General Info Watch the FULL Interactive Analysis at ANY.RUN!

File name

1.rar

Verdict
Malicious activity
Analysis date
1/11/2019, 08:03:38
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-rar
File info:
RAR archive data, v4, os: Win32
MD5

b0f4411635565131bd0e77f0eb0383f1

SHA1

b7b4c7c7c8d28978ad90c5dff3a2725adb059622

SHA256

48821b749239f46d64ce386c026f248f00c979ed0dbd3bc92bde713c6354c9d0

SSDEEP

98304:0TuGTN4Sj59f+BZmbH21GntctlSR08jIR9RnEW2fP:kN/92rmbH216Ol4fjiPGP

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
300 seconds
Additional time used
240 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads dropped or rewritten executable
  • sysdiag.exe (PID: 3432)
  • DllHost.exe (PID: 2276)
  • sysdiag.exe (PID: 3664)
  • explorer.exe (PID: 284)
  • WinRAR.exe (PID: 3088)
  • driver-setup.exe (PID: 2156)
  • SpyAgentSetup.exe (PID: 3496)
Application was dropped or rewritten from another process
  • sysdiag.exe (PID: 3664)
  • npf_mgm.exe (PID: 2200)
  • driver-setup.exe (PID: 2156)
Creates a software uninstall entry
  • SpyAgentSetup.exe (PID: 3496)
Creates executable files which already exist in Windows
  • SpyAgentSetup.exe (PID: 3496)
Executable content was dropped or overwritten
  • driver-setup.exe (PID: 2156)
  • SpyAgentSetup.exe (PID: 3496)
Creates files in the program directory
  • driver-setup.exe (PID: 2156)
  • SpyAgentSetup.exe (PID: 3496)
Creates files in the driver directory
  • driver-setup.exe (PID: 2156)
Creates files in the Windows directory
  • driver-setup.exe (PID: 2156)
  • SpyAgentSetup.exe (PID: 3496)

No info indicators.

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.rar
|   RAR compressed archive (v-4.x) (58.3%)
.rar
|   RAR compressed archive (gen) (41.6%)
EXIF
ZIP
CompressedSize:
1336695
UncompressedSize:
1426944
OperatingSystem:
Win32
ModifyDate:
2007:12:08 20:57:08
PackingMethod:
Normal
ArchivedFileName:
Spytech SpyAgent Stealth 6.2\Crack\sysdiag.exe

Screenshots

Processes

Total processes
42
Monitored processes
8
Malicious processes
3
Suspicious processes
2

Behavior graph

+
start drop and start drop and start drop and start winrar.exe no specs spyagentsetup.exe driver-setup.exe npf_mgm.exe no specs sysdiag.exe no specs explorer.exe no specs Thumbnail Cache Out of Proc Server no specs sysdiag.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
284
CMD
C:\Windows\Explorer.EXE
Path
C:\Windows\explorer.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Windows Explorer
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\slc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\profapi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\iconcodecservice.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sndvolsso.dll
c:\windows\system32\hid.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\timedate.cpl
c:\windows\system32\atl.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\actxprxy.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\userenv.dll
c:\windows\system32\shacct.dll
c:\windows\system32\samlib.dll
c:\windows\system32\samcli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\winanr.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\msftedit.dll
c:\windows\system32\msls31.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\authui.dll
c:\windows\system32\cryptui.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\gameux.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\wer.dll
c:\windows\system32\msiltcfg.dll
c:\windows\system32\version.dll
c:\windows\system32\msi.dll
c:\windows\system32\winsta.dll
c:\windows\system32\psapi.dll
c:\windows\system32\networkexplorer.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wdmaud.drv
c:\windows\system32\ksuser.dll
c:\windows\system32\avrt.dll
c:\windows\system32\audioses.dll
c:\windows\system32\msacm32.drv
c:\windows\system32\msacm32.dll
c:\windows\system32\midimap.dll
c:\windows\system32\stobject.dll
c:\windows\system32\batmeter.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\es.dll
c:\windows\system32\prnfldr.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dxp.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\syncreg.dll
c:\windows\ehome\ehsso.dll
c:\windows\system32\netshell.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\alttab.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
c:\program files\filezilla ftp client\fzshellext.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\pnidui.dll
c:\windows\system32\qutil.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\npmproxy.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\wlanapi.dll
c:\windows\system32\wlanutil.dll
c:\windows\system32\wwanapi.dll
c:\windows\system32\wwapi.dll
c:\windows\system32\qagent.dll
c:\windows\system32\srchadmin.dll
c:\windows\system32\sxs.dll
c:\windows\system32\bthprops.cpl
c:\windows\system32\ieframe.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\synccenter.dll
c:\windows\system32\actioncenter.dll
c:\windows\system32\imapi2.dll
c:\windows\system32\hgcpl.dll
c:\windows\system32\provsvc.dll
c:\windows\system32\netprofm.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\fxsst.dll
c:\windows\system32\fxsapi.dll
c:\windows\system32\fxsresm.dll
c:\windows\system32\wscinterop.dll
c:\windows\system32\wscapi.dll
c:\windows\system32\wscui.cpl
c:\windows\system32\werconcpl.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\wercplsupport.dll
c:\windows\system32\msxml6.dll
c:\windows\system32\hcproviders.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\mpr.dll
c:\windows\system32\drprov.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\thumbcache.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\program files\winrar\winrar.exe
c:\windows\system32\zipfldr.dll
c:\program files\winrar\rarext.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\desktop\spytech spyagent stealth 6.2\spyagentsetup.exe
c:\windows\system32\imageres.dll
c:\windows\system32\msinfo32.exe
c:\windows\system32\structuredquery.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\audiodev.dll
c:\windows\system32\wmvcore.dll
c:\windows\system32\wmasf.dll
c:\windows\system32\ehstorapi.dll
c:\windows\system32\twext.dll
c:\windows\system32\syncui.dll
c:\windows\system32\synceng.dll
c:\program files\notepad++\nppshell_06.dll
c:\windows\system32\acppage.dll
c:\windows\system32\sendmail.dll
c:\windows\system32\mydocs.dll
c:\windows\system32\wfsr.dll
c:\program files\spytech software\spytech spyagent\nostealth.exe
c:\program files\spytech software\spytech spyagent\sysdiag.exe
c:\windows\unvise32.exe
c:\windows\system32\sinvfct.dll
c:\users\admin\desktop\spytech spyagent stealth 6.2\crack\sysdiag.exe

PID
3088
CMD
"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\1.rar"
Path
C:\Program Files\WinRAR\WinRAR.exe
Indicators
No indicators
Parent process
explorer.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Alexander Roshal
Description
WinRAR archiver
Version
5.60.0
Modules
Image
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\uxtheme.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\riched20.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\mpr.dll
c:\windows\system32\drprov.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\winmm.dll
c:\windows\system32\portabledeviceapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\audiodev.dll
c:\windows\system32\wmvcore.dll
c:\windows\system32\wmasf.dll
c:\windows\system32\ehstorapi.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\sinvfct.dll

PID
3496
CMD
"C:\Users\admin\Desktop\Spytech SpyAgent Stealth 6.2\SpyAgentSetup.exe"
Path
C:\Users\admin\Desktop\Spytech SpyAgent Stealth 6.2\SpyAgentSetup.exe
Indicators
Parent process
explorer.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\desktop\spytech spyagent stealth 6.2\spyagentsetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\users\admin\appdata\local\temp\~vis0000\vise32ex.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sxs.dll
c:\windows\system32\actxprxy.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\program files\spytech software\spytech spyagent\sysdiag.exe
c:\program files\spytech software\spytech spyagent\nostealth.exe
c:\progra~1\spytec~1\spytec~1\driver-setup.exe
c:\windows\unvise32.exe
c:\windows\system32\netutils.dll

PID
2156
CMD
"C:\PROGRA~1\SPYTEC~1\SPYTEC~1\driver-setup.exe" -s
Path
C:\PROGRA~1\SPYTEC~1\SPYTEC~1\driver-setup.exe
Indicators
Parent process
SpyAgentSetup.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\progra~1\spytec~1\spytec~1\driver-setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\version.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\users\admin\appdata\local\temp\3722dokn\unpack.dll
c:\windows\system32\crtdll.dll
c:\windows\system32\devrtl.dll
c:\program files\winconfig\npf_mgm.exe

PID
2200
CMD
"C:\Program Files\WinConfig\npf_mgm.exe" -r
Path
C:\Program Files\WinConfig\npf_mgm.exe
Indicators
No indicators
Parent process
driver-setup.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
CACE Technologies
Description
npf_mgm
Version
3, 1, 0, 27
Modules
Image
c:\program files\winconfig\npf_mgm.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
3664
CMD
"C:\Program Files\Spytech Software\Spytech SpyAgent\sysdiag.exe"
Path
C:\Program Files\Spytech Software\Spytech SpyAgent\sysdiag.exe
Indicators
No indicators
Parent process
SpyAgentSetup.exe
User
admin
Integrity Level
HIGH
Version:
Company
Description
Version
Modules
Image
c:\program files\spytech software\spytech spyagent\sysdiag.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\snmpapi.dll
c:\windows\system32\sinvfct.dll
c:\windows\system32\mpr.dll
c:\windows\system32\winspool.drv
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\riched20.dll
c:\windows\system32\inetmib1.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll

PID
2276
CMD
C:\Windows\system32\DllHost.exe /Processid:{AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
Path
C:\Windows\system32\DllHost.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
COM Surrogate
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\dllhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sinvfct.dll
c:\windows\system32\thumbcache.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\psapi.dll
c:\windows\system32\propsys.dll

PID
3432
CMD
"C:\Users\admin\Desktop\Spytech SpyAgent Stealth 6.2\Crack\sysdiag.exe"
Path
C:\Users\admin\Desktop\Spytech SpyAgent Stealth 6.2\Crack\sysdiag.exe
Indicators
No indicators
Parent process
explorer.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\desktop\spytech spyagent stealth 6.2\crack\sysdiag.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\mpr.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\winspool.drv
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\sinvfct.dll
c:\windows\system32\snmpapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll

Registry activity

Total events
5783
Read events
4043
Write events
1737
Delete events
3

Modification events

PID
Process
Operation
Key
Name
Value
3088
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
ShellExtBMP
3088
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
ShellExtIcon
3088
WinRAR.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
3088
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
0
C:\Users\admin\AppData\Local\Temp\1.rar
3088
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
name
120
3088
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
size
80
3088
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
type
120
3088
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
mtime
100
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rar\OpenWithList
a
WinRAR.exe
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rar\OpenWithList
MRUList
a
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\JvaENE\JvaENE.rkr
00000000000000000000000000000000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002E0000003D00000085431500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
NodeSlots
02020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
MRUListEx
0000000001000000020000000700000006000000030000000500000004000000FFFFFFFF
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
8
8000310000000000973A848A10005350595445437E312E320000660008000400EFBE2B4E8B382B4E8B382A00000067DF0000000003000000000000000000000000000000530070007900740065006300680020005300700079004100670065006E007400200053007400650061006C0074006800200036002E00320000001A000000
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
MRUListEx
080000000000000001000000020000000700000006000000030000000500000004000000FFFFFFFF
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
NodeSlots
0202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\8
NodeSlot
95
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\8
MRUListEx
FFFFFFFF
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell
KnownFolderDerivedFolderType
{57807898-8C4F-4462-BB63-71042380B109}
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar
Locked
1
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell
SniffedFolderType
Generic
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
@C:\Windows\system32\msinfo32.exe,-10001
System Information File
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell
NavBar
000000000000000000000000000000008B000000870000003153505305D5CDD59C2E1B10939708002B2CF9AE6B0000005A000000007B00360044003800420042003300440033002D0039004400380037002D0034004100390031002D0041004200350036002D003400460033003000430046004600450046004500390046007D005F0057006900640074006800000013000000F00000000000000000000000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe\OpenWithProgids
exefile
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\Qrfxgbc\Fclgrpu FclNtrag Fgrnygu 6.2\FclNtragFrghc.rkr
00000000010000000000000000000000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFFD0FFDCE37BA9D40100000000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000003D00000085431500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\rkcybere.rkr
00000000060000000900000070EA0300000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF6012F7D45C48D40100000000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000003D0000004D541500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\Qrfxgbc\Fclgrpu FclNtrag Fgrnygu 6.2\FclNtragFrghc.rkr
000000000100000000000000F0070000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFFD0FFDCE37BA9D40100000000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000003D0000003D5C1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\rkcybere.rkr
00000000060000000A00000070EA0300000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF6012F7D45C48D40100000000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000003E0000003D5C1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\rkcybere.rkr
00000000060000000A0000008FEA0300000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF6012F7D45C48D40100000000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000003E0000005C5C1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\Qrfxgbc\Fclgrpu FclNtrag Fgrnygu 6.2\FclNtragFrghc.rkr
000000000100000000000000201A0000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFFD0FFDCE37BA9D40100000000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000003E0000008C6E1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\Qrfxgbc\Fclgrpu FclNtrag Fgrnygu 6.2\FclNtragFrghc.rkr
0000000001000000000000009E1F0000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFFD0FFDCE37BA9D40100000000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000003E0000000A741500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\Qrfxgbc\Fclgrpu FclNtrag Fgrnygu 6.2\FclNtragFrghc.rkr
00000000010000000000000028230000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFFD0FFDCE37BA9D40100000000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000003E00000094771500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\Qrfxgbc\Fclgrpu FclNtrag Fgrnygu 6.2\FclNtragFrghc.rkr
00000000010000000000000058280000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFFD0FFDCE37BA9D40100000000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000003E000000C47C1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\Qrfxgbc\Fclgrpu FclNtrag Fgrnygu 6.2\FclNtragFrghc.rkr
0000000001000000000000002A2D0000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFFD0FFDCE37BA9D40100000000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000003E00000096811500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\Qrfxgbc\Fclgrpu FclNtrag Fgrnygu 6.2\FclNtragFrghc.rkr
000000000100000000000000CA2F0000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFFD0FFDCE37BA9D40100000000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000003E00000036841500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\Qrfxgbc\Fclgrpu FclNtrag Fgrnygu 6.2\FclNtragFrghc.rkr
00000000010000000000000025330000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFFD0FFDCE37BA9D40100000000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000003E00000091871500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
NodeSlots
020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
MRUListEx
010000000800000000000000020000000700000006000000030000000500000004000000FFFFFFFF
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\96\Shell
SniffedFolderType
Generic
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\Qrfxgbc\Fclgrpu FclNtrag Fgrnygu 6.2\FclNtragFrghc.rkr
000000000100000000000000A6350000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFFD0FFDCE37BA9D40100000000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000003E000000128A1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
284
explorer.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spytech SpyAgent\SpyAgent PC Surveillance.lnk
1
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spytech SpyAgent\SpyAgent PC Surveillance.lnk
1
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spytech SpyAgent\Stop SpyAgent Stealth Mode.lnk
1
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spytech SpyAgent\Stop SpyAgent Stealth Mode.lnk
1
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\Qrfxgbc\Fclgrpu FclNtrag Fgrnygu 6.2\FclNtragFrghc.rkr
000000000100000001000000A6350000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFFD0FFDCE37BA9D40100000000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000003F000000128A1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\rkcybere.rkr
00000000060000000A0000007D3B0400000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF6012F7D45C48D40100000000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000003F00000000DB1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\Qrfxgbc\Fclgrpu FclNtrag Fgrnygu 6.2\FclNtragFrghc.rkr
00000000010000000100000073480000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFFD0FFDCE37BA9D40100000000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000003F000000CDED1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\rkcybere.rkr
00000000060000000B0000007D3B0400000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF6012F7D45C48D40100000000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F00000040000000CDED1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702060000000B0000007D3B04007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000005C004400650073006B0074006F0070005C00530070007900740065006300680020005300700079004100670065006E007400200053007400650061006C0074006800200036002E0032005C005300700079004100670065006E007400530065007400750070002E006500780065000000FEFFFFFFE72FC277822EC277000000001CE530020000000090E430020000000090E430027800000048E43002FE72C27754E5300278E73002780000001800000090E430020000000064E4300251EEC27707B5FA75000000001CE530021E00000088E4300220EFC277F00737030AA5C1771E000000000000001CE5300200000000FBB5FA7508E53002D6A8C377A4E43002BCE43002000000000000000000002C00F00737035A008A000E0837030800470032020000BCE4300200000000010500006806370301000000E807370311000000B8452F00B0452F001000000004E5300220EFC27750E50000801209E504E5300282913C7650E5300208E5300227953C76000000008C2BF10230E53002CD943C768C2BF1020027F102D4E53002E1943C76000000000027F102D4E5300238E53002
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\rkcybere.rkr
00000000060000000B000000A63C0400000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF6012F7D45C48D40100000000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F00000040000000F6EE1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702060000000B000000A63C04007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E00650078006500000065007800650000005C004400650073006B0074006F0070005C00530070007900740065006300680020005300700079004100670065006E007400200053007400650061006C0074006800200036002E0032005C005300700079004100670065006E007400530065007400750070002E006500780065000000FEFFFFFFE72FC277822EC277000000001CE530020000000090E430020000000090E430027800000048E43002FE72C27754E5300278E73002780000001800000090E430020000000064E4300251EEC27707B5FA75000000001CE530021E00000088E4300220EFC277F00737030AA5C1771E000000000000001CE5300200000000FBB5FA7508E53002D6A8C377A4E43002BCE43002000000000000000000002C00F00737035A008A000E0837030800470032020000BCE4300200000000010500006806370301000000E807370311000000B8452F00B0452F00100000004CE50000881209E5FCE4300282913C764CE5300200E5300227953C76000000008C2BF10228E53002CD943C768C2BF102D4E530020027F102E1943C76000000000027F102D4E5300230E53002
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\Fclgrpu Fbsgjner\Fclgrpu FclNtrag\flfqvnt.rkr
00000000000000000000000062070000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000004000000058F61500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702060000000B000000A63C04007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E00650078006500000065007800650000005C004400650073006B0074006F0070005C00530070007900740065006300680020005300700079004100670065006E007400200053007400650061006C0074006800200036002E0032005C005300700079004100670065006E007400530065007400750070002E006500780065000000FEFFFFFFE72FC277822EC277000000001CE530020000000090E430020000000090E430027800000048E43002FE72C27754E5300278E73002780000001800000090E430020000000064E4300251EEC27707B5FA75000000001CE530021E00000088E4300220EFC277F00737030AA5C1771E000000000000001CE5300200000000FBB5FA7508E53002D6A8C377A4E43002BCE43002000000000000000000002C00F00737035A008A000E0837030800470032020000BCE4300200000000010500006806370301000000E807370311000000B8452F00B0452F00100000004CE50000881209E5FCE4300282913C764CE5300200E5300227953C76000000008C2BF10228E53002CD943C768C2BF102D4E530020027F102E1943C76000000000027F102D4E5300230E53002
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\rkcybere.rkr
00000000060000000C000000A63C0400000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF6012F7D45C48D40100000000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000004100000058F61500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702060000000C000000A63C04007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C005300700079007400650063006800200053006F006600740077006100720065005C00530070007900740065006300680020005300700079004100670065006E0074005C0073007900730064006900610067002E006500780065000000300090E1300038BE6F0654E430022FB13B7680B06E7694F13002381E3C7614633C76B8152F0088E430020000000062000000381209E568E4300200000000D0327406C831740674E430023DA93C7600000000FBFFFF7F98E4300202000000C807760648F0570620662C000000000001100211FFFFFFFF000000000000000000000000A14B2C03BD4B2C03A14B2C03000000000000000000000000080000002E006C006E006B00000065006E00740011000000B8452F00B0452F0072007600650069006C006C0050E50000801209E504E5300282913C7650E5300208E5300227953C76000000008C2BF10230E53002CD943C768C2BF1020027F102D4E53002E1943C76000000000027F102D4E5300238E53002
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\rkcybere.rkr
00000000060000000C000000B63C0400000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF6012F7D45C48D40100000000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000004100000068F61500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702060000000C000000B63C04007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E00650078006500000098E33002AD6A0C770100000033030110B4E3300246740B77D0074F02000000000100000033030110EC0A4F02FCE3300228420C7733030110F4084F02EC084F02F4084F0200000000D0074F0201000000CC0A4F02EC0A4F02F4E3300258690C7700000000D0074F0214E430020B8C0B770100000000000000537A0B773303011000200000000000000100000060E43002361707763303011010084F020500000000000000FFFFFFFFD0074F02000000005CE4300288E43002000000000000000000000000B4E43002D0353500000000004091067609008001ACE43002355907763303011040F674060500000094E43002506A0C771CC0107701000000EF7A0B77330301101D00000000200000ACE4300263590776B4E43002000000000000000033030110406602760100000018E53002A136B3770000000000000000E0F6340018E5300211000000B8452F00B0452F0000002C004CE50000881209E5FCE4300282913C764CE5300200E5300227953C76000000008C2BF10228E53002CD943C768C2BF102D4E530020027F102E1943C76000000000027F102D4E5300230E53002
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\rkcybere.rkr
00000000060000000D000000B63C0400000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF6012F7D45C48D40100000000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000004200000068F61500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702060000000D000000B63C04007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E00650078006500000000000000F500000000000000000000009049FE75777C09E5D0E330026A70FA75505E2F000000000888E43002FFFFFFFF40BE6F06FFFFFFFF0000000000000000FCE33002A470FA75E0F207000000000088E43002FFFFFFFF40BE6F06FFFFFFFF9049FE75000000000000000024E43002D574FA75000400000000000088E43002FFFFFFFF40BE6F06FFFFFFFFD8E0300090E1300038BE6F0654E430022FB13B7680B06E7694F13002381E3C7614633C76B8152F0088E430020000000062000000381209E568E4300200000000D0327406C831740674E430023DA93C7600000000FBFFFF7F98E4300202000000C807760648F0570620662C000000000001100211FFFFFFFF000000000000000000000000A14B2C03BD4B2C03A14B2C03000000000000000000000000080000002E006C006E006B00000065006E00740011000000B8452F00B0452F0072007600650069006C006C0050E50000801209E504E5300282913C7650E5300208E5300227953C76000000008C2BF10230E53002CD943C768C2BF1020027F102D4E53002E1943C76000000000027F102D4E5300238E53002
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\Fclgrpu Fbsgjner\Fclgrpu FclNtrag\flfqvnt.rkr
0000000000000000000000001F0D0000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000004200000025FC1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702060000000D000000B63C04007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E00650078006500000000000000F500000000000000000000009049FE75777C09E5D0E330026A70FA75505E2F000000000888E43002FFFFFFFF40BE6F06FFFFFFFF0000000000000000FCE33002A470FA75E0F207000000000088E43002FFFFFFFF40BE6F06FFFFFFFF9049FE75000000000000000024E43002D574FA75000400000000000088E43002FFFFFFFF40BE6F06FFFFFFFFD8E0300090E1300038BE6F0654E430022FB13B7680B06E7694F13002381E3C7614633C76B8152F0088E430020000000062000000381209E568E4300200000000D0327406C831740674E430023DA93C7600000000FBFFFF7F98E4300202000000C807760648F0570620662C000000000001100211FFFFFFFF000000000000000000000000A14B2C03BD4B2C03A14B2C03000000000000000000000000080000002E006C006E006B00000065006E00740011000000B8452F00B0452F0072007600650069006C006C0050E50000801209E504E5300282913C7650E5300208E5300227953C76000000008C2BF10230E53002CD943C768C2BF1020027F102D4E53002E1943C76000000000027F102D4E5300238E53002
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell
WFlags
0
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell
ShowCmd
1
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell
HotKey
0
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\96\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Rev
0
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\96\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
1092616193
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\96\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Vid
{137E7700-3573-11CF-AE69-08002B2E1262}
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\rkcybere.rkr
00000000060000000D000000523D0400000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF6012F7D45C48D40100000000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F00000042000000C1FC1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702060000000D000000523D04007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000000000000088E43002FFFFFFFF40BE6F06FFFFFFFF9049FE75000000000000000024E43002D574FA75000400000000000088E43002FFFFFFFF40BE6F06FFFFFFFFD8E0300090E1300038BE6F0654E430022FB13B7680B06E7694F13002381E3C7614633C76B8152F0088E430020000000062000000381209E568E4300200000000D0327406C831740674E430023DA93C7600000000FBFFFF7F98E4300202000000C807760648F0570620662C000000000001100211FFFFFFFF000000000000000000000000A14B2C03BD4B2C03A14B2C03000000000000000000000000080000002E006C006E006B00000065006E00740011000000B8452F00B0452F00720076004CE50000881209E5FCE4300282913C764CE530028C2B0000941209E510E53002B69C3C76902BF1024C06000028E530020027F10234E53002789C3C7636913C7611000000B8452F00B0452F00D0E530022027F102A0E50000541309E550E5300282913C76A0E5300254E5300227953C76000000008C2BF1027CE53002CD943C768C2BF10228E630020027F102E1943C76000000000027F10228E6300284E53002
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\Fclgrpu Fbsgjner\Fclgrpu FclNtrag\flfqvnt.rkr
0000000000000000010000001F0D0000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F00000043000000C1FC1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702060000000D000000523D04007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000000000000088E43002FFFFFFFF40BE6F06FFFFFFFF9049FE75000000000000000024E43002D574FA75000400000000000088E43002FFFFFFFF40BE6F06FFFFFFFFD8E0300090E1300038BE6F0654E430022FB13B7680B06E7694F13002381E3C7614633C76B8152F0088E430020000000062000000381209E568E4300200000000D0327406C831740674E430023DA93C7600000000FBFFFF7F98E4300202000000C807760648F0570620662C000000000001100211FFFFFFFF000000000000000000000000A14B2C03BD4B2C03A14B2C03000000000000000000000000080000002E006C006E006B00000065006E00740011000000B8452F00B0452F00720076004CE50000881209E5FCE4300282913C764CE530028C2B0000941209E510E53002B69C3C76902BF1024C06000028E530020027F10234E53002789C3C7636913C7611000000B8452F00B0452F00D0E530022027F102A0E50000541309E550E5300282913C76A0E5300254E5300227953C76000000008C2BF1027CE53002CD943C768C2BF10228E630020027F102E1943C76000000000027F10228E6300284E53002
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\96\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Mode
4
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\96\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
LogicalViewMode
1
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\96\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
1092616209
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\96\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
IconSize
16
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\96\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
ColInfo
00000000000000000000000000000000FDDFDFFD100000000000000000000000040000001800000030F125B7EF471A10A5F102608C9EEBAC0A0000001001000030F125B7EF471A10A5F102608C9EEBAC0E0000007800000030F125B7EF471A10A5F102608C9EEBAC040000007800000030F125B7EF471A10A5F102608C9EEBAC0C00000050000000
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\96\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Sort
000000000000000000000000000000000100000030F125B7EF471A10A5F102608C9EEBAC0A00000001000000
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\96\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupView
0
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\96\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:FMTID
{00000000-0000-0000-0000-000000000000}
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\96\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:PID
0
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\96\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByDirection
1
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Modules\GlobalSettings\ProperTreeModuleInner
ProperTreeModuleInner
94000000900000003153505305D5CDD59C2E1B10939708002B2CF9AE4100000030000000004E0061007600500061006E0065005F00530068006F0077004C00690062007200610072007900500061006E00650000000B000000FFFF00003300000022000000004E0061007600500061006E0065005F0046006900720073007400520075006E0000000B000000000000000000000000000000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Modules\NavPane
ExpandedState
06000000160014001F8080A63C324DC29940B94D446DD2D7249E0000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000160014001F4225481E03947BC34DB131E946B44C8DD50000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000160014001F43983FFBB4EAC18D42A78AD1F5659CBA930000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D0000000000000000002000000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000160014001F580D1A2CF021BE504388B07367FC96EF3C0000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B00000000000000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000160014001F50E04FD020EA3A6910A2D808002B30309D0000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\rkcybere.rkr
00000000060000000E000000523D0400000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF6012F7D45C48D40100000000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F00000044000000C1FC1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802060000000E000000523D04007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000006100720065005C00530070007900740065006300680020005300700079004100670065006E0074005C0073007900730064006900610067002E0065007800650000002E0065007800650000000000000088E43002FFFFFFFF40BE6F06FFFFFFFF9049FE75000000000000000024E43002D574FA75000400000000000088E43002FFFFFFFF40BE6F06FFFFFFFFD8E0300090E1300038BE6F0654E430022FB13B7680B06E7694F13002381E3C7614633C76B8152F0088E430020000000062000000381209E568E4300200000000D0327406C831740674E430023DA93C7600000000FBFFFF7F98E4300202000000C807760648F0570620662C000000000001100211FFFFFFFF000000000000000000000000A14B2C03BD4B2C03A14B2C03000000000000000000000000080000002E006C006E006B00000065006E00740011000000B8452F00B0452F00720076004CE50000881209E550E50000801209E504E5300282913C7650E5300208E5300227953C76000000008C2BF10230E53002CD943C768C2BF1020027F102D4E53002E1943C76000000000027F102D4E5300238E53002060000000E000000523D04007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000006100720065005C00530070007900740065006300680020005300700079004100670065006E0074005C0073007900730064006900610067002E0065007800650000002E0065007800650000000000000088E43002FFFFFFFF40BE6F06FFFFFFFF9049FE75000000000000000024E43002D574FA75000400000000000088E43002FFFFFFFF40BE6F06FFFFFFFFD8E0300090E1300038BE6F0654E430022FB13B7680B06E7694F13002381E3C7614633C76B8152F0088E430020000000062000000381209E568E4300200000000D0327406C831740674E430023DA93C7600000000FBFFFF7F98E4300202000000C807760648F0570620662C000000000001100211FFFFFFFF000000000000000000000000A14B2C03BD4B2C03A14B2C03000000000000000000000000080000002E006C006E006B00000065006E00740011000000B8452F00B0452F00720076004CE50000881209E550E50000801209E504E5300282913C7650E5300208E5300227953C76000000008C2BF10230E53002CD943C768C2BF1020027F102D4E53002E1943C76000000000027F102D4E5300238E53002
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\Fclgrpu Fbsgjner\Fclgrpu FclNtrag\flfqvnt.rkr
000000000000000001000000E5130000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000004400000087031600090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802060000000E000000523D04007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000006100720065005C00530070007900740065006300680020005300700079004100670065006E0074005C0073007900730064006900610067002E0065007800650000002E0065007800650000000000000088E43002FFFFFFFF40BE6F06FFFFFFFF9049FE75000000000000000024E43002D574FA75000400000000000088E43002FFFFFFFF40BE6F06FFFFFFFFD8E0300090E1300038BE6F0654E430022FB13B7680B06E7694F13002381E3C7614633C76B8152F0088E430020000000062000000381209E568E4300200000000D0327406C831740674E430023DA93C7600000000FBFFFF7F98E4300202000000C807760648F0570620662C000000000001100211FFFFFFFF000000000000000000000000A14B2C03BD4B2C03A14B2C03000000000000000000000000080000002E006C006E006B00000065006E00740011000000B8452F00B0452F00720076004CE50000881209E550E50000801209E504E5300282913C7650E5300208E5300227953C76000000008C2BF10230E53002CD943C768C2BF1020027F102D4E53002E1943C76000000000027F102D4E5300238E53002060000000E000000523D04007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000006100720065005C00530070007900740065006300680020005300700079004100670065006E0074005C0073007900730064006900610067002E0065007800650000002E0065007800650000000000000088E43002FFFFFFFF40BE6F06FFFFFFFF9049FE75000000000000000024E43002D574FA75000400000000000088E43002FFFFFFFF40BE6F06FFFFFFFFD8E0300090E1300038BE6F0654E430022FB13B7680B06E7694F13002381E3C7614633C76B8152F0088E430020000000062000000381209E568E4300200000000D0327406C831740674E430023DA93C7600000000FBFFFF7F98E4300202000000C807760648F0570620662C000000000001100211FFFFFFFF000000000000000000000000A14B2C03BD4B2C03A14B2C03000000000000000000000000080000002E006C006E006B00000065006E00740011000000B8452F00B0452F00720076004CE50000881209E550E50000801209E504E5300282913C7650E5300208E5300227953C76000000008C2BF10230E53002CD943C768C2BF1020027F102D4E53002E1943C76000000000027F102D4E5300238E53002
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\Directory\OpenWithProgids
File Folder
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
MRUListEx
080000000100000000000000020000000700000006000000030000000500000004000000FFFFFFFF
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\8
0
4C00310000000000883715A71020437261636B00380008000400EFBE2B4E8B382B4E8B382A00000068DF000000000300000000000000000000000000000043007200610063006B00000014000000
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\8
MRUListEx
00000000FFFFFFFF
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
NodeSlots
02020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\8\0
NodeSlot
97
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\8\0
MRUListEx
FFFFFFFF
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\97\Shell
KnownFolderDerivedFolderType
{57807898-8C4F-4462-BB63-71042380B109}
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Rev
0
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
1092616193
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Vid
{137E7700-3573-11CF-AE69-08002B2E1262}
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Mode
4
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
LogicalViewMode
1
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
1092616209
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
IconSize
16
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
ColInfo
00000000000000000000000000000000FDDFDFFD100000000000000000000000040000001800000030F125B7EF471A10A5F102608C9EEBAC0A0000001001000030F125B7EF471A10A5F102608C9EEBAC0E0000007800000030F125B7EF471A10A5F102608C9EEBAC040000007800000030F125B7EF471A10A5F102608C9EEBAC0C00000050000000
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Sort
000000000000000000000000000000000100000030F125B7EF471A10A5F102608C9EEBAC0A00000001000000
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupView
0
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:FMTID
{00000000-0000-0000-0000-000000000000}
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:PID
0
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByDirection
1
284
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\97\Shell
SniffedFolderType
Generic
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\Qrfxgbc\Fclgrpu FclNtrag Fgrnygu 6.2\Penpx\flfqvnt.rkr
00000000010000000000000000000000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF4003A9087CA9D40100000000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
00000000300000004400000087031600090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802060000000E000000523D04007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000006100720065005C00530070007900740065006300680020005300700079004100670065006E0074005C0073007900730064006900610067002E0065007800650000002E0065007800650000000000000088E43002FFFFFFFF40BE6F06FFFFFFFF9049FE75000000000000000024E43002D574FA75000400000000000088E43002FFFFFFFF40BE6F06FFFFFFFFD8E0300090E1300038BE6F0654E430022FB13B7680B06E7694F13002381E3C7614633C76B8152F0088E430020000000062000000381209E568E4300200000000D0327406C831740674E430023DA93C7600000000FBFFFF7F98E4300202000000C807760648F0570620662C000000000001100211FFFFFFFF000000000000000000000000A14B2C03BD4B2C03A14B2C03000000000000000000000000080000002E006C006E006B00000065006E00740011000000B8452F00B0452F00720076004CE50000881209E550E50000801209E504E5300282913C7650E5300208E5300227953C76000000008C2BF10230E53002CD943C768C2BF1020027F102D4E53002E1943C76000000000027F102D4E5300238E53002060000000E000000523D04007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000006100720065005C00530070007900740065006300680020005300700079004100670065006E0074005C0073007900730064006900610067002E0065007800650000002E0065007800650000000000000088E43002FFFFFFFF40BE6F06FFFFFFFF9049FE75000000000000000024E43002D574FA75000400000000000088E43002FFFFFFFF40BE6F06FFFFFFFFD8E0300090E1300038BE6F0654E430022FB13B7680B06E7694F13002381E3C7614633C76B8152F0088E430020000000062000000381209E568E4300200000000D0327406C831740674E430023DA93C7600000000FBFFFF7F98E4300202000000C807760648F0570620662C000000000001100211FFFFFFFF000000000000000000000000A14B2C03BD4B2C03A14B2C03000000000000000000000000080000002E006C006E006B00000065006E00740011000000B8452F00B0452F00720076004CE50000881209E550E50000801209E504E5300282913C7650E5300208E5300227953C76000000008C2BF10230E53002CD943C768C2BF1020027F102D4E53002E1943C76000000000027F102D4E5300238E53002
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\rkcybere.rkr
00000000060000000E00000012120600000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF6012F7D45C48D40100000000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
00000000300000004400000047D81700090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802060000000E000000121206007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000B4E53002A5321077F4E53002CCE6300200000000B43210772CE73002014510776A00DE028C00DE02B8ACDE02B0E430020001000101000000000100000000000028FCBC0200E73002E0E2D302DCE63002CAFED302D8E430020CE730026000DE022B0000006A00DE0228FCBC02000000008C00DE0294E630020A00DE020000000005000500A82350026601DE022B0000000F0000002CE73002F4E6300228FCBC021000000074FFBC02050017004E1E5002F4E530021600000002000000B8ACDE020400300228FCBC020300000000000000090909000909090900091111000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000011000000B8452F00B0452F0000000000000000000000000000000000A8E500002C1309E558E5300282913C76A8E530025CE5300227953C76000000008C2BF10284E53002CD943C768C2BF10230E630020027F102E1943C76000000000027F10230E630028CE53002060000000E000000121206007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000B4E53002A5321077F4E53002CCE6300200000000B43210772CE73002014510776A00DE028C00DE02B8ACDE02B0E430020001000101000000000100000000000028FCBC0200E73002E0E2D302DCE63002CAFED302D8E430020CE730026000DE022B0000006A00DE0228FCBC02000000008C00DE0294E630020A00DE020000000005000500A82350026601DE022B0000000F0000002CE73002F4E6300228FCBC021000000074FFBC02050017004E1E5002F4E530021600000002000000B8ACDE020400300228FCBC020300000000000000090909000909090900091111000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000011000000B8452F00B0452F0000000000000000000000000000000000A8E500002C1309E558E5300282913C76A8E530025CE5300227953C76000000008C2BF10284E53002CD943C768C2BF10230E630020027F102E1943C76000000000027F10230E630028CE53002
3496
SpyAgentSetup.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
NodeSlots
0202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
3496
SpyAgentSetup.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
MRUListEx
010000000800000000000000020000000700000006000000030000000500000004000000FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0
MRUListEx
0400000001000000000000000200000003000000FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4\0\0\0\0
1
6E0031000000000000000000100053707974656368205370794167656E7400004E0008000400EFBE00000000000000002A00000000000000000000000000000000000000000000000000530070007900740065006300680020005300700079004100670065006E007400000020000000
3496
SpyAgentSetup.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4\0\0\0\0
MRUListEx
0100000000000000FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
NodeSlots
020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
3496
SpyAgentSetup.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4\0\0\0\0\1
NodeSlot
96
3496
SpyAgentSetup.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4\0\0\0\0\1
MRUListEx
FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\96\Shell
KnownFolderDerivedFolderType
{57807898-8C4F-4462-BB63-71042380B109}
3496
SpyAgentSetup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3496
SpyAgentSetup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3496
SpyAgentSetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spytech SpyAgent
DisplayName
Spytech SpyAgent
3496
SpyAgentSetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spytech SpyAgent
UninstallString
C:\Windows\unvise32.exe C:\Program Files\Spytech Software\Spytech SpyAgent\uninstal.log
3496
SpyAgentSetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\unvise32.exe
1
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
1
14001F50E04FD020EA3A6910A2D808002B30309D0000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
2
14001F4225481E03947BC34DB131E946B44C8DD50000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
3
14001F6880531C87A0426910A2EA08002B30309D0000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
4
4C00310000000000454BB94D1000746F6F6C7300380008000400EFBE454BB94D454BB94D2A000000A844000000000200000000000000000000000000000074006F006F006C007300000014000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
5
9400310000000000000000001000303030312D363330355F56697374615F57696E375F504735333728312900680008000400EFBE00000000000000002A0000000000000000000000000000000000000000000000000030003000300031002D0036003300300035005F00560069007300740061005F00570069006E0037005F005000470035003300370028003100290000002C000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
7
14001F44471A0359723FA74489C55595FE6B30EE0000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
NodeSlot
82
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
8
8000310000000000973A848A10005350595445437E312E320000660008000400EFBE2B4E8B382B4E8B382A00000067DF0000000003000000000000000000000000000000530070007900740065006300680020005300700079004100670065006E007400200053007400650061006C0074006800200036002E00320000001A000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0
1
0C0001008421DE39050000000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0
NodeSlot
5
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0
2
0C0001008421DE39000000000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0
3
0C0001008421DE39030000000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0
4
0C0001008421DE39020000000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0
5
0C0001008421DE39090000000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\0
1
1E007180000000000000000000008B4355C5233C6947A71FB6D3D9B6053A0000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\0\0
NodeSlot
1
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\0\1
0
F7000000F10000EEEBBEE300040000000000510000003153505330F125B7EF471A10A5F102608C9EEBAC350000000A000000001F00000012000000530063007200650065006E0020005200650073006F006C007500740069006F006E000000000000004100000031535053537DEF0C64FAD111A2030000F81FEDEE2500000005000000001F00000009000000530065007400740069006E006700730000000000000000004D000000315350538727BF5CCF480842B90EEE5E5D4202943100000019000000001F0000000F00000044006900730070006C00610079002E0064006C006C002C002D00310000000000000000000000000000000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\0\1
MRUListEx
00000000FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\0\1\0
NodeSlot
2
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\0\1\0
MRUListEx
FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\1
0
1E00718000000000000000000000E4C006BB93D2754F8A90CB05B6477EEE0000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\1
MRUListEx
0100000000000000FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\1
NodeSlot
6
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\1
1
1E007180000000000000000000002F492640692FB846B9BF5654FC07E4230000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\1\0
NodeSlot
4
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\1\0
MRUListEx
FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\1\1
NodeSlot
7
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\1\1
MRUListEx
00000000FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\1\1
0
2B010000250100EEEBBE1701040000000000550000003153505330F125B7EF471A10A5F102608C9EEBAC390000000A000000001F0000001300000043007500730074006F006D0069007A0065002000530065007400740069006E006700730000000000000000005900000031535053537DEF0C64FAD111A2030000F81FEDEE3D00000005000000001F00000016000000500061006700650043006F006E00660069006700750072006500530065007400740069006E006700730000000000000065000000315350538727BF5CCF480842B90EEE5E5D4202944900000019000000001F0000001C0000004600690072006500770061006C006C0043006F006E00740072006F006C00500061006E0065006C002E0064006C006C002C002D0031000000000000000000000000000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\1\1\0
NodeSlot
8
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\1\1\0
MRUListEx
FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2
NodeSlot
9
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2
MRUListEx
02000000090000000100000008000000070000000600000005000000040000000300000000000000FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2
0
1E00718000000000000000000000DBF7EE36AD88814EAD490E313F0C35F80000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2
1
1E00718000000000000000000000C98F908ECCBEF640915BF4CA0E70D03D0000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2
2
1E00718000000000000000000000E4C006BB93D2754F8A90CB05B6477EEE0000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2
3
1E00718000000000000000000000D64E83ED5A4BFE4B8F11A626DCB6A9210000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2
4
1E007180000000000000000000008B4355C5233C6947A71FB6D3D9B6053A0000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2
5
1E007180000000000000000000005076CA67E696DD4FBB43A8E774F73A570000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2
6
1E00718000000000000000000000E5F5739CE77A324EA8E88D23B85255BF0000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2
7
1E007180000000000000000000006ABE817B2BCE7646A29EEB907A5126C50000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2
8
1E00718000000000000000000000A7F864BBE7BE1A4EAB8D7D8273F7FDB60000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2
9
1E007180000000000000000000002F492640692FB846B9BF5654FC07E4230000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\0
NodeSlot
10
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\0
MRUListEx
00000000FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\0
0
FB000000F50000EEEBBEE7000400010000004D0000003153505330F125B7EF471A10A5F102608C9EEBAC310000000A000000001F000000100000004300680061006E00670065002000730065007400740069006E00670073000000000000004900000031535053537DEF0C64FAD111A2030000F81FEDEE2D00000005000000001F0000000D0000007000610067006500530065007400740069006E006700730000000000000000004D000000315350538727BF5CCF480842B90EEE5E5D4202943100000019000000001F0000000F0000007700750063006C007400750078002E0064006C006C002C002D00310000000000000000000000000000000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\0\0
NodeSlot
11
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\0\0
MRUListEx
FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\1
NodeSlot
22
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\1
MRUListEx
00000000FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\1
0
0F010000090100EEEBBEFB00040000000000610000003153505330F125B7EF471A10A5F102608C9EEBAC450000000A000000001F0000001A00000041006400760061006E006300650064002000730068006100720069006E0067002000730065007400740069006E00670073000000000000004100000031535053537DEF0C64FAD111A2030000F81FEDEE2500000005000000001F0000000900000041006400760061006E00630065006400000000000000000055000000315350538727BF5CCF480842B90EEE5E5D4202943900000019000000001F0000001300000069006D006100670065007200650073002E0064006C006C002C002D00310030003100330000000000000000000000000000000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\1\0
NodeSlot
44
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\1\0
MRUListEx
FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\2
NodeSlot
25
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\2
MRUListEx
FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\3
NodeSlot
28
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\3
MRUListEx
FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\4
0
F7000000F10000EEEBBEE300040000000000510000003153505330F125B7EF471A10A5F102608C9EEBAC350000000A000000001F00000012000000530063007200650065006E0020005200650073006F006C007500740069006F006E000000000000004100000031535053537DEF0C64FAD111A2030000F81FEDEE2500000005000000001F00000009000000530065007400740069006E006700730000000000000000004D000000315350538727BF5CCF480842B90EEE5E5D4202943100000019000000001F0000000F00000044006900730070006C00610079002E0064006C006C002C002D00310000000000000000000000000000000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\4
MRUListEx
00000000FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\4\0
NodeSlot
29
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\4\0
MRUListEx
FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\5
NodeSlot
45
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\5
MRUListEx
FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\6
NodeSlot
46
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\6
MRUListEx
FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\7
NodeSlot
52
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\7
MRUListEx
FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\8
NodeSlot
57
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\8
MRUListEx
00000000FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\8
0
1F010000190100EEEBBE0B01040000000000690000003153505330F125B7EF471A10A5F102608C9EEBAC4D0000000A000000001F0000001E0000004300680061006E0067006500200041006300740069006F006E002000430065006E007400650072002000730065007400740069006E00670073000000000000004100000031535053537DEF0C64FAD111A2030000F81FEDEE2500000005000000001F00000009000000530065007400740069006E006700730000000000000000005D000000315350538727BF5CCF480842B90EEE5E5D4202944100000019000000001F0000001700000041006300740069006F006E00430065006E00740065007200430050004C002E0064006C006C002C002D00310000000000000000000000000000000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\8\0
NodeSlot
58
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\8\0
MRUListEx
FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\9
NodeSlot
93
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\9
MRUListEx
00000000FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\9
0
2B010000250100EEEBBE1701040000000000550000003153505330F125B7EF471A10A5F102608C9EEBAC390000000A000000001F0000001300000043007500730074006F006D0069007A0065002000530065007400740069006E006700730000000000000000005900000031535053537DEF0C64FAD111A2030000F81FEDEE3D00000005000000001F00000016000000500061006700650043006F006E00660069006700750072006500530065007400740069006E006700730000000000000065000000315350538727BF5CCF480842B90EEE5E5D4202944900000019000000001F0000001C0000004600690072006500770061006C006C0043006F006E00740072006F006C00500061006E0065006C002E0064006C006C002C002D0031000000000000000000000000000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\9\0
NodeSlot
94
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\9\0
MRUListEx
FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\3
0
1E00718000000000000000000000C7AC07700232D111AAD200805FC1270E0000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\3
MRUListEx
00000000FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\3\0
NodeSlot
23
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\3\0
MRUListEx
FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\4
NodeSlot
42
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\4
MRUListEx
FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\5
NodeSlot
55
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\5
MRUListEx
00000000FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\5
0
1E00718000000000000000000000F1F5061269052C418FEC3204630DFB700000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\5\0
NodeSlot
56
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\5\0
MRUListEx
FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1
0
19002F433A5C000000000000000000000000000000000000000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1
MRUListEx
00000000FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1
NodeSlot
27
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0
0
7400310000000000454B804A1100557365727300600008000400EFBEEE3AA314454B804A2A0000005A01000000000100000000000000000036000000000055007300650072007300000040007300680065006C006C00330032002E0064006C006C002C002D0032003100380031003300000014000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0
MRUListEx
0400000001000000000000000200000003000000FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0
NodeSlot
34
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0
1
8800310000000000464BDD51110050524F4752417E310000700008000400EFBEEE3AA314464BDD512A0000003C000000000001000000000000000000460000000000500072006F006700720061006D002000460069006C0065007300000040007300680065006C006C00330032002E0064006C006C002C002D0032003100370038003100000018000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0
2
5200310000000000464BEA51100057696E646F7773003C0008000400EFBEEE3AA314464BEA512A000000FA010000000001000000000000000000000000000000570069006E0064006F0077007300000016000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0
3
5000310000000000464B9D511000414E5952554E00003A0008000400EFBE454BFD4D464B9D512A0000005545000000000200000000000000000000000000000041004E005900520055004E00000016000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0
4
5E0031000000000000000000100050726F6772616D4461746100440008000400EFBE00000000000000002A00000000000000000000000000000000000000000000000000500072006F006700720061006D00440061007400610000001A000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0
0
4C00310000000000454B854A100061646D696E00380008000400EFBE454B804A454B854A2A0000002D000000000004000000000000000000000000000000610064006D0069006E00000014000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0
MRUListEx
00000000FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0
NodeSlot
54
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0
0
5200310000000000454B814A122041707044617461003C0008000400EFBE454B814A454B814A2A0000007C0100000000020000000000000000000000000000004100700070004400610074006100000016000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0
MRUListEx
00000000FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0
0
5200310000000000454B834A1020526F616D696E67003C0008000400EFBE454B814A454B834A2A0000007D01000000000200000000000000000000000000000052006F0061006D0069006E006700000016000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0
MRUListEx
0000000001000000FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0
1
4C00310000000000454B645310204C6F63616C00380008000400EFBE454B814A454B64532A0000008F0100000000020000000000000000000000000000004C006F00630061006C00000014000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0
NodeSlot
73
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0
0
5800310000000000454B834A14204D4943524F537E310000400008000400EFBE454B814A454B834A2A0000007E0100000000020000000000000000000000000000004D006900630072006F0073006F0066007400000018000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0
MRUListEx
0100000000000000FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0
NodeSlot
72
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0
1
4C003100000000001E4DC56E102041646F626500380008000400EFBE1C4DC45E1E4DC56E2A00000020C40000000002000000000000000000000000000000410064006F0062006500000014000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\0
0
5200310000000000454B854A102057696E646F7773003C0008000400EFBE454B814A454B854A2A0000007F010000000002000000000000000000000000000000570069006E0064006F0077007300000016000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\0
MRUListEx
00000000FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\0\0
0
8200310000000000454B854A110053544152544D7E3100006A0008000400EFBE454B814A454B854A2A000000810100000000020000000000000000004000000000005300740061007200740020004D0065006E007500000040007300680065006C006C00330032002E0064006C006C002C002D0032003100370038003600000018000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\0\0
MRUListEx
00000000FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\0\0\0
NodeSlot
3
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\0\0\0
MRUListEx
FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1
NodeSlot
86
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1
MRUListEx
00000000FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1
0
52003100000000001E4DC16E10204163726F626174003C0008000400EFBE1E4DC16E1E4DC16E2A000000D73D00000000160000000000000000000000000000004100630072006F00620061007400000016000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1\0
NodeSlot
87
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1\0
MRUListEx
00000000FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1\0
0
4400310000000000294D747C102044430000320008000400EFBE1E4DC16E294D747C2A0000000D3E000000001000000000000000000000000000000044004300000012000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1\0\0
NodeSlot
88
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1\0\0
MRUListEx
00000000FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1\0\0
0
5600310000000000294D747C1020536563757269747900003E0008000400EFBE294D747C294D747C2A00000033DA000000000400000000000000000000000000000053006500630075007200690074007900000018000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1\0\0\0
NodeSlot
89
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1\0\0\0
MRUListEx
00000000FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1\0\0\0
0
5600310000000000294D747C102043524C436163686500003E0008000400EFBE294D747C294D747C2A00000034DA0000000003000000000000000000000000000000430052004C0043006100630068006500000018000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1\0\0\0\0
NodeSlot
90
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1\0\0\0\0
MRUListEx
FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1
0
4A00310000000000464B2D52102054656D700000360008000400EFBE454B814A464B2D522A00000090010000000002000000000000000000000000000000540065006D007000000014000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1
MRUListEx
03000000020000000100000000000000FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1
NodeSlot
74
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1
1
50003100000000001D4D1D691020476F6F676C6500003A0008000400EFBE1C4D7C591D4D1D692A000000E9A1000000000A00000000000000000000000000000047006F006F0067006C006500000016000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1
2
58003100000000001C4D8265102046494C455A497E310000400008000400EFBE1C4D43621C4D82652A000000A6C80000000003000000000000000000000000000000460069006C0065005A0069006C006C006100000018000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1
3
58003100000000001D4DB67D10204D4943524F537E310000400008000400EFBE454B814A1D4DB67D2A000000910100000000020000000000000000000000000000004D006900630072006F0073006F0066007400000018000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\0
NodeSlot
39
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\0
MRUListEx
FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1
NodeSlot
75
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1
MRUListEx
0100000000000000FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1
0
72003100000000001D4D1D691020534F465457417E3100005A0008000400EFBE1D4D1D691D4D1D692A0000004BFC000000000100000000000000000000000000000053006F0066007400770061007200650020005200650070006F007200740065007200200054006F006F006C00000018000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1
1
50003100000000001C4D7C5910204368726F6D6500003A0008000400EFBE1C4D7C591C4D7C592A000000ECA100000000070000000000000000000000000000004300680072006F006D006500000016000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\0
NodeSlot
76
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\0
MRUListEx
00000000FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\0
0
52003100000000001D4D1D6910207265706F727473003C0008000400EFBE1D4D1D691D4D1D692A0000004EFC00000000010000000000000000000000000000007200650070006F00720074007300000016000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\0\0
NodeSlot
77
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\0\0
MRUListEx
FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\1
NodeSlot
78
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\1
MRUListEx
00000000FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\1
0
5800310000000000294DE58210205553455244417E310000400008000400EFBE1C4D7C59294DE5822A000000EEA10000000005000000000000000000000000000000550073006500720020004400610074006100000018000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\1\0
NodeSlot
79
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\1\0
MRUListEx
00000000FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\1\0
0
5A003100000000001D4D1D69102053575245504F7E310000420008000400EFBE1C4D7D591D4D1D692A00000092BC0000000003000000000000000000000000000000530077005200650070006F007200740065007200000018000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\1\0\0
NodeSlot
80
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\1\0\0
MRUListEx
00000000FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\1\0\0
0
5C003100000000001D4D1D69102033333137307E312E32303100420008000400EFBE1D4D1D691D4D1D692A000000BBFB0000000002000000000000000000000000000000330033002E003100370030002E0032003000310000001A000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\1\0\0\0
NodeSlot
81
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\1\0\0\0
MRUListEx
FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\2
NodeSlot
83
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\2
MRUListEx
FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\3
NodeSlot
84
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\3
MRUListEx
00000000FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\3
0
5200310000000000294DE38310204F75746C6F6F6B003C0008000400EFBE1B4D1560294DE3832A000000A61B00000000030000000000000000000000000000004F00750074006C006F006F006B00000016000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\3\0
NodeSlot
85
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\3\0
MRUListEx
FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1
NodeSlot
35
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1
MRUListEx
010000000000000002000000FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1
0
50003100000000001C4D54591000476F6F676C6500003A0008000400EFBE1C4D4F591C4D54592A000000FCB0000000000200000000000000000000000000000047006F006F0067006C006500000016000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1
1
5E003100000000001C4DA6691000434F4D4D4F4E7E310000460008000400EFBEEE3AA3141C4DA6692A0000003D00000000000100000000000000000000000000000043006F006D006D006F006E002000460069006C0065007300000018000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1
2
56003100000000001C4D7C60100043436C65616E657200003E0008000400EFBE1C4D7B601C4D7C602A00000069C40000000003000000000000000000000000000000430043006C00650061006E0065007200000018000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0
NodeSlot
59
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0
MRUListEx
000000000200000001000000FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0
0
50003100000000001C4D595910004368726F6D6500003A0008000400EFBE1C4D54591C4D59592A0000007AB500000000020000000000000000000000000000004300680072006F006D006500000016000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0
1
50003100000000001C4D5259100055706461746500003A0008000400EFBE1C4D4F591C4D52592A00000011B10000000002000000000000000000000000000000550070006400610074006500000016000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0
2
5E003100000000001C4D4F5910004352415348527E310000460008000400EFBE1C4D4F591C4D4F592A000000FFB00000000002000000000000000000000000000000430072006100730068005200650070006F00720074007300000018000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0\0
NodeSlot
60
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0\0
MRUListEx
00000000FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0\0
0
5C003100000000001C4D595910004150504C49437E310000440008000400EFBE1C4D59591C4D59592A00000001BB00000000020000000000000000000000000000004100700070006C00690063006100740069006F006E00000018000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0\0\0
NodeSlot
71
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0\0\0
MRUListEx
FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0\1
NodeSlot
61
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0\1
MRUListEx
FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0\2
NodeSlot
70
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0\2
MRUListEx
FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1
NodeSlot
62
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1
MRUListEx
00000000FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1
0
4C003100000000001C4D5866100041646F626500380008000400EFBE1C4D4A661C4D58662A000000E9D90000000003000000000000000000000000000000410064006F0062006500000014000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1\0
NodeSlot
63
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1\0
MRUListEx
000000000100000002000000FFFFFFFF
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1\0
0
46003100000000001C4D4A66100041524D00340008000400EFBE1C4D4A661C4D4A662A000000F6D90000000003000000000000000000000000000000410052004D00000012000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1\0
1
52003100000000001C4D4A6610004163726F626174003C0008000400EFBE1C4D4A661C4D4A662A000000EAD900000000030000000000000000000000000000004100630072006F00620061007400000016000000
3496
SpyAgentSetup.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1\0
2
50003100000000001C4D4B66100052656164657200003A0008000400EFBE1C4D4B661C4D4B662A0000009DDA0000000002000000000000000000000000