General Info

File name

setup-lightshot.exe

Full analysis
https://app.any.run/tasks/4e88b4ad-30ba-4a27-8a8c-e0a95ba46814
Verdict
Malicious activity
Analysis date
7/18/2019, 15:09:12
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

18a6e22d8f806f6757d5796fe08b37f0

SHA1

6a99d9bac7b24d1c7843e9e8ae6bff1968ad0fbe

SHA256

455b17124a474bfa512580ba9bcd275dc8e1119482ad604b83b3cb5611a6f73f

SSDEEP

49152:cZs5nVhJbEh/kstfItGWY1XF4msYrDvxDIskHUlx88vKdbUM:is5nVnbYMQAtGWonb5okeQMP

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (75.0.3770.100)
  • Google Update Helper (1.3.34.7)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.7.2 (4.7.03062)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (14.21.27702.2)
  • Microsoft Visual C++ 2019 X86 Additional Runtime - 14.21.27702 (14.21.27702)
  • Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.21.27702 (14.21.27702)
  • Mozilla Firefox 67.0.4 (x86 en-US) (67.0.4)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • Update for Microsoft .NET Framework 4.7.2 (KB4087364) (1)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB4019990
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Application was dropped or rewritten from another process
  • Updater.exe (PID: 2600)
  • Updater.exe (PID: 3972)
  • updater.exe (PID: 2228)
  • updater.exe (PID: 2988)
  • Updater.exe (PID: 3304)
  • Lightshot.exe (PID: 3936)
  • updater.exe (PID: 2364)
  • Lightshot.exe (PID: 2468)
  • Lightshot.exe (PID: 3676)
  • Lightshot.exe (PID: 2956)
  • updater.exe (PID: 3668)
  • Lightshot.exe (PID: 2752)
  • Updater.exe (PID: 3040)
  • Lightshot.exe (PID: 896)
  • Updater.exe (PID: 2868)
Loads the Task Scheduler DLL interface
  • updater.exe (PID: 2988)
  • Updater.exe (PID: 2868)
Changes settings of System certificates
  • Updater.exe (PID: 2600)
Starts NET.EXE for service management
  • setupupdater.tmp (PID: 1952)
Changes the autorun value in the registry
  • setup-lightshot.tmp (PID: 2788)
Loads dropped or rewritten executable
  • Lightshot.exe (PID: 2752)
Creates files in the user directory
  • Updater.exe (PID: 2600)
  • Updater.exe (PID: 3304)
Creates files in the Windows directory
  • updater.exe (PID: 2988)
  • Updater.exe (PID: 2868)
Executed via COM
  • FlashUtil32_26_0_0_131_ActiveX.exe (PID: 2396)
Adds / modifies Windows certificates
  • Updater.exe (PID: 2600)
Starts Internet Explorer
  • setup-lightshot.tmp (PID: 2608)
Creates files in the program directory
  • Updater.exe (PID: 3304)
Executable content was dropped or overwritten
  • setup-lightshot.exe (PID: 3748)
  • setup-lightshot.tmp (PID: 2788)
  • setup-lightshot.exe (PID: 2164)
  • setupupdater.tmp (PID: 1952)
  • setupupdater.exe (PID: 1312)
Reads Windows owner or organization settings
  • setupupdater.tmp (PID: 1952)
  • setup-lightshot.tmp (PID: 2788)
Uses TASKKILL.EXE to kill process
  • setup-lightshot.tmp (PID: 2788)
Reads the Windows organization settings
  • setupupdater.tmp (PID: 1952)
  • setup-lightshot.tmp (PID: 2788)
Manual execution by user
  • Lightshot.exe (PID: 2956)
  • Lightshot.exe (PID: 3936)
Creates files in the user directory
  • iexplore.exe (PID: 2416)
  • FlashUtil32_26_0_0_131_ActiveX.exe (PID: 2396)
Reads Internet Cache Settings
  • iexplore.exe (PID: 3072)
  • iexplore.exe (PID: 2416)
Reads internet explorer settings
  • iexplore.exe (PID: 2416)
Application launched itself
  • iexplore.exe (PID: 3072)
Reads settings of System Certificates
  • iexplore.exe (PID: 3072)
Application was dropped or rewritten from another process
  • setupupdater.tmp (PID: 1952)
  • setupupdater.exe (PID: 1312)
  • setup-lightshot.tmp (PID: 2788)
  • setup-lightshot.tmp (PID: 2608)
Creates a software uninstall entry
  • setup-lightshot.tmp (PID: 2788)
Creates files in the program directory
  • setup-lightshot.tmp (PID: 2788)
  • setupupdater.tmp (PID: 1952)
Changes internet zones settings
  • iexplore.exe (PID: 3072)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable Delphi generic (57.2%)
.exe
|   Win32 Executable (generic) (18.2%)
.exe
|   Win16/32 Executable Delphi generic (8.3%)
.exe
|   Generic Win/DOS Executable (8%)
.exe
|   DOS Executable Generic (8%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2016:04:06 16:39:04+02:00
PEType:
PE32
LinkerVersion:
2.25
CodeSize:
66560
InitializedDataSize:
419328
UninitializedDataSize:
null
EntryPoint:
0x117dc
OSVersion:
5
ImageVersion:
6
SubsystemVersion:
5
Subsystem:
Windows GUI
FileVersionNumber:
5.4.0.35
ProductVersionNumber:
5.4.0.35
FileFlagsMask:
0x003f
FileFlags:
(none)
FileOS:
Win32
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
Neutral
CharacterSet:
Unicode
Comments:
This installation was built with Inno Setup.
CompanyName:
Skillbrains
FileDescription:
lightshot Setup
FileVersion:
5.4.0.35
LegalCopyright:
ProductName:
lightshot
ProductVersion:
5.4.0.35
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
06-Apr-2016 14:39:04
Detected languages
English - United States
Comments:
This installation was built with Inno Setup.
CompanyName:
Skillbrains
FileDescription:
lightshot Setup
FileVersion:
5.4.0.35
LegalCopyright:
null
ProductName:
lightshot
ProductVersion:
5.4.0.35
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0050
Pages in file:
0x0002
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x000F
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x001A
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x00000100
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
8
Time date stamp:
06-Apr-2016 14:39:04
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x0000F244 0x0000F400 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.37521
.itext 0x00011000 0x00000F64 0x00001000 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 5.7322
.data 0x00012000 0x00000C88 0x00000E00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 2.29672
.bss 0x00013000 0x000056BC 0x00000000 IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.idata 0x00019000 0x00000E04 0x00001000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 4.59781
.tls 0x0001A000 0x00000008 0x00000000 IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.rdata 0x0001B000 0x00000018 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 0.204488
.rsrc 0x0001C000 0x00064408 0x00064600 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 4.90551
Resources
1

2

3

4

5

6

4091

4092

4093

4094

4095

4096

11111

CHARTABLE

DVCLAL

PACKAGEINFO

MAINICON

Imports
    oleaut32.dll

    advapi32.dll

    user32.dll

    kernel32.dll

    comctl32.dll

Exports

    No exports.

Screenshots

Processes

Total processes
67
Monitored processes
28
Malicious processes
5
Suspicious processes
8

Behavior graph

+
drop and start start drop and start drop and start drop and start drop and start drop and start drop and start setup-lightshot.exe setup-lightshot.tmp no specs setup-lightshot.exe setup-lightshot.tmp taskkill.exe no specs taskkill.exe no specs lightshot.exe no specs lightshot.exe no specs setupupdater.exe setupupdater.tmp net.exe no specs net1.exe no specs updater.exe no specs updater.exe no specs updater.exe updater.exe no specs updater.exe updater.exe no specs updater.exe no specs updater.exe no specs updater.exe iexplore.exe iexplore.exe flashutil32_26_0_0_131_activex.exe no specs lightshot.exe no specs lightshot.exe no specs lightshot.exe no specs lightshot.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3748
CMD
"C:\Users\admin\AppData\Local\Temp\setup-lightshot.exe"
Path
C:\Users\admin\AppData\Local\Temp\setup-lightshot.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Skillbrains
Description
lightshot Setup
Version
5.4.0.35
Modules
Image
c:\users\admin\appdata\local\temp\setup-lightshot.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\version.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\shell32.dll
c:\users\admin\appdata\local\temp\is-t8lrp.tmp\setup-lightshot.tmp

PID
2608
CMD
"C:\Users\admin\AppData\Local\Temp\is-T8LRP.tmp\setup-lightshot.tmp" /SL5="$60128,2096383,486912,C:\Users\admin\AppData\Local\Temp\setup-lightshot.exe"
Path
C:\Users\admin\AppData\Local\Temp\is-T8LRP.tmp\setup-lightshot.tmp
Indicators
No indicators
Parent process
setup-lightshot.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\users\admin\appdata\local\temp\is-t8lrp.tmp\setup-lightshot.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shdocvw.dll
c:\program files\skillbrains\lightshot\lightshot.exe
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\program files\internet explorer\iexplore.exe

PID
2164
CMD
"C:\Users\admin\AppData\Local\Temp\setup-lightshot.exe" /SPAWNWND=$5018C /NOTIFYWND=$60128
Path
C:\Users\admin\AppData\Local\Temp\setup-lightshot.exe
Indicators
Parent process
setup-lightshot.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Skillbrains
Description
lightshot Setup
Version
5.4.0.35
Modules
Image
c:\users\admin\appdata\local\temp\setup-lightshot.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\version.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\shell32.dll
c:\users\admin\appdata\local\temp\is-b88g4.tmp\setup-lightshot.tmp

PID
2788
CMD
"C:\Users\admin\AppData\Local\Temp\is-B88G4.tmp\setup-lightshot.tmp" /SL5="$70156,2096383,486912,C:\Users\admin\AppData\Local\Temp\setup-lightshot.exe" /SPAWNWND=$5018C /NOTIFYWND=$60128
Path
C:\Users\admin\AppData\Local\Temp\is-B88G4.tmp\setup-lightshot.tmp
Indicators
Parent process
setup-lightshot.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\users\admin\appdata\local\temp\is-b88g4.tmp\setup-lightshot.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\imageres.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\msftedit.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\program files\skillbrains\lightshot\unins000.exe
c:\program files\skillbrains\lightshot\lightshot.exe
c:\windows\system32\shdocvw.dll
c:\users\admin\appdata\local\temp\is-3fi61.tmp\setupupdater.exe
c:\program files\skillbrains\updater\updater.exe
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\netutils.dll

PID
3064
CMD
"C:\Windows\System32\taskkill.exe" /f /im lightshot.exe
Path
C:\Windows\System32\taskkill.exe
Indicators
No indicators
Parent process
setup-lightshot.tmp
User
admin
Integrity Level
HIGH
Exit code
128
Version:
Company
Microsoft Corporation
Description
Terminates Processes
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\taskkill.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\winsta.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll

PID
2504
CMD
"taskkill.exe" /F /IM lightshot.exe
Path
C:\Windows\system32\taskkill.exe
Indicators
No indicators
Parent process
setup-lightshot.tmp
User
admin
Integrity Level
HIGH
Exit code
128
Version:
Company
Microsoft Corporation
Description
Terminates Processes
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\taskkill.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\winsta.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll

PID
896
CMD
"C:\Program Files\Skillbrains\lightshot\Lightshot.exe"
Path
C:\Program Files\Skillbrains\lightshot\Lightshot.exe
Indicators
No indicators
Parent process
setup-lightshot.tmp
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Starter Module
Version
1, 0, 0, 1
Modules
Image
c:\program files\skillbrains\lightshot\lightshot.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\apphelp.dll
c:\program files\skillbrains\lightshot\5.4.0.35\lightshot.exe

PID
2752
CMD
"C:\Program Files\Skillbrains\lightshot\5.4.0.35\Lightshot.exe"
Path
C:\Program Files\Skillbrains\lightshot\5.4.0.35\Lightshot.exe
Indicators
No indicators
Parent process
Lightshot.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Skillbrains
Description
Lightshot
Version
5.4.0.1
Modules
Image
c:\program files\skillbrains\lightshot\5.4.0.35\lightshot.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\program files\skillbrains\lightshot\5.4.0.35\lightshot.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\d3d9.dll
c:\windows\system32\d3d8thk.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\windowscodecs.dll
c:\program files\skillbrains\lightshot\5.4.0.35\uploader.dll

PID
1312
CMD
"C:\Users\admin\AppData\Local\Temp\is-3FI61.tmp\setupupdater.exe" /verysilent
Path
C:\Users\admin\AppData\Local\Temp\is-3FI61.tmp\setupupdater.exe
Indicators
Parent process
setup-lightshot.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
updater Setup
Version
1.8.0.0
Modules
Image
c:\users\admin\appdata\local\temp\is-3fi61.tmp\setupupdater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\version.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\shell32.dll
c:\users\admin\appdata\local\temp\is-73ps6.tmp\setupupdater.tmp

PID
1952
CMD
"C:\Users\admin\AppData\Local\Temp\is-73PS6.tmp\setupupdater.tmp" /SL5="$30154,490430,120832,C:\Users\admin\AppData\Local\Temp\is-3FI61.tmp\setupupdater.exe" /verysilent
Path
C:\Users\admin\AppData\Local\Temp\is-73PS6.tmp\setupupdater.tmp
Indicators
Parent process
setupupdater.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\users\admin\appdata\local\temp\is-73ps6.tmp\setupupdater.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\imageres.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\net.exe
c:\program files\skillbrains\updater\1.8.0.0\updater.exe
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\program files\skillbrains\updater\updater.exe

PID
3392
CMD
"C:\Windows\system32\net.exe" START SCHEDULE
Path
C:\Windows\system32\net.exe
Indicators
No indicators
Parent process
setupupdater.tmp
User
admin
Integrity Level
HIGH
Exit code
2
Version:
Company
Microsoft Corporation
Description
Net Command
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\net.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\netutils.dll
c:\windows\system32\browcli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\mpr.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\net1.exe

PID
4080
CMD
C:\Windows\system32\net1 START SCHEDULE
Path
C:\Windows\system32\net1.exe
Indicators
No indicators
Parent process
net.exe
User
admin
Integrity Level
HIGH
Exit code
2
Version:
Company
Microsoft Corporation
Description
Net Command
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\net1.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\netutils.dll
c:\windows\system32\logoncli.dll
c:\windows\system32\browcli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\samlib.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\netmsg.dll

PID
2868
CMD
"C:\Program Files\Skillbrains\Updater\1.8.0.0\Updater.exe" -runmode=addsystask
Path
C:\Program Files\Skillbrains\Updater\1.8.0.0\Updater.exe
Indicators
No indicators
Parent process
setupupdater.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Updater Module
Version
1.8.0.0
Modules
Image
c:\program files\skillbrains\updater\1.8.0.0\updater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\profapi.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mstask.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\mpr.dll

PID
3040
CMD
"C:\Program Files\Skillbrains\Updater\Updater.exe" -runmode=addproduct -info="C:\Program Files\Skillbrains\Updater\info.xml"
Path
C:\Program Files\Skillbrains\Updater\Updater.exe
Indicators
No indicators
Parent process
setupupdater.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
TODO: <Company name>
Description
TODO: <File description>
Version
1.0.0.1
Modules
Image
c:\program files\skillbrains\updater\updater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\apphelp.dll
c:\program files\skillbrains\updater\1.8.0.0\updater.exe

PID
3304
CMD
"C:\Program Files\Skillbrains\Updater\1.8.0.0\Updater.exe" -runmode=addproduct -info="C:\Program Files\Skillbrains\Updater\info.xml"
Path
C:\Program Files\Skillbrains\Updater\1.8.0.0\Updater.exe
Indicators
Parent process
Updater.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Updater Module
Version
1.8.0.0
Modules
Image
c:\program files\skillbrains\updater\1.8.0.0\updater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\profapi.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\version.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\gpapi.dll

PID
3972
CMD
"C:\Program Files\Skillbrains\Updater\Updater.exe" -runmode=ping -url="http://updater.prntscr.com/getver/updater?ping=true"
Path
C:\Program Files\Skillbrains\Updater\Updater.exe
Indicators
No indicators
Parent process
setupupdater.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
TODO: <Company name>
Description
TODO: <File description>
Version
1.0.0.1
Modules
Image
c:\program files\skillbrains\updater\updater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\apphelp.dll
c:\program files\skillbrains\updater\1.8.0.0\updater.exe

PID
2600
CMD
"C:\Program Files\Skillbrains\Updater\1.8.0.0\Updater.exe" -runmode=ping -url="http://updater.prntscr.com/getver/updater?ping=true"
Path
C:\Program Files\Skillbrains\Updater\1.8.0.0\Updater.exe
Indicators
Parent process
Updater.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Updater Module
Version
1.8.0.0
Modules
Image
c:\program files\skillbrains\updater\1.8.0.0\updater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\profapi.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\version.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\clbcatq.dll
c:\program files\common files\microsoft shared\office14\msoxmlmf.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\gpapi.dll

PID
2228
CMD
"C:\Program Files\Skillbrains\Updater\updater.exe" -runmode=addtask
Path
C:\Program Files\Skillbrains\Updater\updater.exe
Indicators
No indicators
Parent process
setup-lightshot.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
TODO: <Company name>
Description
TODO: <File description>
Version
1.0.0.1
Modules
Image
c:\program files\skillbrains\updater\updater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\apphelp.dll
c:\program files\skillbrains\updater\1.8.0.0\updater.exe

PID
2988
CMD
"C:\Program Files\Skillbrains\Updater\1.8.0.0\updater.exe" -runmode=addtask
Path
C:\Program Files\Skillbrains\Updater\1.8.0.0\updater.exe
Indicators
No indicators
Parent process
updater.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Updater Module
Version
1.8.0.0
Modules
Image
c:\program files\skillbrains\updater\1.8.0.0\updater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\profapi.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mstask.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\mpr.dll

PID
3668
CMD
"C:\Program Files\Skillbrains\Updater\updater.exe" -runmode=addproduct -info="C:\Program Files\Skillbrains\lightshot\info.xml"
Path
C:\Program Files\Skillbrains\Updater\updater.exe
Indicators
No indicators
Parent process
setup-lightshot.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
TODO: <Company name>
Description
TODO: <File description>
Version
1.0.0.1
Modules
Image
c:\program files\skillbrains\updater\updater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\apphelp.dll
c:\program files\skillbrains\updater\1.8.0.0\updater.exe

PID
2364
CMD
"C:\Program Files\Skillbrains\Updater\1.8.0.0\updater.exe" -runmode=addproduct -info="C:\Program Files\Skillbrains\lightshot\info.xml"
Path
C:\Program Files\Skillbrains\Updater\1.8.0.0\updater.exe
Indicators
Parent process
updater.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Updater Module
Version
1.8.0.0
Modules
Image
c:\program files\skillbrains\updater\1.8.0.0\updater.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\profapi.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\version.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\gpapi.dll

PID
3072
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" -nohome
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
setup-lightshot.tmp
User
admin
Integrity Level
MEDIUM
Exit code
1
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\psapi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\cryptbase.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\ieui.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\clbcatq.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\url.dll
c:\windows\system32\version.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\propsys.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\msfeeds.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\mlang.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\credssp.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\linkinfo.dll

PID
2416
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3072 CREDAT:71937
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
iexplore.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\comdlg32.dll
c:\program files\internet explorer\ieshims.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rsaenh.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mlang.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\apphelp.dll
c:\program files\java\jre1.8.0_92\bin\ssv.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\version.dll
c:\progra~1\micros~1\office14\urlredir.dll
c:\windows\system32\secur32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\progra~1\micros~1\office14\msohev.dll
c:\program files\java\jre1.8.0_92\bin\jp2ssv.dll
c:\program files\java\jre1.8.0_92\bin\msvcr100.dll
c:\program files\java\jre1.8.0_92\bin\deploy.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\sxs.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\credssp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\p2pcollab.dll
c:\windows\system32\qagentrt.dll
c:\windows\system32\fveui.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\feclient.dll
c:\windows\system32\iepeers.dll
c:\windows\system32\winspool.drv
c:\windows\system32\imgutil.dll
c:\windows\system32\jscript.dll
c:\windows\system32\pngfilt.dll
c:\program files\common files\microsoft shared\vgx\vgx.dll
c:\windows\system32\atl.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\dxtrans.dll
c:\windows\system32\ddrawex.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\windows\system32\dxtmsft.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\macromed\flash\flash32_26_0_0_131.ocx
c:\windows\system32\winmm.dll
c:\windows\system32\dsound.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\mscms.dll
c:\windows\system32\dinput8.dll

PID
2396
CMD
C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exe -Embedding
Path
C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Adobe Systems Incorporated
Description
Adobe® Flash® Player Installer/Uninstaller 26.0 r0
Version
26,0,0,131
Modules
Image
c:\windows\system32\macromed\flash\flashutil32_26_0_0_131_activex.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\secur32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\version.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\riched20.dll
c:\windows\system32\cryptui.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\ws2help.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\psapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\macromed\flash\flashutil32_26_0_0_131_activex.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\dinput8.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mlang.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll

PID
3936
CMD
"C:\Program Files\Skillbrains\lightshot\Lightshot.exe"
Path
C:\Program Files\Skillbrains\lightshot\Lightshot.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Starter Module
Version
1, 0, 0, 1
Modules
Image
c:\program files\skillbrains\lightshot\lightshot.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\program files\skillbrains\lightshot\5.4.0.35\lightshot.exe
c:\windows\system32\apphelp.dll

PID
2468
CMD
"C:\Program Files\Skillbrains\lightshot\5.4.0.35\Lightshot.exe"
Path
C:\Program Files\Skillbrains\lightshot\5.4.0.35\Lightshot.exe
Indicators
No indicators
Parent process
Lightshot.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Skillbrains
Description
Lightshot
Version
5.4.0.1
Modules
Image
c:\program files\skillbrains\lightshot\5.4.0.35\lightshot.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll

PID
2956
CMD
"C:\Program Files\Skillbrains\lightshot\Lightshot.exe"
Path
C:\Program Files\Skillbrains\lightshot\Lightshot.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Starter Module
Version
1, 0, 0, 1
Modules
Image
c:\program files\skillbrains\lightshot\lightshot.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\program files\skillbrains\lightshot\5.4.0.35\lightshot.exe
c:\windows\system32\apphelp.dll

PID
3676
CMD
"C:\Program Files\Skillbrains\lightshot\5.4.0.35\Lightshot.exe"
Path
C:\Program Files\Skillbrains\lightshot\5.4.0.35\Lightshot.exe
Indicators
No indicators
Parent process
Lightshot.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Skillbrains
Description
Lightshot
Version
5.4.0.1
Modules
Image
c:\program files\skillbrains\lightshot\5.4.0.35\lightshot.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll

Registry activity

Total events
1568
Read events
1372
Write events
192
Delete events
4

Modification events

PID
Process
Operation
Key
Name
Value
2788
setup-lightshot.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Owner
E40A0000DE8CA3096A3DD501
2788
setup-lightshot.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
SessionHash
633CBD3D86103DF3CBE0EC553FE166D2D9C7DE332A5C36AD2E5B15802E87069A
2788
setup-lightshot.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Sequence
1
2788
setup-lightshot.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
RegFiles0000
C:\Program Files\Skillbrains\lightshot\5.4.0.35\DXGIODScreenshot.dll
2788
setup-lightshot.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
RegFilesHash
B64298CDA9886513969F70DD609B7F16508604D5E8AA071AD39FCCCD611D5956
2788
setup-lightshot.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2788
setup-lightshot.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2788
setup-lightshot.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Lightshot
C:\Program Files\Skillbrains\lightshot\Lightshot.exe
2788
setup-lightshot.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Skillbrains\Lightshot
Locale
EN
2788
setup-lightshot.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1
Inno Setup: Setup Version
5.5.9 (u)
2788
setup-lightshot.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1
Inno Setup: App Path
C:\Program Files\Skillbrains\lightshot
2788
setup-lightshot.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1
InstallLocation
C:\Program Files\Skillbrains\lightshot\
2788
setup-lightshot.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1
Inno Setup: Icon Group
Lightshot
2788
setup-lightshot.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1
Inno Setup: User
admin
2788
setup-lightshot.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1
Inno Setup: Language
english
2788
setup-lightshot.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1
DisplayName
Lightshot-5.4.0.35
2788
setup-lightshot.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1
UninstallString
"C:\Program Files\Skillbrains\lightshot\unins000.exe"
2788
setup-lightshot.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1
QuietUninstallString
"C:\Program Files\Skillbrains\lightshot\unins000.exe" /SILENT
2788
setup-lightshot.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1
DisplayVersion
5.4.0.35
2788
setup-lightshot.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1
Publisher
Skillbrains
2788
setup-lightshot.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1
URLInfoAbout
http://app.prntscr.com/
2788
setup-lightshot.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1
HelpLink
http://app.prntscr.com/
2788
setup-lightshot.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1
URLUpdateInfo
http://app.prntscr.com/
2788
setup-lightshot.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1
NoModify
1
2788
setup-lightshot.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1
NoRepair
1
2788
setup-lightshot.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1
InstallDate
20190718
2788
setup-lightshot.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1
MajorVersion
5
2788
setup-lightshot.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1
MinorVersion
4
2788
setup-lightshot.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1
VersionMajor
5
2788
setup-lightshot.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1
VersionMinor
4
2788
setup-lightshot.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1
EstimatedSize
4477
2788
setup-lightshot.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\setup-lightshot_RASAPI32
EnableFileTracing
0
2788
setup-lightshot.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\setup-lightshot_RASAPI32
EnableConsoleTracing
0
2788
setup-lightshot.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\setup-lightshot_RASAPI32
FileTracingMask
4294901760
2788
setup-lightshot.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\setup-lightshot_RASAPI32
ConsoleTracingMask
4294901760
2788
setup-lightshot.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\setup-lightshot_RASAPI32
MaxFileSize
1048576
2788
setup-lightshot.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\setup-lightshot_RASAPI32
FileDirectory
%windir%\tracing
2788
setup-lightshot.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\setup-lightshot_RASMANCS
EnableFileTracing
0
2788
setup-lightshot.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\setup-lightshot_RASMANCS
EnableConsoleTracing
0
2788
setup-lightshot.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\setup-lightshot_RASMANCS
FileTracingMask
4294901760
2788
setup-lightshot.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\setup-lightshot_RASMANCS
ConsoleTracingMask
4294901760
2788
setup-lightshot.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\setup-lightshot_RASMANCS
MaxFileSize
1048576
2788
setup-lightshot.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\setup-lightshot_RASMANCS
FileDirectory
%windir%\tracing
2788
setup-lightshot.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2788
setup-lightshot.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000079000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2788
setup-lightshot.tmp
delete key
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
2752
Lightshot.exe
write
HKEY_CURRENT_USER\Software\SkillBrains\Lightshot
Locale
EN
2752
Lightshot.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Name
Lightshot.exe
2752
Lightshot.exe
write
HKEY_CURRENT_USER\Software\SkillBrains\Lightshot
appFirstRun
0
1952
setupupdater.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
Owner
A00700006C586A116A3DD501
1952
setupupdater.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
SessionHash
A2E785FCABFA85FCDA5CD1AC8A3DD13AE6B3BDD0E139F465DC6597F0A8065D2F
1952
setupupdater.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
Sequence
1
1952
setupupdater.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
RegFiles0000
C:\Program Files\Skillbrains\Updater\1.8.0.0\Updater.exe
1952
setupupdater.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
RegFilesHash
A03642D495918D8EB8E73E917B7B2E4A8D01671A0A2DFDEE15C2383CA1F39CD1
1952
setupupdater.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Skillbrains\Updater
path
C:\Program Files\Skillbrains\Updater\updater.exe
1952
setupupdater.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
1952
setupupdater.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
1952
setupupdater.tmp
delete key
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
2868
Updater.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Skillbrains\Updater
UserID
{45AEC9A9-DA3B-4D30-BEC4-04AFC0D70B7F}
3304
Updater.exe
write
HKEY_CURRENT_USER\Software\SkillBrains\Updater
ga_unique_id
53841563455386
3304
Updater.exe
write
HKEY_CURRENT_USER\Software\SkillBrains\Updater
ga_first_time
1563455386
3304
Updater.exe
write
HKEY_CURRENT_USER\Software\SkillBrains\Updater
ga_counter
1
3304
Updater.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Updater_RASAPI32
EnableFileTracing
0
3304
Updater.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Updater_RASAPI32
EnableConsoleTracing
0
3304
Updater.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Updater_RASAPI32
FileTracingMask
4294901760
3304
Updater.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Updater_RASAPI32
ConsoleTracingMask
4294901760
3304
Updater.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Updater_RASAPI32
MaxFileSize
1048576
3304
Updater.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Updater_RASAPI32
FileDirectory
%windir%\tracing
3304
Updater.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Updater_RASMANCS
EnableFileTracing
0
3304
Updater.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Updater_RASMANCS
EnableConsoleTracing
0
3304
Updater.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Updater_RASMANCS
FileTracingMask
4294901760
3304
Updater.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Updater_RASMANCS
ConsoleTracingMask
4294901760
3304
Updater.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Updater_RASMANCS
MaxFileSize
1048576
3304
Updater.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Updater_RASMANCS
FileDirectory
%windir%\tracing
3304
Updater.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3304
Updater.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000077000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3304
Updater.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3304
Updater.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3304
Updater.exe
write
HKEY_CURRENT_USER\Software\SkillBrains\Updater
ga_last_time
1563455386
3304
Updater.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
LanguageList
en-US
2600
Updater.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2600
Updater.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000078000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2600
Updater.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2600
Updater.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2600
Updater.exe
write
HKEY_CURRENT_USER\Software\SkillBrains\Updater
ga_counter
2
2600
Updater.exe
write
HKEY_CURRENT_USER\Software\SkillBrains\Updater
ga_last_time
1563455387
2600
Updater.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
LanguageList
en-US
2600
Updater.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\6252DC40F71143A22FDE9EF7348E064251B18118
Blob
0400000001000000100000002C8F9F661D1890B147269D8E86828CA90F00000001000000140000001E427A3639CCE4C27E94B1777964CA289A722CAD09000000010000003E000000303C06082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B0601050507030806082B06010505070309620000000100000020000000D8E0FEBC1DB2E38D00940F37D27D41344D993E734B99D5656D9778D4D81436241400000001000000140000006DAA9B0987C4D0D422ED4007374D19F191FFDED31D000000010000001000000096F98B6E79A74810CE7D398A82F977780B000000010000000E000000430065007200740075006D0000000300000001000000140000006252DC40F71143A22FDE9EF7348E064251B181181900000001000000100000000B6CD9778E41AD67FD6BE0A6903710442000000001000000100300003082030C308201F4A0030201020203010020300D06092A864886F70D0101050500303E310B300906035504061302504C311B3019060355040A1312556E697A65746F2053702E207A206F2E6F2E311230100603550403130943657274756D204341301E170D3032303631313130343633395A170D3237303631313130343633395A303E310B300906035504061302504C311B3019060355040A1312556E697A65746F2053702E207A206F2E6F2E311230100603550403130943657274756D20434130820122300D06092A864886F70D01010105000382010F003082010A0282010100CEB1C12ED34F7CCD25CE183E4FC48C6F806A73C85B51F89BD2DCBB005CB1A0FC7503EE81F088EE2352E9E615338DAC2D09C576F92B398089E4974B90A5A878F873437BA461B0D858CCE16C667E9CF3095E556384D5A8EFF3B12E3068B3C43CD8AC6E8D995A904E34DC369A8F818850B76D964209F3D795830D414BB06A6BF8FC0F7E629F67C4ED265F10260F084FF0A45728CE8FB8ED45F66EEE255DAA6E39BEE4932FD947A072EBFAA65BAFCA533FE20EC69656116EF7E966A926D87F9553ED0A8588BA4F29A5428C5EB6FC852000AA680BA11A85019CC446638288B622B1EEFEAA46597ECF352CD5B6DA5DF748331454B6EBD96FCECD88D6AB1BDA963B1D590203010001A3133011300F0603551D130101FF040530030101FF300D06092A864886F70D01010505000382010100B88DCEEFE714BACFEEB044926CB4393EA2846EADB82177D2D4778287E6204181EEE2F811B763D11737BE1976241C041A4CEB3DAA676F2DD4CDFE653170C51BA6020ABA607B6D58C29A49FE63320B6BE33AC0ACAB3BB0E8D309518C1083C634E0C52BE01AB66014276C32778CBCB27298CFCDCC3FB9C8244214D657FCE62643A91DE58090CE0354283EF73FD3F84DED6A0A3A93139B3B142313639C3FD1872779E54C51E301AD855D1A3BB1D57310A4D3F2BC6E64F55A5690A8C70E4C740F2E713BF7C847F4696F15F2115E831E9C7C52AEFD02DA12A8596718DBBC70DD9BB169ED80CE8940486A0E35CA29661521942CE8602A9B854A40F36B8A24EC06162C73
2364
updater.exe
write
HKEY_CURRENT_USER\Software\SkillBrains\Updater
ga_counter
3
2364
updater.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2364
updater.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
460000007A000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2364
updater.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2364
updater.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2364
updater.exe
write
HKEY_CURRENT_USER\Software\SkillBrains\Updater
ga_last_time
1563455387
2364
updater.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
LanguageList
en-US
3072
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
CompatibilityFlags
0
3072
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3072
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3072
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
SecuritySafe
1
3072
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3072
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
460000007B000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3072
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
{51498F41-A95D-11E9-B506-5254004A04AF}
0
3072
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Type
4
3072
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Count
1
3072
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Time
E3070700040012000D0009003000CE02
3072
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Type
4
3072
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Count
1
3072
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Time
E3070700040012000D0009003000DD02
3072
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
FullScreen
no
3072
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Window_Placement
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF20000000200000004003000078020000
3072
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\Links
Order
08000000020000000C01000001000000020000007E0000000000000070003200EC000000464B245120005355474745537E312E55524C0000540008000400EFBE454B974D464B24512A000000F94300000000020000000000000000000000000000005300750067006700650073007400650064002000530069007400650073002E00750072006C0000001C00000000000000820000000100000074003200E2000000464B24512000574542534C497E312E55524C0000580008000400EFBE454B864A464B24512A000000743E0000000003000000000000000000000000000000570065006200200053006C006900630065002000470061006C006C006500720079002E00750072006C0000001C00000000000000
3072
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Type
3
3072
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Count
1
3072
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Time
E3070700040012000D0009003000D703
3072
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
LoadTime
19
3072
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Type
3
3072
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Count
1
3072
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Time
E3070700040012000D00090031000F00
3072
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
LoadTime
77
3072
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Type
3
3072
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Count
1
3072
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Time
E3070700040012000D00090031005D00
3072
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
LoadTime
74
3072
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D27CDB6E-AE6D-11CF-96B8-444553540000}\iexplore
Type
1
3072
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D27CDB6E-AE6D-11CF-96B8-444553540000}\iexplore
Count
1
3072
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D27CDB6E-AE6D-11CF-96B8-444553540000}\iexplore
Time
E3070700040012000D00090033005A03
3072
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019071820190719
CachePath
%USERPROFILE%\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019071820190719
3072
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019071820190719
CachePrefix
:2019071820190719:
3072
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019071820190719
CacheLimit
8192
3072
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019071820190719
CacheOptions
11
3072
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019071820190719
CacheRepair
0
3072
iexplore.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019032320190324
3072
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\WindowsSearch
UpgradeTime
52F578166A3DD501
3072
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\WindowsSearch
UpgradeTime
AC577B166A3DD501
3072
iexplore.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
LanguageList
en-US
2416
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012019071820190719
CachePath
%USERPROFILE%\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012019071820190719
2416
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012019071820190719
CachePrefix
:2019071820190719:
2416
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012019071820190719
CacheLimit
8192
2416
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012019071820190719
CacheOptions
11
2416
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012019071820190719
CacheRepair
0
2416
iexplore.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012018082820180829

Files activity

Executable files
13
Suspicious files
6
Text files
121
Unknown types
11

Dropped files

PID
Process
Filename
Type
3748
setup-lightshot.exe
C:\Users\admin\AppData\Local\Temp\is-T8LRP.tmp\setup-lightshot.tmp
executable
MD5: dee46f351d74a2ed26122bebc89fdf39
SHA256: 327367cfe4fb2653f4eb04554ecc029915de2fc22997f50681a370d19938a840
1952
setupupdater.tmp
C:\Program Files\Skillbrains\Updater\1.8.0.0\Updater.exe
executable
MD5: fbe0664e1c333e36e3ce73d8bd5cc8a1
SHA256: c4ce15b1bc8adecbf20a655256aab267c1d72e7a33947598af48ea287cca5670
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\net.dll
executable
MD5: 2cdf9b54d61343f95f112876c9dce245
SHA256: e6e98074c5c6c2b6c996215b4d08f348fa61406d9db183ea42bbb8daf6138278
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\Lightshot.exe
executable
MD5: 65ae81be94373742fc6f0b2527eeceaa
SHA256: 0140e0e14e3ce80c0187d66050bc749a5f310558a81e08fbabda40e090e863ab
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\Lightshot.exe
executable
MD5: e05782e0b697cadbbc17e78c67280b30
SHA256: 87a142350f1bd9ff7adddbf80ac5c1efdce93f8e3142b95acc8d85dde77d42d8
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\DXGIODScreenshot.dll
executable
MD5: 3d51f1f54b980431187c28170396522b
SHA256: 10b3f99c81e59ee9360ff009b9529d8638147a568a18e5e5a74a96a062908025
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\unins000.exe
executable
MD5: dee46f351d74a2ed26122bebc89fdf39
SHA256: 327367cfe4fb2653f4eb04554ecc029915de2fc22997f50681a370d19938a840
1952
setupupdater.tmp
C:\Program Files\Skillbrains\Updater\Updater.exe
executable
MD5: 3ec8f4bd54ef439a8fab6467122da0c4
SHA256: a5e3bdc3b0b0bd6455892e23008161b5478b24f4fe1801f43a8a01cfff1bcba7
2164
setup-lightshot.exe
C:\Users\admin\AppData\Local\Temp\is-B88G4.tmp\setup-lightshot.tmp
executable
MD5: dee46f351d74a2ed26122bebc89fdf39
SHA256: 327367cfe4fb2653f4eb04554ecc029915de2fc22997f50681a370d19938a840
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\uploader.dll
executable
MD5: c3881676f18103f898f6cc13e3004b5b
SHA256: f337582eefa94b9080a0e2279014348f5fb54cbbe0f75a778f368abc0cc710e3
2788
setup-lightshot.tmp
C:\Users\admin\AppData\Local\Temp\is-3FI61.tmp\setupupdater.exe
executable
MD5: 843d23f6aab075a3c032b06d30ce9c5d
SHA256: 088f048ee972ef80bd527e301431c1ad7e46d0c994ad8a2b586c4fa6d86ac399
1312
setupupdater.exe
C:\Users\admin\AppData\Local\Temp\is-73PS6.tmp\setupupdater.tmp
executable
MD5: 3613e29d2a7b90c1012ec676819cc1cd
SHA256: fb5761640bb6d375345b780df0f1811f6ae6a1ddeae7c948299379f8bca822c8
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\Lightshot.dll
executable
MD5: 00d11084e5efc37f58f0e042cf4973b5
SHA256: 40c0e4232560bd8dbc6c41df12c8d3b517eba19bc5949966c6f3e84c8a8ea5cd
3304
Updater.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
––
MD5:  ––
SHA256:  ––
3072
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\favicon[1].ico
image
MD5: feb7ca0515d4660fc15fc4f42c8904ef
SHA256: b50109bb17a40d032cb6ee83163e10d220e0d19a19192cb71950063070888570
3072
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019071820190719\index.dat
dat
MD5: f3c4f1435ae2d6db80ef03afe1bd572f
SHA256: 9dd56489f739c775ff340fb8f2383cbc583b80391d770c38d0e1d9589aa99283
2416
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012019071820190719\index.dat
dat
MD5: c77e58aad9c0f8c1c999d03ed2413a5a
SHA256: 45d00e754343effb8306dbbe0790e7585fdb6b35e9aa6f733f2f60801c335586
2416
iexplore.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
text
MD5: 7dbae21bd7ece7f7a1a7339a248031a0
SHA256: 334a1c84c5015dd71dd61223e4c2c0e1f0d5967dccd2590098c7afd03306ac5e
2416
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT
smt
MD5: 60272cba5ad84466b761ccb17bc51037
SHA256: ed2a144c57ac894562da29c3ed8df7a741f5a07e4c053cd366417c3574ec4cae
2416
iexplore.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
––
MD5:  ––
SHA256:  ––
2396
FlashUtil32_26_0_0_131_ActiveX.exe
C:\Users\admin\AppData\Roaming\Adobe\Flash Player\NativeCache\NativeCache.directory:Zone.Identifier
text
MD5: fbccf14d504b7b2dbcb5a5bda75bd93b
SHA256: eacd09517ce90d34ba562171d15ac40d302f0e691b439f91be1b6406e25f5913
2416
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UM3XUZ38\helper-button[1].png
image
MD5: a256a5978303b001f853a192f6107e9e
SHA256: bd85b212b8341928dc6b825085444e909dac699d0fa28983974662b49d1d55ff
2416
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BF499E7O\helper-share[1].png
image
MD5: 5934af33d8edca47fccc23832a7c3cf7
SHA256: eb3fe5fc91735f77bc804682679573c097f374fd9568a721bad5f2c968800a82
2416
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\TOTL9IUE\helper-select[1].png
image
MD5: c61b4c21f7a468dc9799d0b76a793d3b
SHA256: e3e28de0a32613b61dc2fb3e469ae699f53a60a08f2767ddf3a5a786ebf3d74e
2416
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.dat
dat
MD5: 36ee086bb331e17593e9ffe33189fd8d
SHA256: 3db70351ab1614485c5f0746088ebd529c0f9ad6804d46b41ec6925c82f9caeb
2416
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\1OR02DRA\analytics[1].js
text
MD5: 4d88a66690f3506e6a2112b1c4dce0b4
SHA256: a4883cce814b6793c5bd6dd3639d6048ecab39a93a90b560d39a9fd0aff6e263
2416
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\1OR02DRA\button-download[1].png
image
MD5: 63fb601de8dd94a8ae339b1b6130afe2
SHA256: 2222b64c7e37a7d528c8326ebaee33ae44bae57d7654db28e1122c0cae8a93db
2416
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UM3XUZ38\shadow-top[1].png
image
MD5: c3fcdff29a61c3bd7f2fb7732cd03d5f
SHA256: 323cbd97106a38a3c9c7a563581f270ca1d16dace5badd8bbbc0a1a83da892dd
2416
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UM3XUZ38\icon-facebook_gscale[1].png
image
MD5: 41bc3fcc018ccdc715aaec489cfc2f3c
SHA256: 2e6fe8983e6c80684ab4ab666cb31fad9373911a394c93d1fb55acf1703e7a09
2416
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BF499E7O\icon-twitter_gscale[1].png
image
MD5: 8e26b6bb15c19bc6ecc889319afaae9b
SHA256: 9251076990f3881a584eafc43ffe8a85ebee0c82f48c00de4b1f1fa25413e3e7
2416
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BF499E7O\jquery.smartbanner[1].js
html
MD5: 0a5df0d66eec5a3c05c270c434853cfa
SHA256: 1b185d89e437f1591af8c51d5e6dad41d3666e22a81931ee9df22e2cfdacaddb
2416
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\TOTL9IUE\header-logo[1].png
image
MD5: 5531b8e72f3179fa74a6a5c242a12eef
SHA256: 4cee2541161cf165e2e8ce22b81ec2cf8ccc162064124fb350df3b452a992a50
2416
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\TOTL9IUE\jquery.smartbanner[2].css
text
MD5: 5db3b16482a2fe81b7d2fda027f2e848
SHA256: d91d13fd8f9d253a8213aeee7ebaa7e073683fc600a3d82902c3c669b8ffdee7
2416
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\1OR02DRA\footer-logo[1].png
image
MD5: 2f947950b12d9a2064c9a2560913e32f
SHA256: 2f4e37cdda48186daed490f0f71b432614033b2dcd35d6f73e410dad26794dac
2416
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BF499E7O\img-pic-480[1].jpg
image
MD5: e89f04845db22a283878caf211923c88
SHA256: a4f227cdbf6df355c12420bf48a0caa6309ddbd5181dcda8d84a1c166ba7569e
2416
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\TOTL9IUE\jquery.smartbanner[1].css
text
MD5: 5db3b16482a2fe81b7d2fda027f2e848
SHA256: d91d13fd8f9d253a8213aeee7ebaa7e073683fc600a3d82902c3c669b8ffdee7
2416
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\1OR02DRA\script.mix[1].js
text
MD5: a0e3039774fe5e315130ff410290887f
SHA256: 10bbe2aca26e94a2bf64fc8145cd586c0a20038bf0fa1461a4f35d774adbf703
2416
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UM3XUZ38\main[1].css
text
MD5: 1005ef05b14c5c93d6240fb52c294733
SHA256: 726984457662e2ae992435af4efac2f0e43d8c15c03224f21955867081b8fe82
2416
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UM3XUZ38\page-bg[1].png
image
MD5: fbbf5de0a5c439e4236ba793b9fe6a9a
SHA256: 8fe2e9cd2e04b3429639594142c331755700deb125b5bf9f1912a772c68d2423
2416
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BF499E7O\jquery.1.8.2.min[1].js
text
MD5: 0b6ecf17e30037994d3ffee51b525914
SHA256: f554d2f09272c6f71447ebfe4532d3b1dd1959bce669f9a5ccc99e64ef511729
2416
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BF499E7O\main[1].css
––
MD5:  ––
SHA256:  ––
2416
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\TOTL9IUE\thankyou_desktop[1].htm
html
MD5: d882280a9cd75d55d92f386b9e34f966
SHA256: b4401621375999d940f886312eccc899976c23a43cdee350ac7da8d225084988
2364
updater.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\__utm[2].gif
image
MD5: 28d6814f309ea289f847c69cf91194c6
SHA256: 8337212354871836e6763a41e615916c89bac5b3f1f0adf60ba43c7c806e1015
2416
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.dat
dat
MD5: f6b571688d2e4b17e587c6d852ea0cab
SHA256: 8dea6ce43941753bfbed13e4e1adc7691d3682e3dd9ae5f29c405aec4c59c44f
2416
iexplore.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\index.dat
dat
MD5: ce96c73dc74ec6b3f63d3c0e5f0de10f
SHA256: 5a8a14db51732ea97779f950add583f80112f3acd6b58499d09f709da1af862d
2416
iexplore.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
text
MD5: fe3c95ad1b9604a8b67368e774ed8510
SHA256: ad4d0d77972b08bbfcdea5c9699ccb7c89524cef4538d98a5ee82cafd8045587
3072
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\favicon[1].png
image
MD5: 9fb559a691078558e77d6848202f6541
SHA256: 6d8a01dc7647bc218d003b58fe04049e24a9359900b7e0cebae76edf85b8b914
3072
iexplore.exe
C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
––
MD5:  ––
SHA256:  ––
3072
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\favicon[1].ico
––
MD5:  ––
SHA256:  ––
2416
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.dat
dat
MD5: f9a3f2a9504477efdaf28293e6a68c59
SHA256: c842ec61067ca31e5ecca95b7fb43321853a22dd135ae20cb32d636834b5f46c
2416
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\1OR02DRA\desktop.ini
ini
MD5: 4a3deb274bb5f0212c2419d3d8d08612
SHA256: 2842973d15a14323e08598be1dfb87e54bf88a76be8c7bc94c56b079446edf38
2416
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\BF499E7O\desktop.ini
ini
MD5: 4a3deb274bb5f0212c2419d3d8d08612
SHA256: 2842973d15a14323e08598be1dfb87e54bf88a76be8c7bc94c56b079446edf38
2416
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\TOTL9IUE\desktop.ini
ini
MD5: 4a3deb274bb5f0212c2419d3d8d08612
SHA256: 2842973d15a14323e08598be1dfb87e54bf88a76be8c7bc94c56b079446edf38
2416
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\UM3XUZ38\desktop.ini
ini
MD5: 4a3deb274bb5f0212c2419d3d8d08612
SHA256: 2842973d15a14323e08598be1dfb87e54bf88a76be8c7bc94c56b079446edf38
3072
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Feeds Cache\desktop.ini
ini
MD5: 4a3deb274bb5f0212c2419d3d8d08612
SHA256: 2842973d15a14323e08598be1dfb87e54bf88a76be8c7bc94c56b079446edf38
2416
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\desktop.ini
ini
MD5: 4a3deb274bb5f0212c2419d3d8d08612
SHA256: 2842973d15a14323e08598be1dfb87e54bf88a76be8c7bc94c56b079446edf38
2416
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\desktop.ini
ini
MD5: 4a3deb274bb5f0212c2419d3d8d08612
SHA256: 2842973d15a14323e08598be1dfb87e54bf88a76be8c7bc94c56b079446edf38
2600
Updater.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
text
MD5: 69d438c59798201e1dbcae89d850beba
SHA256: 3f7809dc4c845b04653952ff427d2581ce410c1021c215e63709e6e118d6d8cc
2600
Updater.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\__utm[2].gif
image
MD5: 28d6814f309ea289f847c69cf91194c6
SHA256: 8337212354871836e6763a41e615916c89bac5b3f1f0adf60ba43c7c806e1015
2788
setup-lightshot.tmp
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\__utm[1].gif
image
MD5: 28d6814f309ea289f847c69cf91194c6
SHA256: 8337212354871836e6763a41e615916c89bac5b3f1f0adf60ba43c7c806e1015
2788
setup-lightshot.tmp
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\__utm[1].gif
image
MD5: 28d6814f309ea289f847c69cf91194c6
SHA256: 8337212354871836e6763a41e615916c89bac5b3f1f0adf60ba43c7c806e1015
2600
Updater.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\__utm[1].gif
image
MD5: 28d6814f309ea289f847c69cf91194c6
SHA256: 8337212354871836e6763a41e615916c89bac5b3f1f0adf60ba43c7c806e1015
2364
updater.exe
C:\Users\admin\AppData\Local\UserProducts.xml
xml
MD5: d6063cc8b290a77fb7043567c4c94864
SHA256: d15928513e6d0f72851e3b49e50aa16039fcf3aad4542fb2419c1056b391a882
3304
Updater.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\__utm[1].gif
image
MD5: 28d6814f309ea289f847c69cf91194c6
SHA256: 8337212354871836e6763a41e615916c89bac5b3f1f0adf60ba43c7c806e1015
2600
Updater.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\updater[1].xml
xml
MD5: ae4f7437a2dfee6b87f2a6a011cc6625
SHA256: ebe25600d44f1f798ada4b3b62001fd96d7a5e466125484568c3241508bf46c6
2600
Updater.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
text
MD5: ed538002a7bc42b5b619215746a9a05e
SHA256: e1b4e7ea3df05c1943a968c9eb93dd71bff0fbeae9740f14c2e2a4f595291226
2988
updater.exe
C:\Windows\Tasks\update-S-1-5-21-1302019708-1500728564-335382590-1000.job
binary
MD5: b80356811a7a7ead73088812251404ad
SHA256: 0ab8355164217bebd0335da558c7a51b19437e62af8f18803cc473c6ffabec0a
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\info.xml
xml
MD5: 68981cbd99bc526976f47fe72b006396
SHA256: c6825bbabb2cc57d937207a2d4817be11638806420bbcdf428a51600c893ce90
3304
Updater.exe
C:\Program Files\Skillbrains\Updater\MachineProducts.xml
xml
MD5: 365add7ccfb0a5ac3ad31a728695febd
SHA256: e2ee14d35f992d8369bfb9b734c0d982fd2029e3b2418c499d8d2e9cf9fb06c2
1952
setupupdater.tmp
C:\Program Files\Skillbrains\Updater\info.xml
xml
MD5: 07fa60d4a2d9e522199aac63ac768ff1
SHA256: 2ef1d047b796bf6c5a8df374a4f9bd20f85d9b7fc5113d6338befd8c9e740bae
2868
Updater.exe
C:\Windows\Tasks\update-sys.job
binary
MD5: 6cb9f4826af288ce63da9b03802d1e74
SHA256: f7b5e10b6bc43b48f077a982e6a249981e2c22972e367ca9c2fd72e17dae5b53
2868
Updater.exe
C:\Users\admin\AppData\Local\updater.log
text
MD5: ecaa88f7fa0bf610a5a26cf545dcd3aa
SHA256: f1945cd6c19e56b3c1c78943ef5ec18116907a4ca1efc40a57d48ab1db7adfc5
3072
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{51498F41-A95D-11E9-B506-5254004A04AF}.dat
––
MD5:  ––
SHA256:  ––
1952
setupupdater.tmp
C:\Program Files\Skillbrains\Updater\is-213TN.tmp
––
MD5:  ––
SHA256:  ––
2416
iexplore.exe
C:\Users\admin\AppData\Local\Temp\Low\JavaDeployReg.log
text
MD5: c6a74c809a4c2aa8edca80eb5fafe960
SHA256: b0943053c0998c00b2587c5912fe533d8e36fe76e4be337a8ff9068cc8e0dd47
1952
setupupdater.tmp
C:\Program Files\Skillbrains\Updater\1.8.0.0\is-38M95.tmp
––
MD5:  ––
SHA256:  ––
3072
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{51498F42-A95D-11E9-B506-5254004A04AF}.dat
binary
MD5: a3b072230cd9aa20d93ea17005663f78
SHA256: 60b6a2ed62cbc6faf147ba668f1f9358bfb449d1c9fa10fbf406ea3cee213fbc
3072
iexplore.exe
C:\Users\admin\AppData\Local\Temp\~DF467D85CE6EB1922F.TMP
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\unins000.dat
dat
MD5: 5a4da80b54cc756266ad52fdae87c884
SHA256: 18c8dc84562f03f43c1f8292c1fd272d7acf65abecdaeab5dd04b9d337dc88e2
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\unins000.msg
binary
MD5: 79173da528082489a43f39cf200a7647
SHA256: 4f36e6be09cd12e825c2a12ab33544744e7256c9094d7149258ea926705e8ffd
2788
setup-lightshot.tmp
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightshot\Screenshot history.url
text
MD5: 62f8b30ced0855922531b97cc59b0c0b
SHA256: cc30d9069ba066c29a05269a2ec3593a5e904c445d1db050692b4284f7e54c56
2788
setup-lightshot.tmp
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightshot\Learn More.url
text
MD5: a18474414d2875a390a552c146bb89ba
SHA256: b1bccd9fccd63a00ddb83cad3db8ba5c6672cf050e982fe07e0d87e94464b94f
2788
setup-lightshot.tmp
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightshot\Lightshot.lnk
lnk
MD5: 0ff488f1e8f570f4efdb1c40bcad9939
SHA256: 8467831706926b6802532fece152a9045ef912c631b79fce0b57c20e16675516
2788
setup-lightshot.tmp
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightshot\Uninstall Lightshot.lnk
lnk
MD5: d822b618a7a5889f6ecd3ff11aa65c67
SHA256: e6ada0a5f09447290abe2f81bb2ed81b5f799dba9c11792a091e2e269c41389d
3072
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Last Active\RecoveryStore.{577B0B08-A95D-11E9-B506-5254004A04AF}.dat
binary
MD5: bdbcc8b322e24d31c80680165c8f904c
SHA256: d0c85795ee803333fccb3a5f345c1f3cfd9686469e142d894f835de9f7aaf3ad
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\is-JKGD8.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\vi.txt
text
MD5: 32fcb9ca36a07780da8b4b4c84997617
SHA256: 83a2d9ce73a9d3128fa4876dc6e06abd0002a47feae58b458b4cf54594bf4f15
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\zh-CN.txt
text
MD5: dd2c63e55e55b2e84d482a124f29d4c3
SHA256: f60b5740e84492559585350358f0107d65e474601a0db6e0deb5c17ece3b8000
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\zh-TW.txt
text
MD5: 838c1838d7179d4ee301ed448a79bd66
SHA256: 16ca6b6460c44079272ed3dc01efa670730cc585033fe41d8fab153f27e4bdbf
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-O4D53.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-225IS.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-FH362.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\th.txt
text
MD5: 3eca8af4e4dedcffa7a78344fcf4d2a1
SHA256: 99d2a640c702693d70fd5a27ce94bd19cdf0b783891cdf12cf1773760fa00bd2
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\ur.txt
text
MD5: b4213e796bd3b5d8e6efc577228a4128
SHA256: 3148c05f08f56af926306d16aa13257fd7e9386b617f17c1e1c1153e1a90f3d7
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\tr.txt
text
MD5: c2dae97e470fdeb58d53155dc31b6a57
SHA256: 4bf9d07459a5c104290efc4454570be840c9f9ccdcd4976b50b917e7e096a3ad
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\uk.txt
text
MD5: 7b2aa01ced8372dd2c2f3cd9e7376237
SHA256: feee94110db625ca4463cffd123aa28c4eac10d84b9b4ac297e747b82f9e0efd
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-9QV46.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-35Q5L.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-QFGO6.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-18UP5.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\sr-Cyrl.txt
text
MD5: 07497bb84759b11e788870a79d705ddb
SHA256: 5054b7c37f1700de8d1adf340c20f968273143631fa2b59b15afa4069a2990ae
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\sq.txt
text
MD5: 79cc957a2455db1c5b2d7b6be5c7938b
SHA256: 7107eb51042a26aef481596dc7296600b310df8bda0e009954c680607d2e7a42
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\sr.txt
text
MD5: f9a94b828b3c486f34f0ddf2bd68d2c6
SHA256: d94eae7ca797f6484063fb55d956688e801218ef7cf0e522b6c487d2cfe18883
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\sv.txt
text
MD5: 4a1095fa7f4c1e8d35dacb98742238db
SHA256: 6ba9ad29b707786f7880b085abdbe9eb456bd4875d583d8549584667065d4601
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\sl.txt
text
MD5: 3c985b5e85759490cf51a28f89a3b859
SHA256: 143a13c0f251be02ffbcaf21b8708e427815bb0c8ecc2d44f42b62ebf7084484
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-DNH1R.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-303KN.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-RC21H.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-PGE98.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-ERFV6.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\ro.txt
text
MD5: 0ac7a923e5c5a0ac9b485c9367479607
SHA256: 94e58ae597767ae36d6e25f4dc2fd62536beffe7a4786292a42ec6caf65949ca
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\sk.txt
text
MD5: 899d331a59a1a68f656845e338042a71
SHA256: 23256910b90efa3b8a99e4bf872eb2c437dff50fa06544c3abe4fa748b7f42d7
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\ru.txt
text
MD5: fdfe259e9d4c8ce858e2faeb554dd7db
SHA256: aa8b88a1d9681bba228b8a09db39704bdbd2efd206b637f443f5f13e4d5096fb
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\pt-PT.txt
text
MD5: cb4b631b0d783168856f492b97751a00
SHA256: 7d11fd078c07317c8ad48aea4f3292620e7df7acb30f3b27683579194ce35031
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-J1NB4.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-8BSJE.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-2R1DM.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-DBV2E.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\nl.txt
text
MD5: 3fbb181607bb73d98e4611d0df324bed
SHA256: 7d38deb95341b5fb3265071b4ec751a2845273bc15140989003f30e28e66e3c8
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\nb-NO.txt
text
MD5: acf21a98aea3cea8c724a44f857877dd
SHA256: 5e86970d86519bd1329e2d9fa8c7251b08bdab7dc3876ed15fc484409f210df1
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\mk.txt
text
MD5: a509608447de3cbb80be69d5a428ba4e
SHA256: 4615c073df9d8eb1eca47db56cb87b7b4108d12143605a0c26caa90fea80f0d6
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\pl.txt
text
MD5: 7479bbb1c26d5004fcb03a98b64f84da
SHA256: 429cad4f69fec709dae6fb91fac4dfe9d6f0ea26dcfb96612815db44274efb33
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\pt-br.txt
text
MD5: 8cf35497d02a6d23046fd60ac7f0cec8
SHA256: c93f0d72a8a1bb27e3aa0ae12340c4637fb1781b7f306ce2c57f23fcbc67348c
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\lv.txt
text
MD5: 5125df185bded5e32bbf1d65385b18f5
SHA256: 958f4a1fa5bd2014f546c22a74f24dd30756fdc73638d686d14bfffe4f203960
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-Q7ME0.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-GA0SC.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-3BF9G.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-A846L.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-01H66.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-O9LD6.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\ka.txt
text
MD5: b92e59583aae66e74d99039e36afb758
SHA256: c82afeb2efe276dacbde4bb8cb49b5aafe4f645274cdf4cb9f01faf888d197a6
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\ko.txt
text
MD5: c6a57ad854e54005cb8ae6ea3833f447
SHA256: e45ac6c935975b0328926a9eedefdfb4d53dc781ffdbc963213e090699b2b5a9
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\lt.txt
text
MD5: e533ca50842b75236de0163d01d237d7
SHA256: 475a143b146e01a2928f7cd1d3f5fdf9a15d5876883d360b139732c46527b8fc
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\ku.txt
text
MD5: b1568e7572c74ff59caf1a668544b2cb
SHA256: 3919d1ecb3cc1f49f0f1a9b4e9c58b279a0b68dad61751d90bc6cdcc1f7f5183
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-U3A8Q.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-S9NMA.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-KQU3Q.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-ADI11.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\ja.txt
text
MD5: 4b84c519afef69855c2b7f54ebd80b29
SHA256: f3b5eadf29dda244cff30eac25e933907377910d356619295b038b23908c23dd
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\it.txt
text
MD5: a8b6be11d713c0178897b0a0f2510be3
SHA256: c32967b567010aef3ca92d6bc6fc722b14d2ca891c9aea4697d92907a174bde6
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-CAK42.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is.txt
text
MD5: e0f349600a2f84fb8707a2c872973358
SHA256: 05bf65bd7390cba36acf83f5d7fbd51f9e91b33dcf9cdf36d4429654587e2943
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\id.txt
text
MD5: 6d865ba7660d6fb176d8a41d209a3ac0
SHA256: cd9521fc975c2ec6d503681bde7e2b8184f025080bd571cf0899e187576c9be5
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-4F5J4.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-TPQH6.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-BJDQ8.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\hu.txt
text
MD5: 71ef7d84bdebcc579ee26ccab4575e5a
SHA256: 079f4701500362937ef539c2c084b688181724cadcfe4de58319e2c2798b1b4e
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\hy.txt
text
MD5: eab1af5c358761030c5f83e76ce70021
SHA256: d3976fcf80b25505cb1571b751b499ebd6e0e47ec2c0e03e7e91ab8c1718c7a3
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-8N7JO.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-JF74T.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\gl.txt
text
MD5: 959567d83d18693de249d0063f12f851
SHA256: 8da3f72f2bce8dcddc2bfa95f0bf66a19d00d5ff7f06dfd02a29d2e47086e275
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\he.txt
text
MD5: 9c28cc2c63958084df874da5f270afa0
SHA256: de5b7be18db404f760cbab9c8ae79eda410e6dde43a76538de9ca56ca60a64be
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\hr.txt
text
MD5: bb22870209bbd85d796d5f47263c1a09
SHA256: f91998968b7142e347ba619fefff317c30d26e4c37823286488a204c9ea06550
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-8PM53.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-8GIDH.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-NK596.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\fr.txt
text
MD5: ef9054327660b02457b8aeb55a9db7ca
SHA256: c3f50aea2a10a6745b2f1debb88fda588bd24ced4e7ba65e211d1b943f9f5f10
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\fi.txt
text
MD5: efc8b2f84516eb9a2aca53444db5a1d7
SHA256: e53c24ac59d34813a8d010deb581ba2d1822fa79548509578334aa2f83db59af
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-V6SNF.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-NI37T.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\fa.txt
text
MD5: 0f181fe7f9078a716a645d1ae43ac560
SHA256: 03072cf5e32947c43c187c05a28a8bc28ee2e9e7bf90a7cd30808221de1d05d3
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-IRUN1.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\en.txt
text
MD5: cd197f62ee6d954557ba60f57c169911
SHA256: 522536e238889443ea20030e502f54da3ac335076b251b477750a018806d90db
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\et.txt
text
MD5: a9009f79a551e6bd947500b54256072d
SHA256: c90fb3d3a851f318de30a03796e3e0ec50c18481896cc2d2d85b667dd0496a1c
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\es.txt
text
MD5: 135ba16f55a40d14428b972f5a996a83
SHA256: 871de3a370fdc75abacb74b3aeebe2c81f483cafbf2cdaefc1880f19ad96b93f
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-IH6O3.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-SN8CK.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-HVLTN.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\de.txt
text
MD5: 79326fd625d684758d79342b26872b85
SHA256: fedf52bc23a3bc6916254190b3672f8450bb20f2111d5b6c1d073d3f77f46d95
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\el.txt
text
MD5: c8754d361d9a5e39e9031672ec7c5833
SHA256: 5b04dece96645285856e3bedaab6145c0ba30e2cfd37afce2103d40b451522da
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-OITQ6.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-NOMKI.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\da.txt
text
MD5: 2c24dc5f997d69011cfd57ec51d71d9b
SHA256: 380de44e2f4381d468bb657d968a18573559be4fc3353c0261eb3848e6ae4575
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\cs.txt
text
MD5: 54408e605d8510f584155fc26d1c51af
SHA256: 7357c7db6bcddcda80e09fad9b6287b8acb91658a4bc99a8bcec396e705866b5
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-T9HA2.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-N8LHK.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\bn-BD.txt
text
MD5: ee01605f2fa3ab6292c54ce3dd74ab94
SHA256: 1136bda886b5bb9078d109e56509be14bb393e49d3142f123b28ead655c64488
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\bs.txt
text
MD5: 258a25c307c83afb79cd06b239e17244
SHA256: 3487520567d24cbc4fd3fc3fa1bd2ace9694da53aeb4be40f6dfb14c417f57d8
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\ca.txt
text
MD5: 05c5afbfe2a308e95266be63836690bb
SHA256: bbb2c8e7d409dd7f6b9eac465fbbcc646c248d32bad15fc361410ae997505d81
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-QMU69.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-03BJP.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-2F34K.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\bg.txt
text
MD5: e1d1e051026223916f04af6b838ed370
SHA256: 0c390b446d8220b9c64a9c637b31495b193fa888137b37c80b562f6f4d44c9b2
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\be.txt
text
MD5: f5ddd5d6a136fd4aa0dce54243aee7b6
SHA256: b7c045a1f3a92b8134412d3fbff03cf2bcf4d290a611ba75ab08bdcec637b52e
3072
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Last Active\{577B0B09-A95D-11E9-B506-5254004A04AF}.dat
binary
MD5: 526458b1baa69b68e9086481b911f599
SHA256: bf5e7fe4d626ff176f105f53cda066ce2d3e11d71857a42d0a855b1a9ff93a0e
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\ar.txt
text
MD5: fb313a562c24b0ffe0981d2a58f35c1c
SHA256: a5f8eeb6780c31c4f507495b1a6f12bfc0919274e7d7da841dcfb8d89c664931
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\is-7INJ0.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-5J3T3.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-T4TL4.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\locales\is-H1TB4.tmp
––
MD5:  ––
SHA256:  ––
3072
iexplore.exe
C:\Users\admin\AppData\Local\Temp\~DF17264C075F7A05E8.TMP
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\is-9JNPD.tmp
––
MD5:  ––
SHA256:  ––
3072
iexplore.exe
C:\Users\admin\AppData\Local\Temp\~DFAC3B998095F054B8.TMP
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\is-5VG3B.tmp
––
MD5:  ––
SHA256:  ––
2416
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\TOTL9IUE\icon-gallery[1].png
image
MD5: 2583bc5e56263fc6122966fa83b4675d
SHA256: a2902f87b2687446a5c3bfecc0473f71447e342d19231db01119aa4e84e9b48b
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\is-RBDVC.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\learnmore.url
text
MD5: 0a933b6964a69f08a3c7b22831247eab
SHA256: 77b7af088dcb38fd9a0d540858f07bb03e3a96a0d128cb69be2bc1d26f8b2568
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\learnmore_ru.url
text
MD5: 5711278cd3487ee9ea475490b500ecc3
SHA256: 52390bbea655ebbabf8ad68300c137418df6b02add34a9ee67c588b2b9f36965
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\is-D9OKE.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\is-HMH4M.tmp
––
MD5:  ––
SHA256:  ––
2416
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\1OR02DRA\icon-logout[1].png
image
MD5: 738372cb68d7603a7f8dd4bbd8dab7b6
SHA256: 18a32c3887950a2b4fc86a455d1e9ebbc8be9e7cdb0b920a82569ddcbcabd0b8
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\5.4.0.35\is-10H7Q.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Users\admin\AppData\Local\Temp\is-3FI61.tmp\browser-elements-eula-tr.rtf
text
MD5: 4603351abc2d1c2a702cd26814da3656
SHA256: fe381daf8d96c198ef3782d348553f45ade8dec05aa8616bf41e24bebcc83152
2788
setup-lightshot.tmp
C:\Users\admin\AppData\Local\Temp\is-3FI61.tmp\is-NML39.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Users\admin\AppData\Local\Temp\is-3FI61.tmp\browser-elements-eula-ru.rtf
text
MD5: 4f0097a6f888e44fcd5b9747278f32f3
SHA256: 1aee98ae0d700e8def3950f39f238ab2059c20029ee906fe99d5264c6913fbbf
2788
setup-lightshot.tmp
C:\Users\admin\AppData\Local\Temp\is-3FI61.tmp\browser-eula-tr.rtf
text
MD5: 7f0bd956e453c25c8ef118c07de27651
SHA256: 7b6814d66eaada437cc705757e546d0bb5431e74f24849eade487f6676d866c5
2788
setup-lightshot.tmp
C:\Users\admin\AppData\Local\Temp\is-3FI61.tmp\elements-eula-ru.rtf
text
MD5: 9b89832cb406f3e32365a4b948bff0cd
SHA256: 70bb171a009cc272c175e82f308b69e7e9616cc12849c84b413caaab2699a22d
2788
setup-lightshot.tmp
C:\Users\admin\AppData\Local\Temp\is-3FI61.tmp\elements-eula-tr.rtf
text
MD5: 535fe03d3775b0e7dbbbd184602dcdff
SHA256: ccbd55d1c18ae11a9c5fcdecd2638c46bfb02f1b4833382e8dadbb0e8bb16dd9
2788
setup-lightshot.tmp
C:\Users\admin\AppData\Local\Temp\is-3FI61.tmp\is-7LOS7.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Users\admin\AppData\Local\Temp\is-3FI61.tmp\is-I9V18.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Users\admin\AppData\Local\Temp\is-3FI61.tmp\is-D99VN.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Users\admin\AppData\Local\Temp\is-3FI61.tmp\is-BO4R2.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Users\admin\AppData\Local\Temp\is-3FI61.tmp\browser-eula-ru.rtf
text
MD5: 1d1ac3ce9b58cedc3aa01a95d5a1108f
SHA256: 2c84956531c352e849b75bb52013c7fcfe52c682af840455e86c664ce16877dd
2788
setup-lightshot.tmp
C:\Users\admin\AppData\Local\Temp\is-3FI61.tmp\browser-page-tr.rtf
text
MD5: 7c767e77cf32501f35888a14e2c617bb
SHA256: 3283e81732667a4a87c3da1259240041edd56bd93b4d27d78d8d8f8bf9823db7
2788
setup-lightshot.tmp
C:\Users\admin\AppData\Local\Temp\is-3FI61.tmp\browser-page-ru.rtf
text
MD5: 0e5c451f9c309d96bef2023350788316
SHA256: bac74855dce2ed5eaaf919b948913e596d813e3a93da793f3b39b9a611db2482
2788
setup-lightshot.tmp
C:\Users\admin\AppData\Local\Temp\is-3FI61.tmp\is-KHDHI.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Users\admin\AppData\Local\Temp\is-3FI61.tmp\is-48GTA.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Users\admin\AppData\Local\Temp\is-3FI61.tmp\is-0L8KA.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Users\admin\AppData\Local\Temp\is-3FI61.tmp\yandex_browser_setup_tr.bmp
image
MD5: 212974a3c3a7dcc2ef4790d77f6d76c5
SHA256: 25075c00c095053e4717a121a162d47b263d24124bfa7465820d8cc28426829a
2788
setup-lightshot.tmp
C:\Users\admin\AppData\Local\Temp\is-3FI61.tmp\is-5UUEV.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Users\admin\AppData\Local\Temp\is-3FI61.tmp\yandex_browser_setup_ru.bmp
image
MD5: 13067a53c21ebf2042183584a40b4965
SHA256: a92ddceba09ad4e34ce4f5bc0a83e56d1e7b43369be4c433d0cd9130c5e2a833
2788
setup-lightshot.tmp
C:\Users\admin\AppData\Local\Temp\is-3FI61.tmp\is-MI8FO.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Users\admin\AppData\Local\Temp\is-3FI61.tmp\yandex_logo_en.bmp
image
MD5: 3f00f6f1ab01507980a28aa91ae6625a
SHA256: 48bcd5445a3a859f0aaf6ea5fe17bfd1ec9d479f59d0ce37fe6c7cbc4362440c
2788
setup-lightshot.tmp
C:\Users\admin\AppData\Local\Temp\is-3FI61.tmp\yandex_logo_ru.bmp
image
MD5: 3cc6dc168314869272d24653454523b8
SHA256: a8f8a3e92bf296475abd363e513993ac30c22fbe8b449feeec1e4489c68309c2
2788
setup-lightshot.tmp
C:\Users\admin\AppData\Local\Temp\is-3FI61.tmp\is-AU2B5.tmp
––
MD5:  ––
SHA256:  ––
2788
setup-lightshot.tmp
C:\Users\admin\AppData\Local\Temp\is-3FI61.tmp\is-NIH2T.tmp
––
MD5:  ––
SHA256:  ––
3304
Updater.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
dat
MD5: d7a950fefd60dbaa01df2d85fefb3862
SHA256: 75d0b1743f61b76a35b1fedd32378837805de58d79fa950cb6e8164bfa72073a
2788
setup-lightshot.tmp
C:\Program Files\Skillbrains\lightshot\is-UMKB9.tmp
––
MD5:  ––
SHA256:  ––
3304
Updater.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
text
MD5: 04ab5cd833144dfbcbfed1608fdc5b2b
SHA256: 86df642ad7afff28fd906643cb97273dcfbe27285ffdc97c255ff8fc382026b7
3072
iexplore.exe
C:\Users\admin\AppData\Local\Temp\~DF208FE3676E8807D3.TMP
––
MD5:  ––
SHA256:  ––

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
8
TCP/UDP connections
19
DNS requests
6
Threats
1

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
3304 Updater.exe GET 200 172.217.18.110:80 http://www.google-analytics.com/__utm.gif?utmwv=4.4sh&utmac=UA-38715315-1&utmp=%2FUpdater%2Fusr%2FAddProduct%2Fupdater&utmcc=__utma%3D1.53841563455386.1563455386..1563455386.1&utmn=53841563455386&utmsc=32-bit&utmsr=1280x720 US
image
whitelisted
2600 Updater.exe GET 200 104.20.13.105:80 http://updater.prntscr.com/getver/updater?ping=true US
xml
malicious
2600 Updater.exe GET 200 172.217.18.110:80 http://www.google-analytics.com/__utm.gif?utmwv=4.4sh&utmac=UA-38715315-1&utmp=%2FUpdater%2Fusr%2FPing&utmcc=__utma%3D1.53841563455386.1563455386..1563455387.2&utmn=53871563455387&utmsc=32-bit&utmsr=1280x720 US
image
whitelisted
2788 setup-lightshot.tmp GET 200 172.217.18.110:80 http://www.google-analytics.com/__utm.gif?&utmn=2834658&utmwv=4.4sh&utmp=Lightshot/Install%20version/5.4.0.35&utmac=UA-11927135-1&utmcc=__utma%3D1.32755658.1.1.1.1 US
image
whitelisted
2788 setup-lightshot.tmp GET 200 172.217.18.110:80 http://www.google-analytics.com/__utm.gif?&utmn=3867685&utmwv=4.4sh&utmp=Lightshot/General%20Installation/default&utmac=UA-11927135-1&utmcc=__utma%3D1.32755658.1.1.1.1 US
image
whitelisted
2788 setup-lightshot.tmp GET 200 172.217.18.110:80 http://www.google-analytics.com/__utm.gif?&utmn=4791670&utmwv=4.4sh&utmp=Lightshot/Language/english&utmac=UA-11927135-1&utmcc=__utma%3D1.32755658.1.1.1.1 US
image
whitelisted
3072 iexplore.exe GET 200 204.79.197.200:80 http://www.bing.com/favicon.ico US
image
whitelisted
2416 iexplore.exe GET 301 104.20.13.105:80 http://app.prntscr.com/thankyou_desktop.html US
html
malicious

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
3304 Updater.exe 172.217.18.110:80 Google Inc. US whitelisted
2600 Updater.exe 104.20.13.105:80 Cloudflare Inc US shared
2600 Updater.exe 172.217.18.110:80 Google Inc. US whitelisted
3304 Updater.exe 77.88.21.119:443 YANDEX LLC RU whitelisted
2600 Updater.exe 77.88.21.119:443 YANDEX LLC RU whitelisted
2788 setup-lightshot.tmp 172.217.18.110:80 Google Inc. US whitelisted
2364 updater.exe 172.217.18.110:80 Google Inc. US whitelisted
3072 iexplore.exe 204.79.197.200:80 Microsoft Corporation US whitelisted
2416 iexplore.exe 104.20.13.105:80 Cloudflare Inc US shared
2416 iexplore.exe 104.20.13.105:443 Cloudflare Inc US shared
2364 updater.exe 77.88.21.119:443 YANDEX LLC RU whitelisted
2416 iexplore.exe 104.20.14.105:443 Cloudflare Inc US shared
2416 iexplore.exe 172.217.18.110:443 Google Inc. US whitelisted
3072 iexplore.exe 104.20.13.105:443 Cloudflare Inc US shared

DNS requests

Domain IP Reputation
www.google-analytics.com 172.217.18.110
whitelisted
updater.prntscr.com 104.20.13.105
104.20.14.105
malicious
mc.yandex.ru 77.88.21.119
87.250.250.119
87.250.251.119
93.158.134.119
whitelisted
www.bing.com 204.79.197.200
13.107.21.200
whitelisted
app.prntscr.com 104.20.13.105
104.20.14.105
malicious
st.prntscr.com 104.20.14.105
104.20.13.105
malicious

Threats

PID Process Class Message
2600 Updater.exe Misc activity SUSPICIOUS [PTsecurity] Cmd.Powershell.Download HTTP UserAgent (Win7)

Debug output strings

No debug info.