469526d180e223f86c0300f4ec73b887665333c
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Roaming\BitComet\fav\HowTo-AddYourSite.txt
text
MD5: bcb8fcfd9f2895dba661d9d6a2c7e104
SHA256: 64977ee1c99f4f74fd196814736745e30d23d57a0e9f40ae80da9ac4061c5f78
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Roaming\BitComet\fav\download-complete.wav
wav
MD5: 8980afea02e229237a12725d4671f5c4
SHA256: 3dcf2568e492a62f91c6c9bbcfd7f1a12aa272fca37b2a7ec7d68ad40bd462b8
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-zh_CN.mo
gmo
MD5: 1104f246b7e89809e62caa62770c5bb0
SHA256: 0d71cb70ffac13d4e238bdf19f265722a3ad4d8b878adfbb8bb382893eb8d2d2
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-zh_TW.mo
gmo
MD5: 3ca1380cd4bc0d63dd55ab16b7f53c60
SHA256: 2f289631f1bf36b22dc10c9c510658c48600c14fd58989607ab765743235539e
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-ug.mo
gmo
MD5: 9453a0975ea0e7dd9744280745ac7767
SHA256: d383fe9970d440b9b5b87b826608b5322dac0ad28ff802bdf3950f4837c0d7ca
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-uk.mo
gmo
MD5: ae7862d71d4139e21b9d5672abb64bc4
SHA256: e4bae2eef6594acb36ab872144528ec7dd144726b6de7412638deebd8e56cb55
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-vi.mo
gmo
MD5: 986033d73c33a76578e605257fff3abf
SHA256: f296d274d1524b17b1b68ee5f2c52d2fab3bc293119105e8fac7c9fbbdbd32ba
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-ur.mo
gmo
MD5: b23913fee2de60f48f4471838970b685
SHA256: e3ee38997ab8f3b04ab5181ed1706f84a77b9b28e13b41c877097b01ca735998
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-tr.mo
gmo
MD5: 55e6cd8c3be0baca5dabf1aaf88bdbba
SHA256: 3c1e0387ac08c4ceb8bea75dcb8cc117e561a5a20321eb24dd5600e25b6ee132
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-th.mo
gmo
MD5: ab5d2db46d658920b6676aff1d80bd23
SHA256: b278124bb12679887c253fa40469c383be65bac922bb058fa07f9f321cad89c0
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-sv.mo
gmo
MD5: fd05b5234c0f6af6e558be985f0e9573
SHA256: 5821984b93559f22e4cbf5a8472937fe4aa4a488dc05b43f679f8c8781a89da7
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-ta.mo
gmo
MD5: 0fb455e757560088f231731e2161a48f
SHA256: 78e2e780a02dbde6bd68684a1de3b8c025801502b6287bb061df9f55f78c3224
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-sr.mo
gmo
MD5: 08f08a8c7d60b4c797d9879b194de698
SHA256: 167846cd43b5579cd26a76e96df45acbdec94b7067d963d40a743601a1f4d041
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-ru.mo
gmo
MD5: ac5c5ef3773d18b751d4a4a50068507e
SHA256: 3338f9b382234b55e3cdabf9bf26cf98829ae7a85b4a53dd8e7d9e79d3c49e3d
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-sk.mo
gmo
MD5: b216b91fc7858ebec4f7c8bbc5dccad0
SHA256: 64e94aadf69b08ceb601e589ed99d56859132fcd5a569e3677c44fe44962faa1
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Local\Temp\nsk809B.tmp
––
MD5:  ––
SHA256:  ––
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-sl.mo
gmo
MD5: f99f516ecf78245fc3f27865b68585fb
SHA256: dd5ed6cb8ef7446ea131183d1e5e6339d9c1d8ebb6e0976c05afa8565f333797
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-ro.mo
gmo
MD5: c80f811e793f202fc5f686ef7d36b083
SHA256: dd44f0e5a349b1e3ec60a1c717bec0d06b2ecb8d82a90be896a8d0ccb9978c7e
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-pt_BR.mo
gmo
MD5: 00ebfd59ea96fcebbfcb8e276e2e6684
SHA256: 87d49038ed8c74766991b6961ebce79671690c38ff1e5084e153d2cc65de32f4
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-pt.mo
gmo
MD5: a3f96d1e5a707b1af99f5274314151f8
SHA256: c0a4d06d3f611cce688e6170000e9fd7eb6755e2051230ef5478d262acf666d9
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-nl.mo
gmo
MD5: 62b6f6f41ad17d75d8dda84cd3007a86
SHA256: 1d5ba681b73d221fa1e2abecb9fce019b1bd8b66141884bc3dbd707777baabe4
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-pl.mo
gmo
MD5: 2820972967ff13b53719e2a40d67d82a
SHA256: 131c1acafa548f56201957f3eaf568b7567893a24524342ff874a6a563429546
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-nb.mo
gmo
MD5: e393279719144382190ea3fdfd96c79f
SHA256: e04a46b846dc6dcd11c8d55f3c73c35ab757207f9c18545477518937ed022232
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-ne.mo
gmo
MD5: ac5f85fbd22efcc4e2b883de7fc0f2de
SHA256: f69e68a012fa1ba806657a82abdf265d76a8e2a07bb11cef6768ea9cefb923d6
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-mk.mo
gmo
MD5: 97fe69f9fb6eecf92833191c79db9063
SHA256: 87580a38bff84709774d8f00eb2a6bad01086389d294da9a8f1a1957cec7da9a
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-lv.mo
gmo
MD5: 798b2384060048b67c92ed3881cf7fd4
SHA256: 3bc8803e58c944a13e372bf993aa0a9c7519a283b815a44c748b22e46c02daaa
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-ms.mo
gmo
MD5: 482a2ec737541d249053606fc604821d
SHA256: 9e5ac8761441e6d3aad5cda0a335540727c96d56d7dd7e0444663032241238a5
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-ku.mo
gmo
MD5: 7b7996b943ff978828c223f53adcfc2d
SHA256: d7ca5018287a09d420ee5e51409887d90bc0b1ca6b30464183587979b96f851a
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-lt.mo
gmo
MD5: c11d9d8b66baf6902f629645114266e2
SHA256: 3befb0237b7d63f538fc5a5ee232d45798a0eeaddfadc694db61e223f82229e6
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-kk.mo
gmo
MD5: 290970828aaf08c157d4f7e9e399ecdf
SHA256: 88ce33905eef737922a7086f3debd72d29c67aa5e713c8b1e2c7b93313fde7b5
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-ko.mo
gmo
MD5: 2fa3826c0357a89c698e709e9cfa2a39
SHA256: a8c74584358e72ffa02d0ecf9e216a33d70bf884129ef412269a703f57cc46ee
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-ja.mo
gmo
MD5: 0cd2b2cbb1bba0515c916702c3b5c960
SHA256: 65b938f1b9540034535013c06c2b1d37f5abf5822badb7dde97a1ec0ca196882
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-kn.mo
gmo
MD5: 8189a08d6dc3bb4b35d42f1d22179737
SHA256: f5e73158c63db43e6af82add00b31610e3176dd9ad56b90cb2c000fdf6cbf285
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-it.mo
gmo
MD5: fe067d4dcd7a3391e77c906149f3b487
SHA256: 2450ba3ed12e0fc4a5d0a7d8e92af1759bf80990f5c93b7cf98dc84906e91828
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-id.mo
gmo
MD5: 8723f49de23f0e43637fdbe255bb2660
SHA256: c68c2bce87d808b63e562945fb636959017b2bb99cd27325732d14acdd0d5e42
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-fr.mo
gmo
MD5: dea2ab51079dfe5b1832630898f7973f
SHA256: 550d025cc38640cb83192a7d4667c80a2d3488607518736e647dbd69f0c5a62b
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-hu.mo
gmo
MD5: 0b9c05297753f2e5d48f63d6674d1e01
SHA256: d87e1604427d70b7149c523369dc52f87391675e87f01e3f205219b8617528ea
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-gl.mo
gmo
MD5: d9a26b55fd8765faf464d01d56353024
SHA256: 8a0ed2c581575d103c74769abe975449f3296872e735af98d1717317a5ae3381
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-hr.mo
gmo
MD5: 06235172ff0aa10fab4f93b2b94d6fb1
SHA256: 61cc6924d17e01dd1cb025765d6a46642846e60d4a75a0fb046456483e1a8677
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-he.mo
gmo
MD5: f4ed0b17c2849d1467040d91072df298
SHA256: b80add04ce7a972095a3f1eca165eed7bb046d7ef90ad06b6f985fc3b8cfbf42
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-hy.mo
gmo
MD5: f2212a5bbf80938d67ddf09f8cd68100
SHA256: 638f551bbb8bea87d0917c6662809b98325fc7bd044c517fa6e8edf02eabfbe2
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-eu.mo
gmo
MD5: 2d8767f3b44722657ec03f9baddeccd3
SHA256: 70cecd27c85a4a42ab96048de05c2010c16e066a14dc753d8b4fe23b21bfbf4a
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-fa.mo
gmo
MD5: cf5474ca96f9587a329472c4f408c1e5
SHA256: 3351f64f12943e221fb74359b6aebfd7e04ad8d2c8b643ec10b49c9e641fb3b9
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-fi.mo
gmo
MD5: f31fbb12db2d458e2bbcc8184637a0a9
SHA256: c33acfadb18f451afe3888ff3a30facb2229e9b8f951ed2cc2bfd1eab25c03bb
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-et.mo
gmo
MD5: 80a395c19570058376ba357eb55662cb
SHA256: e43e959c7d54288965e662f05e04b9315fbc2b15c3752e4e46899fa650061336
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-es.mo
gmo
MD5: 9e911aec05b48cd5067a7416066b3398
SHA256: dcbdd28f0e2cb6a1b164bb60038d3bc5a1f6c904932b42080f6a45597f2e6876
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-el.mo
gmo
MD5: b30f0821c4e4eeed3f436e4b67aa10fa
SHA256: 6b848d26060f39eadcacbb82ac0428dbced08a95a98a712934057958bb813b11
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-en_US.mo
gmo
MD5: b2f96361f0a69b1e736d420eb827a82b
SHA256: f0306d06bbfcaf0a6d2f3f07ced61774a6e983f618d134c9d4ec7744901f2b69
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-de.mo
gmo
MD5: 472c81094eb2924193d526f8b8245b8b
SHA256: 155f1eb67973d640f9fafbb4d9cd17a1a39e3643261942c758aa16e41840b3a3
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-da.mo
gmo
MD5: e7720efcbb04eaed414cc61516a72ceb
SHA256: ad35986ba579b464eff6686275ccf537c962aa617f44f11b70a49a92160dc89f
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-cs.mo
gmo
MD5: 0aebb10c5802b9d51064a7fbe7a8abfc
SHA256: 9abc7cbdbd00f6b9220551ef675dc5b72dcceda1df7810e9b0d51ed8a182d754
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-bg.mo
gmo
MD5: 79326f27cb037d8c42dee8b23099dbf4
SHA256: da29dd17c88aa7ead853ae38892a24ad8883bce555f5abc13b96542eeb190268
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-ar.mo
gmo
MD5: 8b1de1707325837735bbb953ce8f63fc
SHA256: 80de98f3e109834b0d9d1bf627b808792e885b9026ac7b74527fd55ebe582845
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-bs.mo
gmo
MD5: 53f5a99d7099d4ad9e0993352cd03c75
SHA256: 9bbe21b38544231638c24d6ab66716369c308fcd309861a13e8b8544c6979b1e
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\lang\bitcomet-ca.mo
gmo
MD5: 57f926b1f614a6e0cb0699a84ef6d677
SHA256: f1f39e71915abc80bfca1cee97b16bdb78b87111cf2d32ab234ccb91fc751184
3088
BitComet.exe
C:\Users\admin\AppData\Roaming\BitComet\BitComet.xml
xml
MD5: 30e3b9f4dfb45742b69dacc98be3d5ff
SHA256: 62e5ec0e632db1af1f1fef725e81c068138f21f39fe7537ba3f4b54789011cf2
3088
BitComet.exe
C:\Users\admin\AppData\Local\Temp\bc_cache\temp1
eml
MD5: 962a67f37bc2e781a76d60b5b9da8791
SHA256: 304f60fe9155462d6a476a11d26efbcd906e520a5f7db9298a1fe4936a52a616
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\ChangeLog.txt
text
MD5: c929b3b37df4f0096cd65e5879f58988
SHA256: ffaab184bd788d79d14507068737555067d4aa8a70a4be2aef516cf28b641bca
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\License.txt
text
MD5: f89b3e6b67b0f87daa225822c9bc752c
SHA256: a4e351b0c180d29d9ca058111e8ed0606556d59e902f0125b1995fc1cf20612b
2460
BitComet_1.37_x86_setup.exe
C:\Program Files\BitComet\ReadMe.txt
text
MD5: 01f80614ceb7e0394f966d3531064eb7
SHA256: 65ffdb69b24f7b1fa0c3855f82069193e71127124873f977dcf9acd46b2884ab
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Local\Temp\nsk809C.tmp\installgtb.ini
text
MD5: ac287ac4a20a2d888c48d9f5a6fcccaf
SHA256: f3afae8ca014f227cd5d81ac10537a6196a1dbe25993ae74dc07f5d906bde323
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Local\Temp\nsk809C.tmp\installgtb.ini
text
MD5: c45b9d07934d3ead34f44f6ba4be0d21
SHA256: ed1a2f80f32281a395e986f157c3884710f2cf4057a3283ac126b3a49310d402
3088
BitComet.exe
C:\Users\admin\AppData\Local\Temp\bc_cache\temp0
eml
MD5: 2e31c4127a405f8cc4a9810a55320c2d
SHA256: b8e9033c62e41a0cf84b9cb5196ba0acc5219dbcb9273294c7cdf051569f0a17
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Local\Temp\nsk809C.tmp\installgtb.ini
text
MD5: 6a6957419b17a54067fe86f5697ad980
SHA256: 5b66550b9884d7a4c1b51e416d2442874929d0c7f9b26e02fdd3cc7cb8f53f2e
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Local\Temp\nsk809C.tmp\ioSpecial.ini
text
MD5: f4140d35af1f466840c212491f80f0f9
SHA256: 4877fb3f28c7e9aece8c532fe2e616703f236a6f19a4b1f334907a1daace1483
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Local\Temp\nsk809C.tmp\ioSpecial.ini
text
MD5: 1d4b1ccfec8cf9d7fded63a61f41ae86
SHA256: 8e87e9992be9c98662275d577deac6cafdc2983b059c3ff1a4cd42d55ea40572
3088
BitComet.exe
C:\Users\admin\AppData\Roaming\BitComet\fav\passport_login_en_us.mht
eml
MD5: 962a67f37bc2e781a76d60b5b9da8791
SHA256: 304f60fe9155462d6a476a11d26efbcd906e520a5f7db9298a1fe4936a52a616
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Local\Temp\nsk809C.tmp\modern-wizard.bmp
image
MD5: 9e4cd80a60db6947642677bf31a10906
SHA256: a7b2f12e01cbea88d4f645f797f2ca6107d76ae13cd1be6dc532b759bfe0d925
3088
BitComet.exe
C:\Users\admin\AppData\Roaming\BitComet\fav\passport_info_en_us.mht.bak
mht
MD5: 1522a605f1ef6ab932aa62825d55a42d
SHA256: 7874727953375a578ec58b9b02a56c4c1d6a191ccf38b4b1f22b6f8f9671e64c
3088
BitComet.exe
C:\Users\admin\AppData\Roaming\BitComet\fav\passport_login_en_us.mht.bak
mht
MD5: 748f48f40919f6882ec66dffbd246ead
SHA256: 110f45f7a774f6f93593fc473014bd4ef9641ef89d596a47b74d3f4f07fdd538
3088
BitComet.exe
C:\Users\admin\AppData\Roaming\BitComet\fav\passport_info_en_us.mht
eml
MD5: 2e31c4127a405f8cc4a9810a55320c2d
SHA256: b8e9033c62e41a0cf84b9cb5196ba0acc5219dbcb9273294c7cdf051569f0a17
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Local\Temp\nsk809C.tmp\bitcomet_extension_signed.xpi
compressed
MD5: 4bc8ac47a1c661f9dab2608152705fda
SHA256: 13414ffc77ea9bab8c92919772e6a6a1f8a931d2cd54ca8ab8f1f6efe67eaf20
3088
BitComet.exe
C:\Users\admin\AppData\Local\Temp\bc_cache\temp2
––
MD5:  ––
SHA256:  ––
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Local\Temp\nsk809C.tmp\firefoxextension.ini
text
MD5: daa9b5dd2de4f31d67c473518e0b5f27
SHA256: fcaa7249d9e038dff7a327de52987ec9c4f14e640f747f9163c274508876c5bf
3088
BitComet.exe
C:\Users\admin\AppData\Roaming\BitComet\fav\fav_en_us.xml
xml
MD5: d5261eed2ad6a3d575a41ad04d2a642e
SHA256: 7ffc245b285b07d908ee24dbe0861d97bcbc5529f513a8bbde4e5ab318d6ba74
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Local\Temp\nsk809C.tmp\chrome_preview.gif
image
MD5: 3a52d16f3090baf3a43505df4041b864
SHA256: fa9030b1421c9b41e159c0d05bc7be7e5c2b908e5420a899027125dbcb5c5664
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Local\Temp\nsk809C.tmp\chromeinstallcomplete.ini
text
MD5: 8eff23b6d3600f3abf30daa1af2febe0
SHA256: 9457d4a8a6452176b91f8ccae1d9e3c127919b18dc75fc09874d103cd7d88a03
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Local\Temp\nsk809C.tmp\chrome_installed.gif
image
MD5: 175060a5bba6748efd8cafa55d8db9e5
SHA256: bc59d700639365916e14b5a08e6ec15b9cf43e515e7e3957f9ca0674f102254f
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Local\Temp\nsk809C.tmp\chrome_icon.gif
image
MD5: 33892ca38b4d47faa5490dbede65c04b
SHA256: a36ea17ca0ca39f688ec2f8a5de7b6f77783388b5846f8bc379a7d972f6c5846
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Local\Temp\nsk809C.tmp\installchrome.ini
text
MD5: 5a51d74262a2849db41877011ba97ea3
SHA256: eac6dea03d330a0519b7a4d040f71a2d0a7aa7c0f0308992028583b300a33500
3088
BitComet.exe
C:\Users\admin\AppData\Roaming\BitComet\fav\fav_en_us.xml.bak
xml
MD5: 2a197a5912d0b6434835e02a3950420f
SHA256: 3529715faef07f6691ae0f02297aa9eb1e14926b2be48236aecbc0f044bc0169
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Local\Temp\nsk809C.tmp\toolbarinstalled_en.gif
image
MD5: f6a524b3c625968088effb1cd600a532
SHA256: db1f1c1998c8f79a7d36f625a16537d8252f5fe7be248a923722dcc4075667c3
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Local\Temp\nsk809C.tmp\toolbarinstalled_cn.gif
image
MD5: dec4280df7c521109c61cd7c47f0ce77
SHA256: 8b09a147d727f279a7ac4332afbb02d9474f183e17c456c927595a46aa54ff40
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Local\Temp\nsk809C.tmp\installchrome_gtb.ini
text
MD5: 4d1794f577763193874f09eadbcbf293
SHA256: 826ffd1e4b004770b5d8abcf071ef121a6b81e681c2b85bc0df801f5ff6f4ee7
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Local\Temp\nsk809C.tmp\toolbarpreview_en.gif
image
MD5: 1ceaccc0643f0bc669f27836de1c07ad
SHA256: 5cc70a779f1fcb19fd1a17ec067435caf6cfdf1e2c27bcdcc50f7d66f58c7968
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Local\Temp\nsk809C.tmp\toolbarpreview_cn.gif
image
MD5: a8cfbbf5f2bc09a3c444d33d22a16bd4
SHA256: dcd23e8ca857da6ca435631ec8cad2f1970640a7b7b56c9efc5fef0531d7c373
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Local\Temp\nsk809C.tmp\toolbar_share.gif
image
MD5: 8b1d7f57d889be806c97ca0d04f95784
SHA256: 4025a2e570e2aa102edba3d1e9a4943b0203fc2f0376a9519e383db8d7a3d84f
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Local\Temp\nsk809C.tmp\toolbar_translate.gif
image
MD5: 726fc364d40dfbf9cd818dbd53b227ce
SHA256: 55ee55da92c819cb8a10bb448139ea1e66890777f143065e16eaf80c81e9fb62
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Local\Temp\nsk809C.tmp\toolbar_search.gif
image
MD5: 8ecc19594c13e5c49996d2709bd8626b
SHA256: 2787432b9aa0fa55a77c87cd749ad93de7429168c5b66d5c61df92fb2060ae7d
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Local\Temp\nsk809C.tmp\gtbinstallcomplete.ini
text
MD5: a72130fa85e927d09d9af98cd0b9fc0e
SHA256: 845b27c7e1a4d9ac6c677072abb0d0d8a7cee567b33d5e101c4aca36b6e6b73b
2460
BitComet_1.37_x86_setup.exe
C:\Users\admin\AppData\Local\Temp\nsk809C.tmp\installgtb.ini
text
MD5: 99ce7caef229103da32c57d8d362c8da
SHA256: 3b513ae341aabb57a7530f8bda073627982f24e8e72d735585ae60656fa31f1e
3088
BitComet.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\wbkF52F.tmp
html
MD5: 4b1325dadcfe60127463b0194dd5bad2
SHA256: 8ad81bfe3e0d99bd48476f964afb9a908ebcea94da9488c66b283b61768f3c61

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
10
TCP/UDP connections
5587
DNS requests
7
Threats
12

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
3060 http_Downloader.exe GET 200 213.136.77.195:80 http://download.bitcomet.com/google_component/bitcomet_toolbar.exe DE
executable
suspicious
4008 GoogleUpdate.exe POST 200 216.58.206.14:80 http://tools.google.com/service/update2 US
xml
xml
whitelisted
4008 GoogleUpdate.exe POST 200 216.58.206.14:80 http://tools.google.com/service/update2 US
xml
xml
whitelisted
3088 BitComet.exe GET 200 54.70.241.215:80 http://update.bitcomet.com/client/bitcomet/?ver=1.37&intl=en_us&osintl=en_us&cid=8df8a09fac922b319d16e2876e64f2a3&btcnt=0&httpcnt=0&p=x86&idt=20190210 US
xml
suspicious
3088 BitComet.exe GET 200 54.70.241.215:80 http://update.bitcomet.com/client/bitcomet/passport/v0.89-v1.40/passport_info_en_us.mht US
eml
suspicious
2168 updater.exe GET 302 213.136.77.195:80 http://download.bitcomet.com/update/bitcomet_setup.exe DE
––
––
suspicious
3088 BitComet.exe GET 200 54.70.241.215:80 http://update.bitcomet.com/client/bitcomet/passport/v0.89-v1.40/passport_login_en_us.mht US
eml
suspicious
3088 BitComet.exe GET 200 54.70.241.215:80 http://update.bitcomet.com/client/bitcomet/fav/v1.05-v1.40/fav_en_us.xml US
xml
suspicious
2168 updater.exe GET 200 143.204.98.159:80 http://d3sug1er2oor8n.cloudfront.net/28~p80d77gulh/bitcomet_setup.exe US
executable
suspicious
3088 BitComet.exe GET –– 208.100.26.240:80 http://tracker.p2pcache.org/issupported US
––
––
suspicious

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

<
PID Process IP ASN CN Reputation
3060 http_Downloader.exe 213.136.77.195:80 Contabo GmbH DE suspicious
4008 GoogleUpdate.exe 216.58.206.14:80 Google Inc. US whitelisted
3088 BitComet.exe 67.215.246.10:6881 QuadraNet, Inc US suspicious
–– –– 5.144.57.113:17177 Triple C Cloud Computing Ltd. IL unknown
–– –– 93.73.159.245:1257 Volia UA suspicious
–– –– 103.212.116.152:14590 first E-commerce and TriplePlay Service ISP in Mongolia. MN unknown
–– –– 79.36.111.65:40818 Telecom Italia IT unknown
–– –– 188.251.97.205:22102 Servicos De Comunicacoes E Multimedia S.A. PT unknown
–– –– 91.159.132.13:6881 Elisa Oyj FI unknown
–– –– 2.236.243.32:6881 Fastweb IT unknown
–– –– 112.185.148.31:54000 Korea Telecom KR unknown
–– –– 188.246.253.68:39748 Kassir, Ltd. RU unknown
–– –– 89.160.108.146:29144 Bredband2 AB SE unknown
–– –– 181.160.14.195:6881 TELEFÓNICA CHILE S.A. CL unknown
–– –– 179.113.186.78:60146 TELEFÔNICA BRASIL S.A BR unknown
–– –– 93.120.170.181:49050 PJSC Rostelecom RU unknown
–– –– 2.154.174.8:24874 Vodafone Ono, S.A. ES unknown
–– –– 178.67.44.138:60736 PJSC Rostelecom RU unknown
–– –– 189.18.96.70:40523 TELEFÔNICA BRASIL S.A BR unknown
–– –– 109.252.13.35:5973 OJS Moscow city telephone network RU unknown
–– –– 177.95.0.140:55230 TELEFÔNICA BRASIL S.A BR unknown
–– –– 70.45.42.26:50321 San Juan Cable, LLC PR unknown
–– –– 37.134.236.143:48597 Orange Espagne S.A.U. ES unknown
–– –– 189.54.145.147:6751 CLARO S.A. BR unknown
–– –– 178.87.201.16:52558 Saudi Telecom Company JSC SA unknown
–– –– 24.148.131.42:8472 Time Warner Cable Internet LLC US unknown
–– –– 123.202.164.66:25647 Hong Kong Broadband Network Ltd. HK unknown
–– –– 2.123.59.4:6881 Sky UK Limited GB unknown
–– –– 109.124.240.149:62593 LLC Sip nis RU unknown
–– –– 188.242.55.127:38885 SkyNet Ltd. RU unknown
–– –– 35.212.240.11:8102 US unknown
–– –– 82.208.127.122:46431 PJSC Rostelecom RU unknown
–– –– 173.249.44.184:44702 Contabo GmbH US unknown
–– –– 88.217.225.233:6881 M-net Telekommunikations GmbH DE unknown
–– –– 81.26.169.218:58112 TelemaxX Telekommunikation GmbH DE unknown
–– –– 173.249.44.185:32938 Contabo GmbH US unknown
–– –– 94.61.18.213:51413 Vodafone Portugal - Communicacoes Pessoais S.A. PT unknown
–– –– 89.160.184.119:13117 Fjarskipti ehf IS unknown
–– –– 213.144.15.201:43466 TelemaxX Telekommunikation GmbH DE unknown
–– –– 84.249.142.195:16413 Telia Finland Oyj FI unknown
–– –– 185.21.216.140:57428 Joshua Peter McQuistan GB unknown
–– –– 86.15.233.25:6881 Virgin Media Limited GB unknown
–– –– 5.19.190.38:33985 Perspectiva Ltd. RU unknown
–– –– 207.180.210.81:41189 River City Internet Group (Primary Networks) US unknown
–– –– 108.56.196.88:6881 MCI Communications Services, Inc. d/b/a Verizon Business US unknown
–– –– 139.194.168.35:61031 Linknet-Fastnet ASN ID unknown
–– –– 175.158.192.13:13884 Smart Broadband, Inc. PH unknown
–– –– 94.230.206.109:12701 KhmelnitskInfocom LTD UA unknown
–– –– 41.248.70.73:60766 MT-MPLS MA unknown
–– –– 110.152.23.1:28317 No.31,Jin-rong Street CN unknown
–– –– 176.214.19.86:44000 JSC ER-Telecom Holding RU unknown
–– –– 93.36.198.52:46418 Fastweb IT unknown
–– –– 111.242.147.166:7729 Data Communication Business Group TW unknown
–– –– 81.35.102.113:34945 Telefonica De Espana ES unknown
–– –– 77.101.246.16:6882 Virgin Media Limited GB unknown
–– –– 130.185.216.30:40759 Optinet Ltd BG unknown
–– –– 109.65.54.95:16134 Bezeq International IL unknown
–– –– 117.91.128.54:20683 No.31,Jin-rong Street CN unknown
–– –– 114.41.30.130:7167 Data Communication Business Group TW unknown
–– –– 89.242.58.171:6881 TalkTalk GB unknown
–– –– 87.134.138.192:9089 Deutsche Telekom AG DE unknown
–– –– 221.88.94.38:6881 Softbank BB Corp. JP unknown
–– –– 198.27.80.18:53537 OVH SAS CA unknown
–– –– 113.39.54.133:6881 UCOM Corp. JP unknown
–– –– 203.121.231.70:8580 DaDa Broadband LTD. TW unknown
–– –– 109.252.72.40:10265 OJS Moscow city telephone network RU unknown
–– –– 186.156.119.59:31922 VTR BANDA ANCHA S.A. CL unknown
–– –– 177.3.41.72:11044 Brasil Telecom S/A - Filial Distrito Federal BR unknown
–– –– 126.117.254.24:56696 Softbank BB Corp. JP unknown
–– –– 94.7.118.183:6881 Sky UK Limited GB unknown
–– –– 92.62.52.116:8082 SatTel Corporation, Ltd. RU unknown
–– –– 194.176.236.131:20711 Magyar Telekom plc. HU unknown
–– –– 173.249.4.73:53099 Contabo GmbH US unknown
–– –– 207.180.211.251:7000 River City Internet Group (Primary Networks) US unknown
–– –– 207.180.192.206:52334 River City Internet Group (Primary Networks) US unknown
–– –– 51.15.70.45:64879 Online S.a.s. FR unknown
–– –– 5.55.116.107:1024 Vodafone-panafon Hellenic Telecommunications Company SA GR unknown
–– –– 36.232.117.228:1026 Data Communication Business Group TW unknown
–– –– 142.44.178.206:39688 OVH SAS CA unknown
–– –– 109.251.146.107:26888 Freenet Ltd. UA unknown
–– –– 173.28.123.131:22787 Mediacom Communications Corp US unknown
–– –– 121.211.3.84:7011 Telstra Pty Ltd AU unknown
–– –– 118.83.189.213:6889 Jupiter Telecommunications Co., Ltd. JP unknown
–– –– 46.167.104.136:59623 Maginfo JSC RU unknown
–– –– 178.67.150.194:26985 PJSC Rostelecom RU unknown
–– –– 176.109.222.56:42706 MEGABIT SERVIS Ltd. UA unknown
–– –– 95.26.87.146:41137 VimpelCom RU unknown
–– –– 188.18.44.97:36795 RU unknown
–– –– 176.108.166.56:34926 SKTV Ltd. RU unknown
–– –– 95.67.208.49:12193 PJSC Rostelecom RU unknown
–– –– 94.190.80.35:23900 INTERRA telecommunications group, Ltd. RU unknown
–– –– 89.178.205.95:28490 VimpelCom RU unknown
–– –– 88.80.54.109:35041 MTS PJSC RU unknown
–– –– 31.180.194.161:25531 PJSC Rostelecom RU unknown
–– –– 109.229.113.141:17560 OJSC Telecommunication networks RU unknown
–– –– 95.154.136.127:33700 Production co-operative Economic-legal laboratory RU unknown
–– –– 95.154.163.195:14362 Production co-operative Economic-legal laboratory RU unknown
–– –– 77.108.198.65:33448 MTS PJSC RU unknown
–– –– 77.94.216.164:36998 MTS PJSC RU unknown
–– –– 100.15.207.95:6889 MCI Communications Services, Inc. d/b/a Verizon Business US unknown
–– –– 68.174.134.133:8500 Time Warner Cable Internet LLC US unknown
–– –– 37.9.174.64:51413 Websupport s.r.o. SK unknown
–– –– 80.98.114.126:40103 Liberty Global Operations B.V. HU unknown
–– –– 37.113.222.218:6881 JSC ER-Telecom Holding RU unknown
–– –– 185.162.184.10:61957 Sonassi Ltd NL unknown
–– –– 221.241.43.244:51413 UCOM Corp. JP unknown
–– –– 160.16.184.120:6881 SAKURA Internet Inc. JP unknown
–– –– 116.41.254.23:57760 LG POWERCOMM KR unknown
–– –– 175.114.161.48:41144 SK Broadband Co Ltd KR unknown
–– –– 221.138.220.102:50577 SK Broadband Co Ltd KR unknown
–– –– 106.246.120.98:24884 LG DACOM Corporation KR unknown
–– –– 61.75.51.42:7321 Korea Telecom KR unknown
–– –– 198.13.193.35:6881 ACN CA unknown
–– –– 194.190.92.100:49001 Telecommunication Company 'Motel' Ltd. RU unknown
–– –– 220.118.49.251:34853 Korea Telecom KR unknown
–– –– 109.105.2.165:41565 Naracom Kft. HU unknown
–– –– 24.132.163.86:36006 Liberty Global Operations B.V. NL unknown
–– –– 67.198.72.46:50370 Grande Communications Networks, LLC US unknown
–– –– 181.143.29.70:60530 EPM Telecomunicaciones S.A. E.S.P. CO unknown
–– –– 195.154.173.85:55011 Online S.a.s. FR unknown
–– –– 62.210.71.160:55080 Online S.a.s. FR unknown
–– –– 158.174.179.36:50666 Bahnhof Internet AB SE unknown
–– –– 172.223.70.226:6881 Charter Communications US unknown
–– –– 131.100.243.246:26781 INFOLINE BANDA LARGA LTDA BR unknown
–– –– 68.48.20.202:26510 Comcast Cable Communications, LLC US unknown
–– –– 37.59.39.175:59159 OVH SAS FR unknown
–– –– 68.202.236.246:49160 BRIGHT HOUSE NETWORKS, LLC US unknown
–– –– 179.178.78.68:16292 TELEFÔNICA BRASIL S.A BR unknown
–– –– 208.96.94.59:19222 PERSONA COMMUNICATIONS INC. CA unknown
–– –– 179.34.205.150:21285 Tim Celular S.A. BR unknown
–– –– 186.136.167.51:41977 CABLEVISION S.A. AR unknown
–– –– 101.108.32.80:30287 TOT Public Company Limited TH unknown
–– –– 46.61.81.5:37660 PJSC Rostelecom RU unknown
–– –– 109.60.251.63:19209 Closed Joint Stock Company TransTeleCom RU unknown
–– –– 217.62.34.14:52872 Ziggo NL unknown
–– –– 79.176.232.243:62445 Bezeq International IL unknown
–– –– 163.172.190.248:51413 Online S.a.s. FR unknown
–– –– 94.236.245.176:63883 Vivacom BG unknown
–– –– 93.45.70.50:56563 Fastweb IT unknown
–– –– 80.246.81.39:8704 PJSC Rostelecom RU unknown
–– –– 81.26.169.217:60229 TelemaxX Telekommunikation GmbH DE unknown
–– –– 58.247.85.218:21146 China Unicom Shanghai network CN unknown
–– –– 121.140.209.27:26918 Korea Telecom KR unknown
–– –– 118.170.86.49:6881 Data Communication Business Group TW unknown
–– –– 5.141.81.19:36878 PJSC Rostelecom RU unknown
–– –– 31.10.15.128:31010 CJSC Settelecom RU unknown
–– –– 134.0.106.183:51413 Iskratelecom CJSC RU unknown
–– –– 5.18.233.64:5715 Perspectiva Ltd. RU unknown
–– –– 46.73.0.149:51413 Net By Net Holding LLC RU unknown
–– –– 5.94.141.107:6889 Vodafone Italia S.p.A. IT unknown
–– –– 14.47.186.53:6889 Korea Telecom KR unknown
–– –– 139.47.67.20:12141 Xtra Telecom S.A. ES unknown
–– –– 217.150.72.60:4097 Kozitskiy A.M. PI RU unknown
–– –– 213.136.79.238:33430 Contabo GmbH DE unknown
–– –– 5.189.187.90:51508 Contabo GmbH DE unknown
–– –– 85.84.24.49:36533 Euskaltel S.A. ES unknown
–– –– 200.123.122.196:51413 Techtel LMDS Comunicaciones Interactivas S.A. AR unknown
–– –– 87.218.23.196:27585 Orange Espagne S.A.U. ES unknown
–– –– 79.144.71.173:17148 Telefonica De Espana ES unknown
–– –– 77.27.222.152:52921 R Cable y Telecomunicaciones Galicia, S.A. ES unknown
–– –– 88.25.114.5:43611 Telefonica De Espana ES unknown
–– –– 189.148.162.114:6881 Uninet S.A. de C.V. MX unknown
–– –– 51.15.180.95:51413 Online S.a.s. FR unknown
–– –– 89.212.197.221:14263 T-2, d.o.o. SI unknown
–– –– 151.49.136.38:12616 Wind Telecomunicazioni SpA IT unknown
–– –– 93.232.168.46:6889 Deutsche Telekom AG DE unknown
–– –– 37.113.253.197:55666 JSC ER-Telecom Holding RU unknown
–– –– 217.113.242.22:9228 KAOS redes IP S.A. ES unknown
–– –– 190.206.185.128:22095 CANTV Servicios, Venezuela VE unknown
–– –– 94.41.100.32:34678 OJSC Ufanet RU unknown
–– –– 80.5.76.51:43746 Virgin Media Limited GB unknown
–– –– 180.199.63.218:6889 Chubu Telecommunications Company, Inc. JP unknown
–– –– 185.157.245.75:61980 Netrix SAS FR unknown
–– –– 62.138.18.133:51413 Host Europe GmbH DE unknown
–– –– 176.105.40.15:36520 Bilink LLC UA unknown
–– –– 188.120.228.170:54883 JSC ISPsystem RU unknown
–– –– 93.123.187.230:38189 Information and Communication Technologies LLC RU unknown
3088 BitComet.exe 54.70.241.215:80 Amazon.com, Inc. US suspicious
–– –– 185.42.147.235:1167 INSYS LLC RU unknown
–– –– 37.192.45.34:51413 Novotelecom Ltd RU unknown
–– –– 92.50.149.46:58802 OJSC Ufanet RU unknown
–– –– 178.214.243.174:54409 LLC Telecontur RU unknown
–– –– 46.242.9.106:6279 PJSC Rostelecom RU unknown
–– –– 198.98.125.252:6881 Enzu Inc US unknown
–– –– 69.197.191.74:6881 WholeSale Internet, Inc. US unknown
–– –– 133.130.101.63:6881 GMO Internet,Inc JP unknown
–– –– 212.58.121.174:20287 Magticom Ltd. GE unknown
–– –– 78.194.50.51:51413 Free SAS FR unknown
–– –– 117.152.235.62:50720 Guangdong Mobile Communication Co.Ltd. CN unknown
–– –– 35.230.45.206:47175 US unknown
–– –– 123.181.237.247:3315 No.31,Jin-rong Street CN unknown
–– –– 115.161.171.24:58967 QRIXNETKS-AS- KR unknown
–– –– 37.187.104.161:51413 OVH SAS FR unknown
–– –– 142.4.211.221:6881 OVH SAS CA unknown
–– –– 24.8.59.247:6881 Comcast Cable Communications, LLC US unknown
–– –– 185.107.95.66:23659 NForce Entertainment B.V. NL unknown
–– –– 86.61.24.182:6881 Telekom Slovenije d.d. SI unknown
–– –– 109.128.52.106:28442 Proximus NV BE unknown
–– –– 78.46.36.195:22992 Hetzner Online GmbH DE unknown
–– –– 151.28.138.106:52088 Wind Telecomunicazioni SpA IT unknown
–– –– 54.38.46.195:1028 OVH SAS FR unknown
–– –– 70.65.206.193:25667 Shaw Communications Inc. CA unknown
–– –– 185.46.248.164:20742 Private Joint Stock Company datagroup UA unknown
–– –– 31.128.95.125:21696 Private Joint Stock Company datagroup UA unknown
–– –– 2.26.194.150:50952 EE Limited GB unknown
–– –– 109.91.39.80:16466 Liberty Global Operations B.V. DE unknown
–– –– 88.12.2.27:62687 Telefonica De Espana ES unknown
–– –– 118.37.240.2:41074 Korea Telecom KR unknown
–– –– 213.208.169.248:8621 LLC Nauka-Svyaz RU unknown
–– –– 94.23.206.138:51413 OVH SAS FR unknown
–– –– 213.114.183.216:51413 Telenor Norge AS SE unknown
–– –– 90.252.249.220:60986 Vodafone Enterprise U.K. GB unknown
–– –– 103.207.36.25:3800 VNPT Corp VN unknown
–– –– 125.129.235.2:51413 Korea Telecom KR unknown
–– –– 74.56.134.11:6889 Videotron Telecom Ltee CA unknown
–– –– 46.38.57.251:51413 LLC tc Tel Center RU unknown
–– –– 5.189.188.23:6963 Contabo GmbH DE unknown
–– –– 124.241.180.83:19885 COMMUNITY NETWORK CENTER INC. JP unknown
–– –– 95.167.0.52:6881 PJSC Rostelecom RU unknown
–– –– 58.166.139.162:6881 Telstra Pty Ltd AU unknown
–– –– 68.195.137.142:34857 Cablevision Systems Corp. US unknown
–– –– 24.204.239.12:6881 Cogeco Cable CA unknown
–– –– 185.21.216.150:55591 Joshua Peter McQuistan GB unknown
–– –– 36.238.138.199:25080 Data Communication Business Group TW unknown
–– –– 94.96.8.74:8999 Saudi Telecom Company JSC SA unknown
–– –– 175.181.97.23:22942 Digital United Inc. TW unknown
–– –– 136.61.180.175:57076 Google Fiber Inc. US unknown
–– –– 220.247.66.201:20706 ARTERIA Networks Corporation JP unknown
–– –– 89.212.57.248:19161 T-2, d.o.o. SI unknown
–– –– 173.178.23.127:24346 Videotron Telecom Ltee CA unknown
2168 updater.exe 213.136.77.195:80 Contabo GmbH DE suspicious
–– –– 194.132.235.236:53039 TELE2 SE unknown
–– –– 59.22.40.51:51413 Korea Telecom KR unknown
–– –– 185.19.104.45:49001 Orceda Limited SC unknown
–– –– 195.154.179.2:26954 Online S.a.s. FR unknown
–– –– 82.11.80.21:6882 Virgin Media Limited GB unknown
–– –– 70.24.55.88:57606 Bell Canada CA unknown
–– –– 78.141.72.219:44969 Orange Slovensko a.s. SK unknown
–– –– 121.167.104.40:51413 Korea Telecom KR unknown
–– –– 24.216.177.231:50321 Charter Communications US unknown
–– –– 144.76.70.220:6881 Hetzner Online GmbH DE unknown
–– –– 62.210.109.160:55011 Online S.a.s. FR unknown
–– –– 128.69.183.197:6889 VimpelCom RU unknown
–– –– 98.148.90.166:24866 Time Warner Cable Internet LLC US unknown
–– –– 5.79.131.87:56106 Intersvyaz-2 JSC RU unknown
–– –– 69.172.180.168:43995 TekSavvy Solutions, Inc. CA unknown
–– –– 90.149.175.177:49159 NextGenTel AS NO unknown
–– –– 67.175.1.70:8999 Comcast Cable Communications, LLC US unknown
–– –– 122.222.15.193:9616 ARTERIA Networks Corporation JP unknown
–– –– 24.175.176.49:6882 Time Warner Cable Internet LLC US unknown
–– –– 82.102.27.195:58300 GB unknown
–– –– 36.227.217.191:16560 Data Communication Business Group TW unknown
–– –– 144.76.60.37:8999 Hetzner Online GmbH DE unknown
–– –– 218.35.185.220:14441 Asia Pacific On-line Service Inc. TW unknown
–– –– 69.120.198.240:63972 Cablevision Systems Corp. US unknown
–– –– 71.190.227.36:8999 MCI Communications Services, Inc. d/b/a Verizon Business US unknown
–– –– 78.118.70.32:6881 SFR FR unknown
–– –– 60.134.41.199:18881 Softbank BB Corp. JP unknown
–– –– 223.176.130.115:29548 Bharti Airtel Ltd. AS for GPRS Service IN unknown
–– –– 85.11.132.251:51326 SOFCOMPANY Ltd BG unknown
–– –– 125.192.23.92:64332 BIGLOBE Inc. JP unknown
2168 updater.exe 143.204.98.159:80 US suspicious
–– –– 77.253.16.97:30746 Netia SA PL unknown
–– –– 176.63.24.200:20683 Liberty Global Operations B.V. HU unknown
–– –– 173.252.53.56:23348 EastLink CA unknown
–– –– 91.211.194.55:51413 Closed Joint Stock Company Russian company RU unknown
–– –– 109.106.142.166:2694 Svyaz-Telecom Ltd. RU unknown
–– –– 93.80.54.142:34768 VimpelCom RU unknown
–– –– 94.181.188.183:6882 JSC ER-Telecom Holding RU unknown
–– –– 178.140.17.78:34478 PJSC Rostelecom RU unknown
–– –– 94.253.19.213:54927 Flex Ltd. RU unknown
–– –– 95.106.186.160:33333 PJSC Rostelecom RU unknown
–– –– 79.243.106.189:58435 Deutsche Telekom AG DE unknown
–– –– 199.229.250.166:27425 Total Server Solutions L.L.C. US unknown
–– –– 46.242.13.10:7083 PJSC Rostelecom RU unknown
–– –– 78.149.25.3:24202 TalkTalk GB unknown
–– –– 176.108.163.130:18872 SKTV Ltd. RU unknown
–– –– 94.23.200.150:51413 OVH SAS FR unknown
–– –– 27.121.213.106:35885 ARTERIA Networks Corporation JP unknown
–– –– 37.187.122.55:6999 OVH SAS FR unknown
–– –– 114.46.37.175:9005 Data Communication Business Group TW unknown
–– –– 178.141.20.17:55432 MTS PJSC RU unknown
–– –– 46.242.9.50:21054 PJSC Rostelecom RU unknown
–– –– 94.63.99.212:25455 Vodafone Portugal - Communicacoes Pessoais S.A. PT unknown
–– –– 148.71.146.239:28893 Vodafone Portugal - Communicacoes Pessoais S.A. PT unknown
–– –– 130.180.208.154:8999 Intertelecom Ltd UA unknown
–– –– 114.45.116.123:62348 Data Communication Business Group TW unknown
–– –– 95.72.170.169:32194 PJSC Rostelecom RU unknown
–– –– 5.135.185.43:52654 OVH SAS FR unknown
–– –– 46.39.108.3:40871 Stockholms Stadsnat AB SE unknown
–– –– 128.199.142.232:51413 Digital Ocean, Inc. SG unknown
–– –– 5.196.69.19:51413 OVH SAS FR unknown
–– –– 185.107.47.194:6881 NForce Entertainment B.V. NL unknown
–– –– 91.181.74.34:2433 Proximus NV BE unknown
–– –– 95.32.166.195:57685 PJSC Rostelecom RU unknown
–– –– 50.116.28.103:51413 Linode, LLC US unknown
–– –– 66.58.196.167:8999 GENERAL COMMUNICATION, INC. US unknown
–– –– 90.79.124.39:51413 Orange FR unknown
–– –– 185.157.245.95:55029 Netrix SAS FR unknown
–– –– 174.89.150.17:6881 Bell Canada CA unknown
–– –– 5.135.190.179:49154 OVH SAS FR unknown
–– –– 79.93.158.203:6881 SFR FR unknown
–– –– 188.133.204.48:49001 PJSC Rostelecom RU unknown
–– –– 37.116.56.238:6881 Vodafone Italia S.p.A. IT unknown
–– –– 123.142.21.42:40908 LG DACOM Corporation KR unknown
–– –– 121.136.80.205:6881 Korea Telecom KR unknown
–– –– 188.227.31.6:51413 OOO DevelopOnBox RU unknown
–– –– 5.79.68.205:51415 LeaseWeb Netherlands B.V. NL unknown
–– –– 80.200.194.43:10637 Proximus NV BE unknown
–– –– 80.116.169.91:62684 Telecom Italia IT unknown
–– –– 46.166.143.68:54537 NForce Entertainment B.V. LU unknown
–– –– 92.58.187.102:34542 Orange Espagne SA ES unknown
–– –– 176.151.158.26:28229 Bouygues Telecom SA FR unknown
–– –– 202.100.51.28:1044 No.31,Jin-rong Street CN unknown
–– –– 184.218.148.119:12745 Sprint US unknown
–– –– 27.207.93.27:21042 CHINA UNICOM China169 Backbone CN unknown
–– –– 118.112.156.214:25864 No.31,Jin-rong Street CN unknown
3088 BitComet.exe 208.100.26.240:80 Steadfast US suspicious
–– –– 121.142.144.14:49160 Korea Telecom KR unknown
–– –– 121.237.243.32:26560 No.31,Jin-rong Street CN unknown
–– –– 178.34.45.191:38122 PJSC Rostelecom RU unknown
–– –– 91.144.200.32:31383 Verdo Tele A/S DK unknown
–– –– 85.184.149.216:36328 Aura Fiber OE A/S DK unknown
–– –– 75.157.70.253:51413 TELUS Communications Inc. CA unknown
–– –– 118.241.8.65:51413 So-net Entertainment Corporation JP unknown
–– –– 185.45.195.167:28032 NForce Entertainment B.V. NL unknown
–– –– 185.162.184.13:50903 Sonassi Ltd NL unknown
–– –– 121.99.200.121:12864 CallPlus Services Limited NZ unknown
–– –– 5.189.183.129:51309 Contabo GmbH DE unknown
3088 BitComet.exe 5.189.166.124:5444 Contabo GmbH DE suspicious
–– –– 175.143.189.194:9469 TM Net, Internet Service Provider MY unknown
–– –– 173.212.202.22:6967 Contabo GmbH DE unknown
–– –– 188.127.133.250:6889 Vac City KabelTV Ltd. HU unknown
–– –– 68.188.21.150:14800 Charter Communications US unknown
–– –– 95.24.126.63:6882 VimpelCom RU unknown
–– –– 173.212.202.22:6915 Contabo GmbH DE unknown
–– –– 188.187.71.143:61645 JSC ER-Telecom Holding RU unknown
–– –– 62.210.204.153:51413 Online S.a.s. FR unknown
–– –– 81.171.31.161:51413 LeaseWeb Netherlands B.V. NL unknown
–– –– 66.172.117.22:6881 LocalTel Communications US unknown
–– –– 222.153.156.175:6881 Spark New Zealand Trading Ltd. NZ unknown
–– –– 151.80.20.111:51413 OVH SAS FR unknown
–– –– 93.100.82.0:25724 SkyNet Ltd. RU unknown
–– –– 87.117.169.204:55463 PJSC Rostelecom RU unknown
–– –– 185.21.217.75:50357 Joshua Peter McQuistan GB unknown
–– –– 109.195.87.222:37092 JSC ER-Telecom Holding RU unknown
–– –– 185.48.37.41:7800 LLC Telecom MPK RU unknown
–– –– 46.166.143.68:64244 NForce Entertainment B.V. LU unknown
–– –– 178.215.88.70:25680 OOO MediaSeti RU unknown
–– –– 79.56.12.128:6881 Telecom Italia IT unknown
–– –– 77.159.84.63:17749 SFR FR unknown
–– –– 86.0.67.29:50321 Virgin Media Limited GB unknown
–– –– 91.228.24.87:33859 Ker Broadband Communications Ltd IE unknown
–– –– 193.9.245.161:2049 VIP-TELECOM-SERVICE Ltd. RU unknown
–– –– 189.39.249.90:14523 Mar Internet Provider Ltda. BR unknown
–– –– 2.181.76.146:59733 Telecommunication Infrastructure Company IR unknown
–– –– 27.147.183.49:14955 Link3 Technologies Ltd. BD unknown
–– –– 141.0.148.122:6881 Hyperoptic Ltd GB unknown
–– –– 62.210.182.160:55140 Online S.a.s. FR unknown
–– –– 109.89.96.127:60334 Brutele SC BE unknown
–– –– 51.175.97.170:6881 Altibox AS NO unknown
–– –– 95.90.89.52:6881 Vodafone Kabel Deutschland GmbH DE unknown
–– –– 99.241.148.48:50321 Rogers Cable Communications Inc. CA unknown
–– –– 95.120.190.75:8621 Telefonica De Espana ES unknown
–– –– 88.250.199.108:6889 Turk Telekom TR unknown
–– –– 112.219.83.77:41094 LG DACOM Corporation KR unknown
–– –– 211.48.53.228:41027 Korea Telecom KR unknown
–– –– 114.199.41.92:40987 GREEN CABLE TELEVISION STATION KR unknown
–– –– 86.123.158.117:6889 RCS & RDS RO unknown
–– –– 213.136.79.238:6971 Contabo GmbH DE unknown
–– –– 185.148.3.200:17475 Magna Capax Finland Oy FI unknown
–– –– 69.132.70.128:6882 Time Warner Cable Internet LLC US unknown
–– –– 119.109.65.29:18061 CHINA UNICOM China169 Backbone CN unknown
–– –– 184.145.130.58:58216 Bell Canada CA unknown
–– –– 95.208.234.111:51413 Kabel BW DE unknown
–– –– 95.76.36.205:23626 Liberty Global Operations B.V. RO unknown
–– –– 210.178.80.251:25254 Korea Telecom KR unknown
–– –– 69.159.146.215:14748 Bell Canada CA unknown
–– –– 178.208.213.78:56898 Gibtelecom Ltd. GI unknown
–– –– 119.196.234.196:6881 Korea Telecom KR unknown
–– –– 173.75.13.239:6881 MCI Communications Services, Inc. d/b/a Verizon Business US unknown
–– –– 85.84.108.64:51413 Euskaltel S.A. ES unknown
–– –– 80.211.211.237:51413 INTERNET CZ, a.s. CZ unknown
–– –– 70.30.54.170:8999 Bell Canada CA unknown
–– –– 191.187.248.222:12936 CLARO S.A. BR unknown
–– –– 108.170.175.199:11864 Start Communications CA unknown
–– –– 78.58.111.199:24881 Telia Lietuva, AB LT unknown
–– –– 70.180.243.154:6882 Cox Communications Inc. US unknown
–– –– 94.13.182.188:50321 Sky UK Limited GB unknown
–– –– 91.239.74.63:51413 PE Vinokurov Anton Vladyslavovych UA unknown
–– –– 93.78.120.2:22177 Volia UA unknown
–– –– 185.45.195.180:28089 NForce Entertainment B.V. NL unknown
–– –– 109.87.215.150:44735 Content Delivery Network Ltd UA unknown
–– –– 178.150.47.161:47806 Content Delivery Network Ltd UA unknown
–– –– 185.107.47.35:21413 NForce Entertainment B.V. NL unknown
–– –– 178.150.13.240:40650 Content Delivery Network Ltd UA unknown
–– –– 93.170.175.104:31984 cable television EKTA - BROVARY Ltd. UA unknown
–– –– 14.47.249.195:50433 Korea Telecom KR unknown
–– –– 37.187.4.119:51413 OVH SAS FR unknown
–– –– 50.100.53.42:12866 Bell Canada CA unknown
–– –– 162.216.16.239:51413 Linode, LLC US unknown
–– –– 213.167.58.194:13911 Digit One LLC RU unknown
–– –– 42.189.30.215:54176 MY unknown
–– –– 198.245.62.144:51413 OVH SAS CA unknown
–– –– 81.162.16.6:43098 RU unknown
–– –– 142.44.137.5:3800 OVH SAS CA unknown
–– –– 208.68.107.136:51413 Loose Foot Computing Limited CA unknown
–– –– 186.36.189.229:50321 Telmex Servicios Empresariales S.A. CL unknown
–– –– 186.156.30.146:11882 VTR BANDA ANCHA S.A. CL unknown
–– –– 62.210.71.209:55000 Online S.a.s. FR unknown
–– –– 190.246.195.38:34470 CABLEVISION S.A. AR unknown
–– –– 79.68.70.91:47592 Tiscali UK Limited GB unknown
–– –– 190.22.155.164:52707 TELEFÓNICA CHILE S.A. CL unknown
–– –– 121.44.45.183:16753 Internode Pty Ltd AU unknown
–– –– 218.110.200.212:45861 So-net Entertainment Corporation JP unknown
–– –– 151.80.45.107:6881 OVH SAS FR unknown
–– –– 189.18.217.195:43895 TELEFÔNICA BRASIL S.A BR unknown
–– –– 185.162.184.4:55968 Sonassi Ltd NL unknown
–– –– 83.149.125.19:30192 LeaseWeb Netherlands B.V. NL unknown
–– –– 62.210.148.234:55051 Online S.a.s. FR unknown
–– –– 79.167.104.137:63808 Vodafone-panafon Hellenic Telecommunications Company SA GR unknown
–– –– 37.48.95.41:53333 LeaseWeb Netherlands B.V. NL unknown
–– –– 185.21.217.61:65150 Joshua Peter McQuistan GB unknown
–– –– 217.208.87.104:6889 Telia Company AB SE unknown
–– –– 5.189.95.182:51413 LLC KomTehCentr RU unknown
–– –– 83.58.48.20:6881 Telefonica De Espana ES unknown
–– –– 99.228.38.210:6889 Rogers Cable Communications Inc. CA unknown
–– –– 114.33.147.62:16242 Data Communication Business Group TW unknown
–– –– 95.28.184.184:10030 VimpelCom RU unknown
–– –– 89.28.162.47:40678 KVS Ltd RU unknown
–– –– 5.104.50.156:53495 TRK Metro LLC UA unknown
–– –– 2.93.95.239:19267 VimpelCom RU unknown
–– –– 94.188.52.78:6711 Net By Net Holding LLC RU unknown
–– –– 82.9.107.226:6881 Virgin Media Limited GB unknown
–– –– 37.145.125.249:27623 VimpelCom RU unknown
–– –– 46.72.37.166:17591 Net By Net Holding LLC RU unknown
–– –– 185.68.117.222:16662 Rial Com JSC RU unknown
–– –– 95.54.206.244:31585 PJSC Rostelecom RU unknown
–– –– 178.167.94.8:6881 Flex Ltd. RU unknown
–– –– 109.86.236.208:46291 Content Delivery Network Ltd UA unknown
–– –– 94.242.209.213:62930 root SA LU unknown
–– –– 176.15.129.80:22219 VimpelCom RU unknown
–– –– 188.115.145.12:14835 TeNeT Scientific Production Enterprise LLC UA unknown
–– –– 37.203.23.10:36377 TeNeT Scientific Production Enterprise LLC UA unknown
–– –– 176.193.14.129:61326 Net By Net Holding LLC RU unknown
–– –– 46.188.67.175:58099 2COM Co Ltd. RU unknown
–– –– 136.169.135.33:13757 OJSC Ufanet RU unknown
–– –– 37.150.217.176:35482 JSC Kazakhtelecom KZ unknown
–– –– 2.134.224.253:51941 JSC Kazakhtelecom KZ unknown
–– –– 176.108.171.19:23216 SKTV Ltd. RU unknown
–– –– 94.241.26.25:60928 PJSC Rostelecom RU unknown
–– –– 178.45.201.201:27245 PJSC Rostelecom RU unknown
–– –– 91.225.73.117:36656 Teleradiokompaniya Vizit-A Limited Liability Company UA unknown
–– –– 5.141.188.182:19301 PJSC Rostelecom RU unknown
–– –– 95.25.190.25:56492 VimpelCom RU unknown
–– –– 195.18.60.159:6881 PJSC Rostelecom RU unknown
–– –– 94.181.156.45:12129 JSC ER-Telecom Holding RU unknown
–– –– 46.61.42.126:23336 PJSC Rostelecom RU unknown
–– –– 46.53.240.31:4359 BY unknown
–– –– 187.35.204.188:31162 TELEFÔNICA BRASIL S.A BR unknown
–– –– 128.69.190.33:41208 VimpelCom RU unknown
–– –– 91.219.199.104:40653 Private Enterprise Tron Vitaliy Vladimirovich UA unknown
–– –– 46.138.167.102:29375 OJS Moscow city telephone network RU unknown
–– –– 188.170.196.140:33374 PJSC MegaFon RU unknown
–– –– 84.42.76.205:4673 PJSC Rostelecom RU unknown
–– –– 190.18.79.103:51370 CABLEVISION S.A. AR unknown
–– –– 93.4.196.182:6881 SFR FR unknown
–– –– 71.81.94.195:8999 Charter Communications US unknown
–– –– 186.228.160.113:62441 Tim Celular S.A. BR unknown
–– –– 177.149.199.78:51413 Tim Celular S.A. BR unknown
–– –– 81.36.43.72:36415 Telefonica De Espana ES unknown
–– –– 85.191.201.16:58946 EG A/S DK unknown
–– –– 177.46.81.54:14997 BR unknown
–– –– 78.189.86.92:19133 Turk Telekom TR unknown
–– –– 176.59.195.138:13906 T2 Mobile LLC RU unknown
–– –– 94.180.32.68:51277 JSC ER-Telecom Holding RU unknown
–– –– 176.15.228.32:26992 VimpelCom RU unknown
–– –– 95.188.130.114:37958 PJSC Rostelecom RU unknown
–– –– 185.116.231.70:24579 LLC NOVA Telecom RU unknown
–– –– 93.73.192.173:53724 Volia UA unknown
–– –– 88.200.214.250:48953 PJSC Rostelecom RU unknown
–– –– 173.172.186.1:14001 Time Warner Cable Internet LLC US unknown
–– –– 185.40.51.159:54846 UA unknown
–– –– 2.132.160.108:53065 JSC Kazakhtelecom KZ unknown
–– –– 217.8.92.195:48302 Net By Net Holding LLC RU unknown
–– –– 71.130.14.7:37412 AT&T Services, Inc. US unknown
–– –– 195.154.164.216:6881 Online S.a.s. FR unknown
–– –– 176.193.3.65:42337 Net By Net Holding LLC RU unknown
–– –– 31.181.113.175:39581 PJSC Rostelecom RU unknown
–– –– 37.122.37.47:45435 PJSC Bashinformsvyaz RU unknown
–– –– 95.179.4.170:10091 PJSC Rostelecom RU unknown
–– –– 176.194.130.200:43681 Net By Net Holding LLC RU unknown
–– –– 95.79.133.67:41058 JSC ER-Telecom Holding RU unknown
–– –– 93.124.34.108:49054 PJSC Rostelecom RU unknown
–– –– 106.181.150.104:60968 KDDI CORPORATION JP unknown
–– –– 178.211.189.112:20643 INTERRA telecommunications group, Ltd. RU unknown
–– –– 37.114.28.8:60216 Telecom-MK Ltd. RU unknown
–– –– 88.147.249.248:24629 PJSC Rostelecom RU unknown
–– –– 91.143.142.222:27294 Regionset Ltd RU unknown
–– –– 178.57.49.157:19158 OJSC Kostroma Municipal Telephone Network RU unknown
–– –– 2.94.54.32:18584 VimpelCom RU unknown
–– –– 178.91.122.213:17131 JSC Kazakhtelecom KZ unknown
–– –– 46.0.12.103:35354 JSC ER-Telecom Holding RU unknown
–– –– 89.129.63.98:17964 Orange Espagne SA ES unknown
–– –– 41.217.112.95:6881 Spectranet NG unknown
–– –– 78.107.252.6:61197 VimpelCom RU unknown
–– –– 31.180.247.210:36671 PJSC Rostelecom RU unknown
–– –– 171.51.140.118:16742 Bharti Airtel Ltd. AS for GPRS Service IN unknown
–– –– 2.95.92.153:51750 PVimpelCom RU unknown
–– –– 95.29.187.166:50793 VimpelCom RU unknown
–– –– 95.179.43.67:13386 PJSC Rostelecom RU unknown
–– –– 46.35.248.229:39536 Lancom Ltd. UA unknown
–– –– 5.143.205.119:42593 PJSC Rostelecom RU unknown
–– –– 37.26.53.225:39553 Uninet AZ unknown
–– –– 91.122.254.113:25841 PJSC Rostelecom RU unknown
–– –– 176.99.100.181:65323 FOP Sinev Maksim Viktorovich UA unknown
–– –– 46.175.160.38:61543 Little Enterprise Independent Television Company Norma-4 LTD UA unknown
–– –– 85.93.58.94:4457 PJSC Rostelecom RU unknown
–– –– 95.72.222.45:12694 PJSC Rostelecom RU unknown
–– –– 213.87.127.226:7800 MTS PJSC RU unknown
–– –– 58.104.234.21:31431 Microplex PTY LTD AU unknown
–– –– 86.225.181.175:6346 Orange FR unknown
–– –– 82.40.37.138:6881 Virgin Media Limited GB unknown
–– –– 188.243.36.124:48091 SkyNet Ltd. RU unknown
–– –– 128.71.21.118:36629 PVimpelCom RU unknown
–– –– 5.166.22.210:38349 JSC ER-Telecom Holding RU unknown
–– –– 5.18.204.13:4096 Perspectiva Ltd. RU unknown
–– –– 46.191.161.201:54791 OJSC Ufanet RU unknown
–– –– 109.63.201.138:42588 Net By Net Holding LLC RU unknown
–– –– 95.106.157.36:34388 PJSC Rostelecom RU unknown
–– –– 2.93.3.67:62421 VimpelCom RU unknown
–– –– 95.27.244.176:13160 VimpelCom RU unknown
–– –– 81.30.119.60:37539 MIR-Telecom LLC RU unknown
–– –– 79.164.91.219:38781 Central Telegraph Public Joint-stock Company RU unknown
–– –– 94.75.165.225:32055 PJSC Rostelecom RU unknown
–– –– 46.185.55.97:24058 Kyivstar PJSC UA unknown
–– –– 73.123.112.87:42259 Comcast Cable Communications, LLC US unknown
–– –– 178.44.160.68:49001 PJSC Rostelecom RU unknown
–– –– 80.151.144.62:55501 Deutsche Telekom AG DE unknown
–– –– 178.65.125.162:6881 PJSC Rostelecom RU unknown
–– –– 93.36.217.248:34668 Fastweb IT unknown
–– –– 207.89.23.91:36881 Micfo, LLC. US unknown
–– –– 201.180.156.126:40233 Telefonica de Argentina AR unknown
–– –– 185.109.86.64:49001 Hans Fredrik Lennart Neij SE unknown
–– –– 163.172.222.244:51413 Online S.a.s. NL unknown
–– –– 91.121.177.120:51413 OVH SAS FR unknown
–– –– 93.191.14.102:16748 LLC trc Fiord RU unknown
–– –– 37.81.25.230:55993 Deutsche Telekom AG DE unknown
–– –– 43.225.60.6:33597 The Signal Co. Wireless AU unknown
–– –– 69.120.156.14:48999 Cablevision Systems Corp. US unknown
–– –– 73.93.130.234:6889 Comcast Cable Communications, LLC US unknown
–– –– 109.199.44.204:49900 ANTENNA HUNGARIA Magyar Musorszoro es Radiohirkozlesi Zartkoruen Mukodo Reszvenytarsasag HU unknown
–– –– 178.164.240.141:30561 DIGI Tavkozlesi es Szolgaltato Kft. HU unknown
–– –– 79.122.21.94:19500 Magyar Telekom plc. HU unknown
–– –– 84.236.0.134:45027 DIGI Tavkozlesi es Szolgaltato Kft. HU unknown
–– –– 193.131.100.109:8999 3c. Kft. HU unknown
–– –– 84.236.80.3:8999 DIGI Tavkozlesi es Szolgaltato Kft. HU unknown
–– –– 178.164.181.133:60028 DIGI Tavkozlesi es Szolgaltato Kft. HU unknown
–– –– 78.92.16.89:45490 Magyar Telekom plc. HU unknown
–– –– 91.205.156.10:51413 Webzilla B.V. UA unknown
–– –– 37.187.102.17:51413 OVH SAS FR unknown
–– –– 164.132.42.187:51413 OVH SAS FR unknown
–– –– 31.179.93.168:17932 Liberty Global Operations B.V. PL unknown
–– –– 142.114.97.78:50321 Bell Canada CA unknown
–– –– 109.228.247.121:29518 Milleni.com TR unknown
–– –– 110.145.108.91:20179 Telstra Pty Ltd AU unknown
–– –– 108.41.130.221:6881 MCI Communications Services, Inc. d/b/a Verizon Business US unknown
–– –– 5.39.93.205:51413 OVH SAS FR unknown
–– –– 83.226.234.48:6889 Telenor Norge AS SE unknown
–– –– 67.168.222.82:52888 Comcast Cable Communications, LLC US unknown
–– –– 86.21.48.210:50321 Virgin Media Limited GB unknown
–– –– 77.49.218.143:42154 Forthnet GR unknown
–– –– 78.228.230.239:20425 Free SAS FR unknown
–– –– 71.217.142.74:6881 Qwest Communications Company, LLC US unknown
–– –– 188.232.219.73:51413 JSC ER-Telecom Holding RU unknown
–– –– 77.237.133.46:1134 WMS s.r.o. CZ unknown
–– –– 151.24.200.106:6881 Wind Telecomunicazioni SpA IT unknown
–– –– 80.56.192.62:6889 Liberty Global Operations B.V. NL unknown
–– –– 195.184.26.146:41773 Invitech Megoldasok Zrt. HU unknown
–– –– 108.60.212.8:15717 EBL Global Networks, Inc. US unknown
–– –– 125.99.160.252:10227 Hathway IP Over Cable Internet IN unknown
–– –– 46.249.178.22:61865 Splius, Uab LT unknown
–– –– 46.241.58.251:59664 JSC Zap-Sib TransTeleCom, Novosibirsk RU unknown
–– –– 93.81.140.28:59089 VimpelCom RU unknown
–– –– 5.197.226.163:11131 AG Telecom LTD. AZ unknown
–– –– 84.53.198.146:18306 PJSC Rostelecom RU unknown
–– –– 5.35.122.252:63007 LLC Multiscan RU unknown
–– –– 64.180.71.230:25477 TELUS Communications Inc. CA unknown
–– –– 62.122.60.168:46895 OOO NPO Intermet UA unknown
–– –– 82.73.29.65:26632 Ziggo NL unknown
–– –– 31.27.157.220:6881 Vodafone Italia S.p.A. IT unknown
–– –– 213.136.79.7:6890 Contabo GmbH DE unknown
–– –– 86.219.102.168:52301 Orange FR unknown
–– –– 49.149.15.46:16758 Philippine Long Distance Telephone Company PH unknown
–– –– 173.212.202.22:51475 Contabo GmbH DE unknown
–– –– 93.140.35.239:6889 Hrvatski Telekom d.d. HR unknown
–– –– 86.138.177.54:50321 British Telecommunications PLC GB unknown
–– –– 114.32.181.229:6881 Data Communication Business Group TW unknown
–– –– 93.103.205.133:21897 T-2, d.o.o. SI unknown
–– –– 109.252.68.107:1335 OJS Moscow city telephone network RU unknown
–– –– 217.146.110.238:49341 Merula Limited GB unknown
–– –– 121.168.181.152:51413 Korea Telecom KR unknown
–– –– 71.229.157.94:7760 Comcast Cable Communications, LLC US unknown
–– –– 219.91.15.114:24034 Asia Pacific On-line Service Inc. TW unknown
–– –– 221.161.46.175:41215 Korea Telecom KR unknown
–– –– 93.176.159.167:5460 Xtra Telecom S.A. ES unknown
–– –– 112.169.210.209:6889 Korea Telecom KR unknown
–– –– 144.172.68.130:51413 Psychz Networks US unknown
–– –– 27.104.129.191:50321 MobileOne Ltd. Mobile/Internet Service Provider Singapore SG unknown
–– –– 222.164.1.245:14059 Starhub Internet Pte Ltd SG unknown
–– –– 14.198.76.70:7702 Hong Kong Broadband Network Ltd. HK unknown
–– –– 80.151.57.155:56133 Deutsche Telekom AG DE unknown
–– –– 180.164.18.208:1812 China Telecom (Group) CN unknown
–– –– 1.173.69.118:6881 Data Communication Business Group TW unknown
–– –– 109.206.49.230:58948 Private Joint Stock Company datagroup UA unknown
–– –– 200.30.250.233:25671 VTR BANDA ANCHA S.A. CL unknown
–– –– 151.177.96.24:50321 Com Hem AB SE unknown
–– –– 149.62.50.249:33957 Limited liability company New Line RU unknown
–– –– 71.84.116.74:43611 Charter Communications US unknown
–– –– 60.112.208.197:7521 Softbank BB Corp. JP unknown
–– –– 94.23.197.142:51413 OVH SAS FR unknown
–– –– 213.136.79.238:33440 Contabo GmbH DE unknown
–– –– 173.212.202.248:51483 Contabo GmbH DE unknown
–– –– 118.33.29.191:6889 Korea Telecom KR unknown
–– –– 176.15.64.132:22586 VimpelCom RU unknown
–– –– 74.192.187.230:13570 Suddenlink Communications US unknown
–– –– 92.191.58.151:52021 Orange Espagne S.A.U. ES unknown
–– –– 161.22.127.109:64216 Canal + Telecom SAS GF unknown
–– –– 176.103.209.157:25760 Online Ukraine Ltd. UA unknown
–– –– 37.48.118.94:50068 LeaseWeb Netherlands B.V. NL unknown
–– –– 5.19.140.156:27556 Perspectiva Ltd. RU unknown
–– –– 213.136.82.39:59176 Contabo GmbH DE unknown
–– –– 168.235.74.52:51413 RamNode LLC US unknown
–– –– 31.208.90.199:6881 Bredband2 AB SE unknown
–– –– 5.189.188.23:6946 Contabo GmbH DE unknown
–– –– 82.146.0.167:13224 Vivacom BG unknown
–– –– 213.178.18.101:6889 Hees riconet GmbH DE unknown
–– –– 77.251.218.101:6889 Liberty Global Operations B.V. NL unknown
–– –– 59.17.229.37:6889 Korea Telecom KR unknown
–– –– 73.90.168.64:7316 Comcast Cable Communications, LLC US unknown
–– –– 75.50.84.26:6889 AT&T Services, Inc. US unknown
–– –– 94.207.184.227:6881 Emirates Integrated Telecommunications Company PJSC (EITC-DU) AE unknown
–– –– 84.48.237.35:46856 NextGenTel AS NO unknown
–– –– 176.37.122.199:49001 Lanet Network Ltd UA unknown
–– –– 115.187.183.19:40803 Symbio Networks AU unknown
–– –– 90.46.106.174:6781 Orange FR unknown
–– –– 114.139.151.240:15653 No.31,Jin-rong Street CN unknown
–– –– 222.129.39.104:1024 China Unicom Beijing Province Network CN unknown
–– –– 223.139.115.236:3535 Long Distance & Mobile Business Group TW unknown
–– –– 185.212.128.36:54 Virtual Trade Ltd NL unknown
–– –– 121.111.81.231:16887 KDDI CORPORATION JP unknown
–– –– 27.83.33.196:61137 KDDI CORPORATION JP unknown
–– –– 2.154.240.157:51413 Vodafone Spain ES unknown
–– –– 91.121.109.138:51413 OVH SAS FR unknown
–– –– 62.210.69.229:55100 Online S.a.s. FR unknown
–– –– 76.17.160.110:55155 Comcast Cable Communications, LLC US unknown
–– –– 108.191.150.84:6889 BRIGHT HOUSE NETWORKS, LLC US unknown
–– –– 103.252.202.66:43483 MyRepublic Ltd. SG unknown
–– –– 124.56.81.145:7683 LG POWERCOMM KR unknown
–– –– 180.143.52.5:8884 No.31,Jin-rong Street CN unknown
–– –– 124.5.33.106:41362 DLIVE KR unknown
–– –– 110.12.6.7:41199 SK Broadband Co Ltd KR unknown
–– –– 112.150.219.220:64049 LG POWERCOMM KR unknown
–– –– 211.37.68.164:41646 SK Broadband Co Ltd KR unknown
–– –– 49.171.28.5:46900 LG POWERCOMM KR unknown
–– –– 180.228.136.226:58122 LG POWERCOMM KR unknown
–– –– 118.219.22.220:41015 SK Broadband Co Ltd KR unknown
–– –– 61.106.188.32:51074 Korea Telecom KR unknown
–– –– 58.226.5.101:52552 SK Broadband Co Ltd KR unknown
–– –– 183.196.217.251:24045 Hebei Mobile Communication Company Limited CN unknown
–– –– 114.201.140.126:40969 SK Broadband Co Ltd KR unknown
–– –– 59.7.18.172:40484 Korea Telecom KR unknown
–– –– 175.197.234.107:53503 Korea Telecom KR unknown
–– –– 1.11.245.118:41047 CJ-HELLOVISION KR unknown
–– –– 101.184.28.169:40684 Telstra Pty Ltd AU unknown
–– –– 185.107.95.66:21010 NForce Entertainment B.V. NL unknown
–– –– 121.180.163.107:44531 Korea Telecom KR unknown
–– –– 5.103.132.172:51413 FIBIA P/S DK unknown
–– –– 201.173.172.148:50321 Television Internacional, S.A. de C.V. MX unknown
–– –– 1.34.9.118:51413 Data Communication Business Group TW unknown
–– –– 223.134.77.213:13590 So-net Entertainment Corporation JP unknown
–– –– 175.115.215.111:52413 SK Broadband Co Ltd KR unknown
–– –– 119.207.219.18:6881 Korea Telecom KR unknown
–– –– 183.99.21.224:49664 Korea Telecom KR unknown
–– –– 112.163.205.126:58415 Korea Telecom KR unknown
–– –– 220.116.111.151:49769 Korea Telecom KR unknown
–– –– 115.144.244.105:10516 Korea Telecom KR unknown
–– –– 114.205.176.232:51413 SK Broadband Co Ltd KR unknown
–– –– 210.103.125.138:51621 Korea Telecom KR unknown
–– –– 211.243.169.39:40876 SK Broadband Co Ltd KR unknown
–– –– 210.100.222.207:19278 Korea Telecom KR unknown
–– –– 1.250.193.105:40931 SK Broadband Co Ltd KR unknown
–– –– 124.5.145.72:18164 DLIVE KR unknown
–– –– 193.232.183.47:18059 RU unknown
–– –– 121.138.68.162:60317 Korea Telecom KR unknown
–– –– 66.254.106.61:6882 Reflected Networks, Inc. US unknown
–– –– 175.113.171.219:49549 SK Broadband Co Ltd KR unknown
–– –– 121.172.152.130:51413 Korea Telecom KR unknown
–– –– 59.22.77.5:58689 Korea Telecom KR unknown
–– –– 1.215.239.242:40772 LG DACOM Corporation KR unknown
–– –– 222.237.82.202:40993 SK Broadband Co Ltd KR unknown
–– –– 121.137.158.85:58204 Korea Telecom KR unknown
–– –– 60.171.117.97:7588 No.31,Jin-rong Street CN unknown
–– –– 78.157.177.6:6881 SilesNet s.r.o. CZ unknown
–– –– 79.117.195.85:12721 RCS & RDS RO unknown
–– –– 98.28.164.146:46163 Time Warner Cable Internet LLC US unknown
–– –– 72.74.144.153:51413 MCI Communications Services, Inc. d/b/a Verizon Business US unknown
–– –– 93.117.84.54:8621 Orange Espagne SA ES unknown
–– –– 188.65.70.155:51413 SatTel Corporation, Ltd. RU unknown
–– –– 201.8.144.147:10000 Telemar Norte Leste S.A. BR unknown
–– –– 174.119.176.241:23090 Rogers Cable Communications Inc. CA unknown
–– –– 78.83.207.117:55328 BG unknown
–– –– 37.187.96.226:61938 OVH SAS FR unknown
–– –– 95.111.37.14:56206 Mobiltel Ead BG unknown
–– –– 175.139.73.129:31413 TM Net, Internet Service Provider MY unknown
–– –– 1.234.141.92:51413 SK Broadband Co Ltd KR unknown
–– –– 14.53.188.193:8999 Korea Telecom KR unknown
–– –– 175.211.105.134:59257 Korea Telecom KR unknown
–– –– 211.184.134.201:52086 Korea Telecom KR unknown