General Info

File name

WinZIP_v19.0_Web_Installer.exe

Full analysis
https://app.any.run/tasks/71b9fb56-c25f-4367-8e2e-28e5da516cfe
Verdict
Malicious activity
Analysis date
5/15/2019, 06:57:33
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:

adware

pup

installcore

Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

f62e7667e988a9cbdbb16aefe0c1e5ba

SHA1

ddf3c184bf6dd653148da6c9cec811d742d644f6

SHA256

4d753499dfc07886971875252cee1be36d5792fdbab679c69531df208d3b583b

SSDEEP

24576:1rvOWfUJEOGGBzaCNiCBbeQLacp8xrA6pPM:1TdUJdDNZRaxrA6u

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (73.0.3683.75)
  • Google Update Helper (1.3.33.23)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 65.0.2 (x86 en-US) (65.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads dropped or rewritten executable
  • svchost.exe (PID: 840)
  • WINZIP32.EXE (PID: 860)
  • MsiExec.exe (PID: 1892)
  • FAHWindow.exe (PID: 2824)
  • FAHWindow.exe (PID: 2668)
  • explorer.exe (PID: 2036)
Application was dropped or rewritten from another process
  • WzPreviewer32.exe (PID: 1916)
  • WINZIP32.EXE (PID: 860)
  • FAHWindow.exe (PID: 2824)
  • FAHWindow.exe (PID: 2668)
  • FAHConsole.exe (PID: 1672)
  • FAHConsole.exe (PID: 3928)
  • UpdateHelper.exe (PID: 3416)
  • FAHConsole.exe (PID: 3336)
Runs injected code in another process
  • FAHWindow.exe (PID: 2824)
Changes settings of System certificates
  • msiexec.exe (PID: 1244)
Application was injected by another process
  • explorer.exe (PID: 2036)
Connects to CnC server
  • WinZIP_v19.0_Web_Installer.exe (PID: 2856)
INSTALLCORE was detected
  • WinZIP_v19.0_Web_Installer.exe (PID: 2856)
Creates COM task schedule object
  • WINZIP32.EXE (PID: 860)
  • MsiExec.exe (PID: 1892)
Changes IE settings (feature browser emulation)
  • msiexec.exe (PID: 1244)
Modifies the open verb of a shell class
  • WINZIP32.EXE (PID: 860)
  • msiexec.exe (PID: 1244)
Creates a software uninstall entry
  • WINZIP32.EXE (PID: 860)
Reads Internet Cache Settings
  • WINZIP32.EXE (PID: 860)
Creates files in the user directory
  • WINZIP32.EXE (PID: 860)
Creates files in the Windows directory
  • MsiExec.exe (PID: 2972)
Changes the autorun value in the registry
  • msiexec.exe (PID: 1244)
Adds / modifies Windows certificates
  • msiexec.exe (PID: 1244)
Reads Environment values
  • WinZIP_v19.0_Web_Installer.exe (PID: 2856)
Starts Microsoft Installer
  • WinZIP_v19.0_Web_Installer.exe (PID: 2856)
Application launched itself
  • WinZIP_v19.0_Web_Installer.exe (PID: 2856)
  • WinZIP_v19.0_Web_Installer.exe (PID: 1256)
Executable content was dropped or overwritten
  • msiexec.exe (PID: 1244)
  • WinZIP_v19.0_Web_Installer.exe (PID: 2856)
  • WinZIP_v19.0_Web_Installer.exe (PID: 1256)
Reads the machine GUID from the registry
  • WinZIP_v19.0_Web_Installer.exe (PID: 2856)
Reads internet explorer settings
  • WinZIP_v19.0_Web_Installer.exe (PID: 2856)
Creates files in the program directory
  • WinZIP_v19.0_Web_Installer.exe (PID: 2856)
Loads dropped or rewritten executable
  • msiexec.exe (PID: 1244)
  • MsiExec.exe (PID: 2972)
Application launched itself
  • msiexec.exe (PID: 1244)
Creates a software uninstall entry
  • msiexec.exe (PID: 1244)
Creates files in the program directory
  • msiexec.exe (PID: 1244)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable Delphi generic (57.2%)
.exe
|   Win32 Executable (generic) (18.2%)
.exe
|   Win16/32 Executable Delphi generic (8.3%)
.exe
|   Generic Win/DOS Executable (8%)
.exe
|   DOS Executable Generic (8%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
1992:06:20 00:22:17+02:00
PEType:
PE32
LinkerVersion:
2.25
CodeSize:
37888
InitializedDataSize:
42496
UninitializedDataSize:
null
EntryPoint:
0x9c40
OSVersion:
1
ImageVersion:
6
SubsystemVersion:
4
Subsystem:
Windows GUI
FileVersionNumber:
0.0.0.0
ProductVersionNumber:
0.0.0.0
FileFlagsMask:
0x003f
FileFlags:
(none)
FileOS:
Win32
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
Neutral
CharacterSet:
Unicode
Comments:
This installation was built with Inno Setup.
CompanyName:
FileDescription:
FileVersion:
LegalCopyright:
ProductName:
ProductVersion:
1.5
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
19-Jun-1992 22:22:17
Detected languages
English - United States
Comments:
This installation was built with Inno Setup.
CompanyName:
null
FileDescription:
null
FileVersion:
null
LegalCopyright:
null
ProductName:
null
ProductVersion:
1.5
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0050
Pages in file:
0x0002
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x000F
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x001A
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x00000100
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
8
Time date stamp:
19-Jun-1992 22:22:17
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
CODE 0x00001000 0x00009364 0x00009400 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.71137
DATA 0x0000B000 0x0000024C 0x00000400 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 2.7391
BSS 0x0000C000 0x00000E88 0x00000000 IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.idata 0x0000D000 0x00000950 0x00000A00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 4.43073
.tls 0x0000E000 0x00000008 0x00000000 IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.rdata 0x0000F000 0x00000018 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_SHARED 0.204488
.reloc 0x00010000 0x000008B4 0x00000000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_SHARED 0
.rsrc 0x00011000 0x00009554 0x00009600 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_SHARED 4.70608
Resources
1

2

3

4

4089

4090

4091

4093

4094

4095

11111

MAINICON

Imports
    kernel32.dll

    user32.dll

    oleaut32.dll

    advapi32.dll

    comctl32.dll

Exports

    No exports.

Screenshots

Processes

Total processes
53
Monitored processes
18
Malicious processes
4
Suspicious processes
2

Behavior graph

+
start drop and start drop and start drop and start drop and start drop and start inject winzip_v19.0_web_installer.exe #INSTALLCORE winzip_v19.0_web_installer.exe winzip_v19.0_web_installer.exe no specs msiexec.exe no specs msiexec.exe msiexec.exe no specs fahconsole.exe no specs fahconsole.exe no specs fahwindow.exe no specs updatehelper.exe no specs explorer.exe msiexec.exe no specs msiexec.exe no specs fahconsole.exe no specs fahwindow.exe no specs winzip32.exe no specs svchost.exe wzpreviewer32.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
840
CMD
C:\Windows\system32\svchost.exe -k netsvcs
Path
C:\Windows\System32\svchost.exe
Indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Host Process for Windows Services
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\gpsvc.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\nsi.dll
c:\windows\system32\sysntfy.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\themeservice.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\profsvc.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\atl.dll
c:\windows\system32\winsta.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\slc.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\sens.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\shsvcs.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\schedsvc.dll
c:\windows\system32\pcwum.dll
c:\windows\system32\shell32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\authz.dll
c:\windows\system32\ubpm.dll
c:\windows\system32\ktmw32.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\credssp.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\fveapi.dll
c:\windows\system32\tbs.dll
c:\windows\system32\fvecerts.dll
c:\windows\system32\logoncli.dll
c:\windows\system32\wiarpc.dll
c:\windows\system32\samlib.dll
c:\windows\system32\taskcomp.dll
c:\windows\system32\version.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\netjoin.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\ikeext.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\wbem\wmisvc.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\iphlpsvc.dll
c:\windows\system32\firewallapi.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\wdscore.dll
c:\windows\system32\srvsvc.dll
c:\windows\system32\browser.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\vssapi.dll
c:\windows\system32\vsstrace.dll
c:\windows\system32\sscore.dll
c:\windows\system32\clusapi.dll
c:\windows\system32\cryptdll.dll
c:\windows\system32\resutils.dll
c:\windows\system32\samcli.dll
c:\windows\system32\nci.dll
c:\windows\system32\netprofm.dll
c:\windows\system32\propsys.dll
c:\windows\system32\spinf.dll
c:\windows\system32\wbem\wbemcore.dll
c:\windows\system32\wbem\esscli.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\wmiutils.dll
c:\windows\system32\wbem\repdrvfs.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\npmproxy.dll
c:\windows\system32\sxs.dll
c:\windows\system32\wbem\wmiprvsd.dll
c:\windows\system32\ncobjapi.dll
c:\windows\system32\wbem\wbemess.dll
c:\windows\system32\wbem\ncprov.dll
c:\windows\system32\qmgr.dll
c:\windows\system32\bitsperf.dll
c:\windows\system32\bitsigd.dll
c:\windows\system32\upnp.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\ssdpapi.dll
c:\windows\system32\wuaueng.dll
c:\windows\system32\esent.dll
c:\windows\system32\winspool.drv
c:\windows\system32\cabinet.dll
c:\windows\system32\mspatcha.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wmsgapi.dll
c:\windows\system32\wer.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\aelupsvc.dll
c:\windows\system32\appinfo.dll
c:\windows\system32\tschannel.dll
c:\windows\system32\hnetcfg.dll
c:\windows\system32\netcfgx.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\ndiscapcfg.dll
c:\windows\system32\rascfg.dll
c:\windows\system32\mprapi.dll
c:\windows\system32\tcpipcfg.dll
c:\windows\system32\windanr.exe
c:\users\admin\appdata\local\temp\winzip_v19.0_web_installer.exe
c:\program files\file association helper\fahconsole.exe
c:\program files\file association helper\fahwindow.exe
c:\program files\file association helper\updatehelper.exe
c:\program files\winzip\winzip32.exe
c:\program files\winzip\wz32.dll

PID
2036
CMD
C:\Windows\Explorer.EXE
Path
C:\Windows\explorer.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Windows Explorer
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\slc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\profapi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\iconcodecservice.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sndvolsso.dll
c:\windows\system32\hid.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\timedate.cpl
c:\windows\system32\atl.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\actxprxy.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\userenv.dll
c:\windows\system32\shacct.dll
c:\windows\system32\samlib.dll
c:\windows\system32\samcli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\msftedit.dll
c:\windows\system32\msls31.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\authui.dll
c:\windows\system32\cryptui.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\gameux.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\wer.dll
c:\windows\system32\msiltcfg.dll
c:\windows\system32\version.dll
c:\windows\system32\msi.dll
c:\windows\system32\winsta.dll
c:\windows\system32\psapi.dll
c:\windows\system32\networkexplorer.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wdmaud.drv
c:\windows\system32\ksuser.dll
c:\windows\system32\avrt.dll
c:\windows\system32\audioses.dll
c:\windows\system32\msacm32.drv
c:\windows\system32\msacm32.dll
c:\windows\system32\midimap.dll
c:\windows\system32\stobject.dll
c:\windows\system32\batmeter.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\es.dll
c:\windows\system32\prnfldr.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dxp.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\syncreg.dll
c:\windows\ehome\ehsso.dll
c:\windows\system32\netshell.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\alttab.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
c:\program files\filezilla ftp client\fzshellext.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\pnidui.dll
c:\windows\system32\qutil.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\npmproxy.dll
c:\windows\system32\wlanapi.dll
c:\windows\system32\wlanutil.dll
c:\windows\system32\wwanapi.dll
c:\windows\system32\wwapi.dll
c:\windows\system32\qagent.dll
c:\windows\system32\srchadmin.dll
c:\windows\system32\sxs.dll
c:\windows\system32\bthprops.cpl
c:\windows\system32\ieframe.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\synccenter.dll
c:\windows\system32\actioncenter.dll
c:\windows\system32\imapi2.dll
c:\windows\system32\hgcpl.dll
c:\windows\system32\provsvc.dll
c:\windows\system32\netprofm.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\fxsst.dll
c:\windows\system32\fxsapi.dll
c:\windows\system32\fxsresm.dll
c:\windows\system32\wscinterop.dll
c:\windows\system32\wscapi.dll
c:\windows\system32\wscui.cpl
c:\windows\system32\werconcpl.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\wercplsupport.dll
c:\windows\system32\msxml6.dll
c:\windows\system32\hcproviders.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\mpr.dll
c:\windows\system32\drprov.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\devrtl.dll
c:\program files\common files\microsoft shared\office14\msoxev.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\mlang.dll
c:\windows\system32\msutb.dll
c:\windows\system32\thumbcache.dll
c:\windows\system32\winanr.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\users\admin\appdata\local\temp\winzip_v19.0_web_installer.exe
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\users\admin\appdata\local\temp\icreinstall_winzip_v19.0_web_installer.exe
c:\program files\file association helper\fahdll.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\program files\adobe\acrobat reader dc\reader\acrord32.exe
c:\program files\filezilla ftp client\filezilla.exe
c:\windows\system32\ie4uinit.exe
c:\program files\ccleaner\ccleaner.exe
c:\program files\internet explorer\iexplore.exe
c:\windows\installer\{ac76ba86-7ad7-ffff-7b44-ac0f074e4100}\sc_reader.ico
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\imageres.dll
c:\windows\installer\{90140000-003d-0000-0000-0000000ff1ce}\wordicon.exe
c:\program files\windows media player\wmplayer.exe
c:\program files\google\chrome\application\chrome.exe

PID
1256
CMD
"C:\Users\admin\AppData\Local\Temp\WinZIP_v19.0_Web_Installer.exe"
Path
C:\Users\admin\AppData\Local\Temp\WinZIP_v19.0_Web_Installer.exe
Indicators
Parent process
explorer.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\winzip_v19.0_web_installer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\version.dll
c:\windows\system32\olepro32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\propsys.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\mpr.dll

PID
2856
CMD
"C:\Users\admin\AppData\Local\Temp\WinZIP_v19.0_Web_Installer.exe" /RSF
Path
C:\Users\admin\AppData\Local\Temp\WinZIP_v19.0_Web_Installer.exe
Indicators
Parent process
WinZIP_v19.0_Web_Installer.exe
User
admin
Integrity Level
HIGH
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\winzip_v19.0_web_installer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\version.dll
c:\windows\system32\olepro32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\ws2_32.dll
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\sxs.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\propsys.dll
c:\windows\system32\mlang.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\jscript.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\imgutil.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\pngfilt.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\msiexec.exe

PID
3068
CMD
"C:\Users\admin\AppData\Local\Temp\WinZIP_v19.0_Web_Installer.exe" /_ShowProgress /PrTxt:TG9hZGluZy4uLg==
Path
C:\Users\admin\AppData\Local\Temp\WinZIP_v19.0_Web_Installer.exe
Indicators
No indicators
Parent process
WinZIP_v19.0_Web_Installer.exe
User
admin
Integrity Level
HIGH
Exit code
259
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\winzip_v19.0_web_installer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\version.dll
c:\windows\system32\olepro32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll

PID
3732
CMD
"C:\Windows\System32\msiexec.exe" /i C:\Users\admin\AppData\Local\Temp\is360511915\54FE1FCB_stp\FAH32.msi /qn
Path
C:\Windows\System32\msiexec.exe
Indicators
No indicators
Parent process
WinZIP_v19.0_Web_Installer.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\msimsg.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\rpcrtremote.dll

PID
1244
CMD
C:\Windows\system32\msiexec.exe /V
Path
C:\Windows\system32\msiexec.exe
Indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\msimsg.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msisip.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\winsta.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\microsoft.net\framework\v4.0.30319\fusion.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\cabinet.dll
c:\program files\file association helper\fahconsole.exe
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\program files\winzip\winzip32.exe
c:\program files\winzip\wz32.dll

PID
1892
CMD
"C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\File Association Helper\FAHDll.dll"
Path
C:\Windows\system32\MsiExec.exe
Indicators
No indicators
Parent process
msiexec.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\program files\file association helper\fahdll.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\atl.dll

PID
1672
CMD
"C:\Program Files\File Association Helper\FAHConsole.exe" registerSerialID
Path
C:\Program Files\File Association Helper\FAHConsole.exe
Indicators
No indicators
Parent process
msiexec.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Nico Mak Computing
Description
File Association Helper
Version
1.2.225.65451
Modules
Image
c:\program files\file association helper\fahconsole.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
3336
CMD
"C:\Program Files\File Association Helper\FAHConsole.exe"
Path
C:\Program Files\File Association Helper\FAHConsole.exe
Indicators
No indicators
Parent process
msiexec.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Nico Mak Computing
Description
File Association Helper
Version
1.2.225.65451
Modules
Image
c:\program files\file association helper\fahconsole.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\apphelp.dll
c:\program files\file association helper\fahwindow.exe

PID
2824
CMD
"C:\Program Files\File Association Helper\FAHWindow.exe" register
Path
C:\Program Files\File Association Helper\FAHWindow.exe
Indicators
No indicators
Parent process
FAHConsole.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Nico Mak Computing
Description
File Association Helper
Version
1.2.225.65451
Modules
Image
c:\program files\file association helper\fahwindow.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\file association helper\fahdll.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\credssp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\propsys.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\program files\file association helper\updatehelper.exe

PID
3416
CMD
"C:\Program Files\File Association Helper\UpdateHelper.exe" File Association Helper
Path
C:\Program Files\File Association Helper\UpdateHelper.exe
Indicators
No indicators
Parent process
FAHWindow.exe
User
admin
Integrity Level
HIGH
Exit code
1
Version:
Company
WinZip Computing International, LLC
Description
File Association Helper
Version
Modules
Image
c:\program files\file association helper\updatehelper.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\wininet.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasadhlp.dll

PID
3284
CMD
"C:\Windows\System32\msiexec.exe" /i C:\Users\admin\AppData\Local\Temp\is360511915\2D2397D4_stp.MSI /qn
Path
C:\Windows\System32\msiexec.exe
Indicators
No indicators
Parent process
WinZIP_v19.0_Web_Installer.exe
User
admin
Integrity Level
HIGH
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\msimsg.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\rpcrtremote.dll

PID
2972
CMD
C:\Windows\system32\MsiExec.exe -Embedding 49C7158557D0D91BA72A631769597D81
Path
C:\Windows\system32\MsiExec.exe
Indicators
No indicators
Parent process
msiexec.exe
User
admin
Integrity Level
HIGH
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\installer\msib793.tmp
c:\windows\installer\msib811.tmp
c:\windows\installer\msib822.tmp
c:\windows\system32\odbc32.dll
c:\windows\system32\odbcint.dll
c:\windows\installer\msib823.tmp
c:\windows\system32\psapi.dll
c:\windows\installer\msib833.tmp
c:\windows\installer\msib834.tmp
c:\windows\installer\msib845.tmp
c:\program files\internet explorer\iexplore.exe
c:\windows\installer\msib856.tmp
c:\progra~1\micros~1\office14\winword.exe
c:\progra~1\micros~1\office14\excel.exe
c:\progra~1\micros~1\office14\powerpnt.exe
c:\windows\installer\msib886.tmp
c:\windows\installer\msib896.tmp
c:\windows\installer\msib897.tmp
c:\windows\installer\msib8a8.tmp
c:\windows\installer\msib8a9.tmp
c:\windows\installer\msib985.tmp
c:\windows\installer\msib986.tmp
c:\windows\installer\msib996.tmp
c:\windows\installer\msib997.tmp
c:\windows\installer\msib9a8.tmp
c:\windows\installer\msib9b8.tmp
c:\windows\installer\msib9d9.tmp
c:\windows\installer\msib9e9.tmp
c:\windows\installer\msib9ea.tmp
c:\windows\installer\msiba88.tmp
c:\windows\installer\msibc00.tmp
c:\windows\installer\msibc10.tmp
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\installer\msibc21.tmp
c:\windows\installer\msibc31.tmp
c:\windows\installer\msibc42.tmp
c:\windows\installer\msibf62.tmp
c:\windows\installer\msicbe6.tmp
c:\windows\installer\msicbf7.tmp
c:\windows\installer\msicbf8.tmp
c:\windows\installer\msicd60.tmp
c:\windows\installer\msicd71.tmp
c:\windows\installer\msid5bf.tmp

PID
3928
CMD
"C:\Program Files\File Association Helper\FAHConsole.exe" unregister
Path
C:\Program Files\File Association Helper\FAHConsole.exe
Indicators
No indicators
Parent process
MsiExec.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Nico Mak Computing
Description
File Association Helper
Version
1.2.225.65451
Modules
Image
c:\program files\file association helper\fahconsole.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\apphelp.dll

PID
2668
CMD
"C:\Program Files\File Association Helper\FAHWindow.exe" unregister
Path
C:\Program Files\File Association Helper\FAHWindow.exe
Indicators
No indicators
Parent process
FAHConsole.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Nico Mak Computing
Description
File Association Helper
Version
1.2.225.65451
Modules
Image
c:\program files\file association helper\fahwindow.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\file association helper\fahdll.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
860
CMD
"C:\Program Files\WinZip\WINZIP32.EXE" /noqp /nodesktop /nostartmenu /nomenugroup /autoinstall /lang 1033
Path
C:\Program Files\WinZip\WINZIP32.EXE
Indicators
No indicators
Parent process
msiexec.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
WinZip Computing, S.L.
Description
WinZip
Version
30.0 (32-bit)
Modules
Image
c:\program files\winzip\winzip32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\msimg32.dll
c:\program files\winzip\wzeay32.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\psapi.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msi.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\uxtheme.dll
c:\program files\winzip\wzwfr32.dll
c:\windows\system32\uiribbon.dll
c:\program files\winzip\wzcktree32.dll
c:\program files\winzip\wzvinfo32.dll
c:\program files\winzip\wzgdip32.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\uiribbonres.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\imageres.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\program files\winzip\wzsensor32.dll
c:\windows\system32\sensorsapi.dll
c:\windows\system32\wdscore.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\mapi32.dll
c:\program files\winzip\wzwpfcldpicker32.dll
c:\windows\system32\mscoree.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcm90.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcp90.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\system32\iconcodecservice.dll
c:\progra~1\micros~1\office14\winword.exe
c:\progra~1\micros~1\office14\excel.exe
c:\progra~1\micros~1\office14\powerpnt.exe
c:\progra~1\micros~1\office14\outlook.exe
c:\program files\winzip\wzwia32.dll
c:\windows\system32\msxml6.dll
c:\windows\system32\netutils.dll

PID
1916
CMD
"C:\Program Files\WinZip\WzPreviewer32.exe" -regserver winzip
Path
C:\Program Files\WinZip\WzPreviewer32.exe
Indicators
No indicators
Parent process
msiexec.exe
User
admin
Integrity Level
HIGH
Version:
Company
WinZip Computing, S.L.
Description
WinZip Previewer (32-bit)
Version
2.1 (32-bit)
Modules
Image

Registry activity

Total events
4064
Read events
3039
Write events
1012
Delete events
13

Modification events

PID
Process
Operation
Key
Name
Value
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\NccQngn\Ybpny\Grzc\JvaMVC_i19.0_Jro_Vafgnyyre.rkr
00000000000000000100000000000000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000000500000004000000C0CD000003000000020000008F8F00004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000002402000000003CE8240201000000000000000000EA7510E82402FCE524025E7C63773CE82402787C6377030000008A018C012C6DD4022CE62402F77C63770100000010E82402847C63777CE6240270E6240288E6240200000000000000000000000078E6240210E82402000000000000000000000000B0E72402B0E7240200000000010000003CE82402B0E72402B2FE6377F270637785FC6377838C4F759A7C62772C6DD402A27E6277F4E7240218000000CCF92402006F62770000000000000000DCE724023C003E003CE82402C34EE5007CE6240200000000D846230000002402D8E62402C4E9240200000088C8000000C8000000C8000000C8000000F20103000000000000000769D8914D030106004000000000B0E92402105307697FEBE4752000000011000000B8452400B045240000000000C4E924020000000064E700001F3C892414E724028291097664E7240218E72402279509760000000024CDDE0240E72402CD94097624CDDE02ECE7240298C8DE02E19409760000000098C8DE02ECE7240248E7240203000000020000008F8F00004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000002402000000003CE8240201000000000000000000EA7510E82402FCE524025E7C63773CE82402787C6377030000008A018C012C6DD4022CE62402F77C63770100000010E82402847C63777CE6240270E6240288E6240200000000000000000000000078E6240210E82402000000000000000000000000B0E72402B0E7240200000000010000003CE82402B0E72402B2FE6377F270637785FC6377838C4F759A7C62772C6DD402A27E6277F4E7240218000000CCF92402006F62770000000000000000DCE724023C003E003CE82402C34EE5007CE6240200000000D846230000002402D8E62402C4E9240200000088C8000000C8000000C8000000C8000000F20103000000000000000769D8914D030106004000000000B0E92402105307697FEBE4752000000011000000B8452400B045240000000000C4E924020000000064E700001F3C892414E724028291097664E7240218E72402279509760000000024CDDE0240E72402CD94097624CDDE02ECE7240298C8DE02E19409760000000098C8DE02ECE7240248E7240203000000020000008F8F00004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000002402000000003CE8240201000000000000000000EA7510E82402FCE524025E7C63773CE82402787C6377030000008A018C012C6DD4022CE62402F77C63770100000010E82402847C63777CE6240270E6240288E6240200000000000000000000000078E6240210E82402000000000000000000000000B0E72402B0E7240200000000010000003CE82402B0E72402B2FE6377F270637785FC6377838C4F759A7C62772C6DD402A27E6277F4E7240218000000CCF92402006F62770000000000000000DCE724023C003E003CE82402C34EE5007CE6240200000000D846230000002402D8E62402C4E9240200000088C8000000C8000000C8000000C8000000F20103000000000000000769D8914D030106004000000000B0E92402105307697FEBE4752000000011000000B8452400B045240000000000C4E924020000000064E700001F3C892414E724028291097664E7240218E72402279509760000000024CDDE0240E72402CD94097624CDDE02ECE7240298C8DE02E19409760000000098C8DE02ECE7240248E72402
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\NccQngn\Ybpny\Grzc\JvaMVC_i19.0_Jro_Vafgnyyre.rkr
00000000000000000200000000000000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000000500000005000000C0CD000003000000020000008F8F00004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000002402000000003CE8240201000000000000000000EA7510E82402FCE524025E7C63773CE82402787C6377030000008A018C012C6DD4022CE62402F77C63770100000010E82402847C63777CE6240270E6240288E6240200000000000000000000000078E6240210E82402000000000000000000000000B0E72402B0E7240200000000010000003CE82402B0E72402B2FE6377F270637785FC6377838C4F759A7C62772C6DD402A27E6277F4E7240218000000CCF92402006F62770000000000000000DCE724023C003E003CE82402C34EE5007CE6240200000000D846230000002402D8E62402C4E9240200000088C8000000C8000000C8000000C8000000F20103000000000000000769D8914D030106004000000000B0E92402105307697FEBE4752000000011000000B8452400B045240000000000C4E924020000000064E700001F3C892414E724028291097664E7240218E72402279509760000000024CDDE0240E72402CD94097624CDDE02ECE7240298C8DE02E19409760000000098C8DE02ECE7240248E7240203000000020000008F8F00004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000002402000000003CE8240201000000000000000000EA7510E82402FCE524025E7C63773CE82402787C6377030000008A018C012C6DD4022CE62402F77C63770100000010E82402847C63777CE6240270E6240288E6240200000000000000000000000078E6240210E82402000000000000000000000000B0E72402B0E7240200000000010000003CE82402B0E72402B2FE6377F270637785FC6377838C4F759A7C62772C6DD402A27E6277F4E7240218000000CCF92402006F62770000000000000000DCE724023C003E003CE82402C34EE5007CE6240200000000D846230000002402D8E62402C4E9240200000088C8000000C8000000C8000000C8000000F20103000000000000000769D8914D030106004000000000B0E92402105307697FEBE4752000000011000000B8452400B045240000000000C4E924020000000064E700001F3C892414E724028291097664E7240218E72402279509760000000024CDDE0240E72402CD94097624CDDE02ECE7240298C8DE02E19409760000000098C8DE02ECE7240248E7240203000000020000008F8F00004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000002402000000003CE8240201000000000000000000EA7510E82402FCE524025E7C63773CE82402787C6377030000008A018C012C6DD4022CE62402F77C63770100000010E82402847C63777CE6240270E6240288E6240200000000000000000000000078E6240210E82402000000000000000000000000B0E72402B0E7240200000000010000003CE82402B0E72402B2FE6377F270637785FC6377838C4F759A7C62772C6DD402A27E6277F4E7240218000000CCF92402006F62770000000000000000DCE724023C003E003CE82402C34EE5007CE6240200000000D846230000002402D8E62402C4E9240200000088C8000000C8000000C8000000C8000000F20103000000000000000769D8914D030106004000000000B0E92402105307697FEBE4752000000011000000B8452400B045240000000000C4E924020000000064E700001F3C892414E724028291097664E7240218E72402279509760000000024CDDE0240E72402CD94097624CDDE02ECE7240298C8DE02E19409760000000098C8DE02ECE7240248E72402
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\NccQngn\Ybpny\Grzc\JvaMVC_i19.0_Jro_Vafgnyyre.rkr
00000000000000000200000098470000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
0000000005000000050000005815010003000000020000008F8F00004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000002402000000003CE8240201000000000000000000EA7510E82402FCE524025E7C63773CE82402787C6377030000008A018C012C6DD4022CE62402F77C63770100000010E82402847C63777CE6240270E6240288E6240200000000000000000000000078E6240210E82402000000000000000000000000B0E72402B0E7240200000000010000003CE82402B0E72402B2FE6377F270637785FC6377838C4F759A7C62772C6DD402A27E6277F4E7240218000000CCF92402006F62770000000000000000DCE724023C003E003CE82402C34EE5007CE6240200000000D846230000002402D8E62402C4E9240200000088C8000000C8000000C8000000C8000000F20103000000000000000769D8914D030106004000000000B0E92402105307697FEBE4752000000011000000B8452400B045240000000000C4E924020000000064E700001F3C892414E724028291097664E7240218E72402279509760000000024CDDE0240E72402CD94097624CDDE02ECE7240298C8DE02E19409760000000098C8DE02ECE7240248E7240203000000020000008F8F00004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000002402000000003CE8240201000000000000000000EA7510E82402FCE524025E7C63773CE82402787C6377030000008A018C012C6DD4022CE62402F77C63770100000010E82402847C63777CE6240270E6240288E6240200000000000000000000000078E6240210E82402000000000000000000000000B0E72402B0E7240200000000010000003CE82402B0E72402B2FE6377F270637785FC6377838C4F759A7C62772C6DD402A27E6277F4E7240218000000CCF92402006F62770000000000000000DCE724023C003E003CE82402C34EE5007CE6240200000000D846230000002402D8E62402C4E9240200000088C8000000C8000000C8000000C8000000F20103000000000000000769D8914D030106004000000000B0E92402105307697FEBE4752000000011000000B8452400B045240000000000C4E924020000000064E700001F3C892414E724028291097664E7240218E72402279509760000000024CDDE0240E72402CD94097624CDDE02ECE7240298C8DE02E19409760000000098C8DE02ECE7240248E7240203000000020000008F8F00004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000002402000000003CE8240201000000000000000000EA7510E82402FCE524025E7C63773CE82402787C6377030000008A018C012C6DD4022CE62402F77C63770100000010E82402847C63777CE6240270E6240288E6240200000000000000000000000078E6240210E82402000000000000000000000000B0E72402B0E7240200000000010000003CE82402B0E72402B2FE6377F270637785FC6377838C4F759A7C62772C6DD402A27E6277F4E7240218000000CCF92402006F62770000000000000000DCE724023C003E003CE82402C34EE5007CE6240200000000D846230000002402D8E62402C4E9240200000088C8000000C8000000C8000000C8000000F20103000000000000000769D8914D030106004000000000B0E92402105307697FEBE4752000000011000000B8452400B045240000000000C4E924020000000064E700001F3C892414E724028291097664E7240218E72402279509760000000024CDDE0240E72402CD94097624CDDE02ECE7240298C8DE02E19409760000000098C8DE02ECE7240248E72402
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\NccQngn\Ybpny\Grzc\JvaMVC_i19.0_Jro_Vafgnyyre.rkr
00000000000000000300000098470000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
0000000005000000060000005815010003000000020000008F8F00004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000002402000000003CE8240201000000000000000000EA7510E82402FCE524025E7C63773CE82402787C6377030000008A018C012C6DD4022CE62402F77C63770100000010E82402847C63777CE6240270E6240288E6240200000000000000000000000078E6240210E82402000000000000000000000000B0E72402B0E7240200000000010000003CE82402B0E72402B2FE6377F270637785FC6377838C4F759A7C62772C6DD402A27E6277F4E7240218000000CCF92402006F62770000000000000000DCE724023C003E003CE82402C34EE5007CE6240200000000D846230000002402D8E62402C4E9240200000088C8000000C8000000C8000000C8000000F20103000000000000000769D8914D030106004000000000B0E92402105307697FEBE4752000000011000000B8452400B045240000000000C4E924020000000064E700001F3C892414E724028291097664E7240218E72402279509760000000024CDDE0240E72402CD94097624CDDE02ECE7240298C8DE02E19409760000000098C8DE02ECE7240248E7240200000000030000009847000043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C004C006F00630061006C005C00540065006D0070005C00570069006E005A00490050005F007600310039002E0030005F005700650062005F0049006E007300740061006C006C00650072002E006500780065000000000004E524028CE5240298EB2402EDE05F7793740800FEFFFFFFE72F6377822E637700000000A0E624020000000014E624020000000014E6240278000000CCE52402FE726377D8E62402FCE82402780000001800000014E6240200000000E8E5240251EE6377CF8E4F7500000000A0E624021E0000000CE6240220EF6377B8CB2C000AA562771E00000000000000A0E62402000000003B8D4F758CE62402D6A8647728E6240240E62402000000000000000000002100B8CB2C005A008A00D6CB2C001E000200E120000040E62402000000000105000048C22C0001000000B0CB2C0068E62402E82C6377F0E624021000000088E6240220EF6377A4E72402C059F5751000000018000000F0E6240200000000F0E6240276000000A8E6240211000000B8452400B04524007600000018000000F0E624020000000014E70000533C8924C8E624028291097614E72402CCE62402279509760000000024CDDE02F4E62402CD94097624CDDE0298C8DE0298E72402E19409760000000098C8DE0298E72402FCE6240203000000020000008F8F00004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000002402000000003CE8240201000000000000000000EA7510E82402FCE524025E7C63773CE82402787C6377030000008A018C012C6DD4022CE62402F77C63770100000010E82402847C63777CE6240270E6240288E6240200000000000000000000000078E6240210E82402000000000000000000000000B0E72402B0E7240200000000010000003CE82402B0E72402B2FE6377F270637785FC6377838C4F759A7C62772C6DD402A27E6277F4E7240218000000CCF92402006F62770000000000000000DCE724023C003E003CE82402C34EE5007CE6240200000000D846230000002402D8E62402C4E9240200000088C8000000C8000000C8000000C8000000F20103000000000000000769D8914D030106004000000000B0E92402105307697FEBE4752000000011000000B8452400B045240000000000C4E924020000000064E700001F3C892414E724028291097664E7240218E72402279509760000000024CDDE0240E72402CD94097624CDDE02ECE7240298C8DE02E19409760000000098C8DE02ECE7240248E72402
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\NccQngn\Ybpny\Grzc\JvaMVC_i19.0_Jro_Vafgnyyre.rkr
00000000000000000300000021530000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
2036
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000000500000006000000E120010003000000020000008F8F00004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000002402000000003CE8240201000000000000000000EA7510E82402FCE524025E7C63773CE82402787C6377030000008A018C012C6DD4022CE62402F77C63770100000010E82402847C63777CE6240270E6240288E6240200000000000000000000000078E6240210E82402000000000000000000000000B0E72402B0E7240200000000010000003CE82402B0E72402B2FE6377F270637785FC6377838C4F759A7C62772C6DD402A27E6277F4E7240218000000CCF92402006F62770000000000000000DCE724023C003E003CE82402C34EE5007CE6240200000000D846230000002402D8E62402C4E9240200000088C8000000C8000000C8000000C8000000F20103000000000000000769D8914D030106004000000000B0E92402105307697FEBE4752000000011000000B8452400B045240000000000C4E924020000000064E700001F3C892414E724028291097664E7240218E72402279509760000000024CDDE0240E72402CD94097624CDDE02ECE7240298C8DE02E19409760000000098C8DE02ECE7240248E7240200000000030000002153000043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C004C006F00630061006C005C00540065006D0070005C00570069006E005A00490050005F007600310039002E0030005F005700650062005F0049006E007300740061006C006C00650072002E0065007800650000006500780065000000000004E524028CE5240298EB2402EDE05F7793740800FEFFFFFFE72F6377822E637700000000A0E624020000000014E624020000000014E6240278000000CCE52402FE726377D8E62402FCE82402780000001800000014E6240200000000E8E5240251EE6377CF8E4F7500000000A0E624021E0000000CE6240220EF6377B8CB2C000AA562771E00000000000000A0E62402000000003B8D4F758CE62402D6A8647728E6240240E62402000000000000000000002100B8CB2C005A008A00D6CB2C001E000200E120000040E62402000000000105000048C22C0001000000B0CB2C0068E62402E82C6377F0E624021000000088E6240220EF6377A4E72402C059F5751000000018000000F0E6240200000000F0E6240276000000A8E6240211000000B8452400B0452400760000001800000010E700004B3C8924C0E624028291097610E72402C4E62402279509760000000024CDDE02ECE62402CD94097624CDDE0298E7240298C8DE02E19409760000000098C8DE0298E72402F4E6240203000000020000008F8F00004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000002402000000003CE8240201000000000000000000EA7510E82402FCE524025E7C63773CE82402787C6377030000008A018C012C6DD4022CE62402F77C63770100000010E82402847C63777CE6240270E6240288E6240200000000000000000000000078E6240210E82402000000000000000000000000B0E72402B0E7240200000000010000003CE82402B0E72402B2FE6377F270637785FC6377838C4F759A7C62772C6DD402A27E6277F4E7240218000000CCF92402006F62770000000000000000DCE724023C003E003CE82402C34EE5007CE6240200000000D846230000002402D8E62402C4E9240200000088C8000000C8000000C8000000C8000000F20103000000000000000769D8914D030106004000000000B0E92402105307697FEBE4752000000011000000B8452400B045240000000000C4E924020000000064E700001F3C892414E724028291097664E7240218E72402279509760000000024CDDE0240E72402CD94097624CDDE02ECE7240298C8DE02E19409760000000098C8DE02ECE7240248E72402
2036
explorer.exe
delete key
HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
2036
explorer.exe
delete key
HKEY_CLASSES_ROOT\Local Settings\MuiCache\62
2036
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\63\52C64B7E
LanguageList
en-US
2036
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\63\52C64B7E
@"%windir%\System32\ie4uinit.exe",-732
Finds and displays information and Web sites on the Internet.
1256
WinZIP_v19.0_Web_Installer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
1256
WinZIP_v19.0_Web_Installer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2856
WinZIP_v19.0_Web_Installer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2856
WinZIP_v19.0_Web_Installer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2856
WinZIP_v19.0_Web_Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WinZIP_v19_RASAPI32
EnableFileTracing
0
2856
WinZIP_v19.0_Web_Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WinZIP_v19_RASAPI32
EnableConsoleTracing
0
2856
WinZIP_v19.0_Web_Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WinZIP_v19_RASAPI32
FileTracingMask
4294901760
2856
WinZIP_v19.0_Web_Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WinZIP_v19_RASAPI32
ConsoleTracingMask
4294901760
2856
WinZIP_v19.0_Web_Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WinZIP_v19_RASAPI32
MaxFileSize
1048576
2856
WinZIP_v19.0_Web_Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WinZIP_v19_RASAPI32
FileDirectory
%windir%\tracing
2856
WinZIP_v19.0_Web_Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WinZIP_v19_RASMANCS
EnableFileTracing
0
2856
WinZIP_v19.0_Web_Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WinZIP_v19_RASMANCS
EnableConsoleTracing
0
2856
WinZIP_v19.0_Web_Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WinZIP_v19_RASMANCS
FileTracingMask
4294901760
2856
WinZIP_v19.0_Web_Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WinZIP_v19_RASMANCS
ConsoleTracingMask
4294901760
2856
WinZIP_v19.0_Web_Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WinZIP_v19_RASMANCS
MaxFileSize
1048576
2856
WinZIP_v19.0_Web_Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WinZIP_v19_RASMANCS
FileDirectory
%windir%\tracing
2856
WinZIP_v19.0_Web_Installer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2856
WinZIP_v19.0_Web_Installer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000071000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
1244
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000_CLASSES\Local Settings\MuiCache\62\52C64B7E
LanguageList
en-US
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81
Blob
0F000000010000001400000085FEF11B4F47FE3952F98301C9F98976FEFEE0CE09000000010000002A000000302806082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030353000000010000002500000030233021060B6086480186F8450107300130123010060A2B0601040182373C0101030200C01400000001000000140000007B5B45CFAFCECB7AFD31921A6AB6F346EB5748501D00000001000000100000005B3B67000EEB80022E42605B6B3B72400B000000010000000E000000740068006100770074006500000003000000010000001400000091C6D6EE3E8AC86384E548C299295C756C817B812000000001000000240400003082042030820308A0030201020210344ED55720D5EDEC49F42FCE37DB2B6D300D06092A864886F70D01010505003081A9310B300906035504061302555331153013060355040A130C7468617774652C20496E632E31283026060355040B131F43657274696669636174696F6E205365727669636573204469766973696F6E31383036060355040B132F2863292032303036207468617774652C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79311F301D06035504031316746861777465205072696D61727920526F6F74204341301E170D3036313131373030303030305A170D3336303731363233353935395A3081A9310B300906035504061302555331153013060355040A130C7468617774652C20496E632E31283026060355040B131F43657274696669636174696F6E205365727669636573204469766973696F6E31383036060355040B132F2863292032303036207468617774652C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79311F301D06035504031316746861777465205072696D61727920526F6F7420434130820122300D06092A864886F70D01010105000382010F003082010A0282010100ACA0F0FB8059D49CC7A4CF9DA159730910450C0D2C6E68F16C5B4868495937FC0B3319C2777FCC102D95341CE6EB4D09A71CD2B8C9973602B789D4245F06C0CC4494948D02626FEB5ADD118D289A5C8490107A0DBD74662F6A38A0E2D55444EB1D079F07BA6FEEE9FD4E0B29F53E84A001F19CABF81C7E89A4E8A1D871650DA3517BEEBCD222600DB95B9DDFBAFC515B0BAF98B2E92EE904E86287DE2BC8D74EC14C641EDDCF8758BA4A4FCA68071D1C9D4AC6D52F91CC7C71721CC5C067EB32FDC9925C94DA85C09BBF537D2B09F48C9D911F976A52CBDE0936A477D87B875044D53E6E2969FB3949261E09A5807B402DEBE82785C9FE61FD7EE67C971DD59D0203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E041604147B5B45CFAFCECB7AFD31921A6AB6F346EB574850300D06092A864886F70D010105050003820101007911C04BB391B6FCF0E967D40D6E45BE55E893D2CE033FEDDA25B01D57CB1E3A76A04CEC5076E864720CA4A9F1B88BD6D68784BB32E54111C077D9B3609DEB1BD5D16E4444A9A601EC55621D77B85C8E48497C9C3B5711ACAD73378E2F785C906847D96060E6FC073D222017C4F716E9C4D872F9C8737CDF162F15A93EFD6A27B6A1EB5ABA981FD5E34D640A9D13C861BAF5391C87BAB8BD7B227FF6FEAC4079E5AC106F3D8F1B79768BC437B3211884E53600EB632099B9E9FE3304BB41C8C102F94463209E81CE42D3D63F2C76D3639C59DD8FA6E10EA02E41F72E9547CFBCFD33F3F60B617E7E912B8147C22730EEA7105D378F5C392BE404F07B8D568C68
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81
Blob
190000000100000010000000DC73F9B71E16D51D26527D32B11A6A3D03000000010000001400000091C6D6EE3E8AC86384E548C299295C756C817B810B000000010000000E00000074006800610077007400650000001D00000001000000100000005B3B67000EEB80022E42605B6B3B72401400000001000000140000007B5B45CFAFCECB7AFD31921A6AB6F346EB57485053000000010000002500000030233021060B6086480186F8450107300130123010060A2B0601040182373C0101030200C009000000010000002A000000302806082B0601050507030106082B0601050507030206082B0601050507030406082B060105050703030F000000010000001400000085FEF11B4F47FE3952F98301C9F98976FEFEE0CE2000000001000000240400003082042030820308A0030201020210344ED55720D5EDEC49F42FCE37DB2B6D300D06092A864886F70D01010505003081A9310B300906035504061302555331153013060355040A130C7468617774652C20496E632E31283026060355040B131F43657274696669636174696F6E205365727669636573204469766973696F6E31383036060355040B132F2863292032303036207468617774652C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79311F301D06035504031316746861777465205072696D61727920526F6F74204341301E170D3036313131373030303030305A170D3336303731363233353935395A3081A9310B300906035504061302555331153013060355040A130C7468617774652C20496E632E31283026060355040B131F43657274696669636174696F6E205365727669636573204469766973696F6E31383036060355040B132F2863292032303036207468617774652C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79311F301D06035504031316746861777465205072696D61727920526F6F7420434130820122300D06092A864886F70D01010105000382010F003082010A0282010100ACA0F0FB8059D49CC7A4CF9DA159730910450C0D2C6E68F16C5B4868495937FC0B3319C2777FCC102D95341CE6EB4D09A71CD2B8C9973602B789D4245F06C0CC4494948D02626FEB5ADD118D289A5C8490107A0DBD74662F6A38A0E2D55444EB1D079F07BA6FEEE9FD4E0B29F53E84A001F19CABF81C7E89A4E8A1D871650DA3517BEEBCD222600DB95B9DDFBAFC515B0BAF98B2E92EE904E86287DE2BC8D74EC14C641EDDCF8758BA4A4FCA68071D1C9D4AC6D52F91CC7C71721CC5C067EB32FDC9925C94DA85C09BBF537D2B09F48C9D911F976A52CBDE0936A477D87B875044D53E6E2969FB3949261E09A5807B402DEBE82785C9FE61FD7EE67C971DD59D0203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E041604147B5B45CFAFCECB7AFD31921A6AB6F346EB574850300D06092A864886F70D010105050003820101007911C04BB391B6FCF0E967D40D6E45BE55E893D2CE033FEDDA25B01D57CB1E3A76A04CEC5076E864720CA4A9F1B88BD6D68784BB32E54111C077D9B3609DEB1BD5D16E4444A9A601EC55621D77B85C8E48497C9C3B5711ACAD73378E2F785C906847D96060E6FC073D222017C4F716E9C4D872F9C8737CDF162F15A93EFD6A27B6A1EB5ABA981FD5E34D640A9D13C861BAF5391C87BAB8BD7B227FF6FEAC4079E5AC106F3D8F1B79768BC437B3211884E53600EB632099B9E9FE3304BB41C8C102F94463209E81CE42D3D63F2C76D3639C59DD8FA6E10EA02E41F72E9547CFBCFD33F3F60B617E7E912B8147C22730EEA7105D378F5C392BE404F07B8D568C68
1244
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Owner
DC040000C6D10BC8DA0AD501
1244
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
SessionHash
688F734A824F59426DCD1BD4E13A1D68D72508101FDFEF0B9690D5158E0DD042
1244
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Sequence
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress
C:\Windows\Installer\124cb3.ipi
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Config.Msi\
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\124cb4.rbs
30739171
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\124cb4.rbsLow
708378384
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DA4BB207EC838B24FAA73DEBE04E7AB6
BC3E5798267A41B4DB263A79A290E828
C:\Program Files\File Association Helper\FAH.exe
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3277B15959B706B46BF52981AA9C6C1A
BC3E5798267A41B4DB263A79A290E828
C:\Program Files\File Association Helper\FAHConsole.exe
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\12F437337E7587F4284801EEE7A3E543
BC3E5798267A41B4DB263A79A290E828
C:\Program Files\File Association Helper\FAHDll.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B502849FEC3B3FA4B9EBC43628635369
BC3E5798267A41B4DB263A79A290E828
C:\Program Files\File Association Helper\FAHWindow.exe
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\41B2C2054806AE44E852D3A7325BA02C
BC3E5798267A41B4DB263A79A290E828
C:\Program Files\File Association Helper\UpdateHelper.exe
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E783BB3164730F644AFCD2E818DB9C8D
BC3E5798267A41B4DB263A79A290E828
02:\Software\Nico Mak Computing\File Association Helper\Version
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5B3CB3AA236511941B416EBC3FB634FB
BC3E5798267A41B4DB263A79A290E828
01:\Software\Nico Mak Computing\File Association Helper\Default
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AFF6C02708956E2498F56E53D4B937A0
BC3E5798267A41B4DB263A79A290E828
02:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\FAHConsole
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\File Association Helper\
1244
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Nico Mak Computing\File Association Helper
Default
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\File Association Helper
Version
1020225
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\File Association Helper
CID
aea50844-c115-4b30-0000-d298d1dddd71
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\File Association Helper
Path
C:\Program Files\File Association Helper\
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\File Association Helper
DefaultLanguage
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
FAHConsole
C:\Program Files\File Association Helper\FAHConsole.exe
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BC3E5798267A41B4DB263A79A290E828\InstallProperties
LocalPackage
C:\Windows\Installer\124cb5.msi
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BC3E5798267A41B4DB263A79A290E828\InstallProperties
AuthorizedCDFPrefix
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BC3E5798267A41B4DB263A79A290E828\InstallProperties
Comments
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BC3E5798267A41B4DB263A79A290E828\InstallProperties
Contact
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BC3E5798267A41B4DB263A79A290E828\InstallProperties
DisplayVersion
1.2.225.65451
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BC3E5798267A41B4DB263A79A290E828\InstallProperties
HelpLink
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BC3E5798267A41B4DB263A79A290E828\InstallProperties
HelpTelephone
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BC3E5798267A41B4DB263A79A290E828\InstallProperties
InstallDate
20190515
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BC3E5798267A41B4DB263A79A290E828\InstallProperties
InstallLocation
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BC3E5798267A41B4DB263A79A290E828\InstallProperties
InstallSource
C:\Users\admin\AppData\Local\Temp\is360511915\54FE1FCB_stp\
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BC3E5798267A41B4DB263A79A290E828\InstallProperties
ModifyPath
MsiExec.exe /X{8975E3CB-A762-4B14-BD62-A3972A098E82}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BC3E5798267A41B4DB263A79A290E828\InstallProperties
NoModify
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BC3E5798267A41B4DB263A79A290E828\InstallProperties
NoRepair
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BC3E5798267A41B4DB263A79A290E828\InstallProperties
Publisher
WinZip Computing International, LLC
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BC3E5798267A41B4DB263A79A290E828\InstallProperties
Readme
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BC3E5798267A41B4DB263A79A290E828\InstallProperties
Size
9000
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BC3E5798267A41B4DB263A79A290E828\InstallProperties
EstimatedSize
3971
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BC3E5798267A41B4DB263A79A290E828\InstallProperties
UninstallString
MsiExec.exe /X{8975E3CB-A762-4B14-BD62-A3972A098E82}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BC3E5798267A41B4DB263A79A290E828\InstallProperties
URLInfoAbout
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BC3E5798267A41B4DB263A79A290E828\InstallProperties
URLUpdateInfo
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BC3E5798267A41B4DB263A79A290E828\InstallProperties
VersionMajor
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BC3E5798267A41B4DB263A79A290E828\InstallProperties
VersionMinor
2
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BC3E5798267A41B4DB263A79A290E828\InstallProperties
WindowsInstaller
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BC3E5798267A41B4DB263A79A290E828\InstallProperties
Version
16908513
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BC3E5798267A41B4DB263A79A290E828\InstallProperties
Language
1033
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8975E3CB-A762-4B14-BD62-A3972A098E82}
AuthorizedCDFPrefix
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8975E3CB-A762-4B14-BD62-A3972A098E82}
Comments
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8975E3CB-A762-4B14-BD62-A3972A098E82}
Contact
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8975E3CB-A762-4B14-BD62-A3972A098E82}
DisplayVersion
1.2.225.65451
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8975E3CB-A762-4B14-BD62-A3972A098E82}
HelpLink
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8975E3CB-A762-4B14-BD62-A3972A098E82}
HelpTelephone
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8975E3CB-A762-4B14-BD62-A3972A098E82}
InstallDate
20190515
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8975E3CB-A762-4B14-BD62-A3972A098E82}
InstallLocation
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8975E3CB-A762-4B14-BD62-A3972A098E82}
InstallSource
C:\Users\admin\AppData\Local\Temp\is360511915\54FE1FCB_stp\
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8975E3CB-A762-4B14-BD62-A3972A098E82}
ModifyPath
MsiExec.exe /X{8975E3CB-A762-4B14-BD62-A3972A098E82}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8975E3CB-A762-4B14-BD62-A3972A098E82}
NoModify
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8975E3CB-A762-4B14-BD62-A3972A098E82}
NoRepair
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8975E3CB-A762-4B14-BD62-A3972A098E82}
Publisher
WinZip Computing International, LLC
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8975E3CB-A762-4B14-BD62-A3972A098E82}
Readme
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8975E3CB-A762-4B14-BD62-A3972A098E82}
Size
9000
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8975E3CB-A762-4B14-BD62-A3972A098E82}
EstimatedSize
3971
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8975E3CB-A762-4B14-BD62-A3972A098E82}
UninstallString
MsiExec.exe /X{8975E3CB-A762-4B14-BD62-A3972A098E82}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8975E3CB-A762-4B14-BD62-A3972A098E82}
URLInfoAbout
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8975E3CB-A762-4B14-BD62-A3972A098E82}
URLUpdateInfo
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8975E3CB-A762-4B14-BD62-A3972A098E82}
VersionMajor
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8975E3CB-A762-4B14-BD62-A3972A098E82}
VersionMinor
2
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8975E3CB-A762-4B14-BD62-A3972A098E82}
WindowsInstaller
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8975E3CB-A762-4B14-BD62-A3972A098E82}
Version
16908513
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8975E3CB-A762-4B14-BD62-A3972A098E82}
Language
1033
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\D03BD1E9B79EDE565206F0AA2ABEE734
BC3E5798267A41B4DB263A79A290E828
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BC3E5798267A41B4DB263A79A290E828\InstallProperties
DisplayName
File Association Helper
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8975E3CB-A762-4B14-BD62-A3972A098E82}
DisplayName
File Association Helper
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\BC3E5798267A41B4DB263A79A290E828
FAH
FAHSetup
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BC3E5798267A41B4DB263A79A290E828\Features
FAH
}BH'L%%eM96K1Df)8&[[email protected]==?u*Z6W~[?EXU4*}%VA)(aSut7_o47_+-y=J[*@-^ivGWYS?X5-7jA83d0==[email protected][email protected]+Pfgub`L&M^R9(?QC55dTF&FAHSetup
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\BC3E5798267A41B4DB263A79A290E828
FAHSetup
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BC3E5798267A41B4DB263A79A290E828\Features
FAHSetup
X8&E)-Fzl=XZ2dU`oJbn
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Windows\Installer\{8975E3CB-A762-4B14-BD62-A3972A098E82}\
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BC3E5798267A41B4DB263A79A290E828\Patches
AllPatches
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\BC3E5798267A41B4DB263A79A290E828
ProductName
File Association Helper
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\BC3E5798267A41B4DB263A79A290E828
PackageCode
DC5B85DC4715D3E479063051CD4B81AF
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\BC3E5798267A41B4DB263A79A290E828
Language
1033
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\BC3E5798267A41B4DB263A79A290E828
Version
16908513
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\BC3E5798267A41B4DB263A79A290E828
Assignment
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\BC3E5798267A41B4DB263A79A290E828
AdvertiseFlags
388
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\BC3E5798267A41B4DB263A79A290E828
ProductIcon
C:\Windows\Installer\{8975E3CB-A762-4B14-BD62-A3972A098E82}\icon.ico
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\BC3E5798267A41B4DB263A79A290E828
InstanceType
0
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\BC3E5798267A41B4DB263A79A290E828
AuthorizedLUAApp
0
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\BC3E5798267A41B4DB263A79A290E828
DeploymentFlags
3
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\D03BD1E9B79EDE565206F0AA2ABEE734
BC3E5798267A41B4DB263A79A290E828
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\BC3E5798267A41B4DB263A79A290E828\SourceList
PackageName
FAH32.msi
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\BC3E5798267A41B4DB263A79A290E828\SourceList\Net
1
C:\Users\admin\AppData\Local\Temp\is360511915\54FE1FCB_stp\
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\BC3E5798267A41B4DB263A79A290E828\SourceList\Media
1
;
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\BC3E5798267A41B4DB263A79A290E828
Clients
:
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\BC3E5798267A41B4DB263A79A290E828\SourceList
LastUsedSource
n;1;C:\Users\admin\AppData\Local\Temp\is360511915\54FE1FCB_stp\
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings
StringCacheGeneration
99
1244
msiexec.exe
delete key
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\62\52C64B7E
1244
msiexec.exe
delete key
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\62
1244
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
1244
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback
1244
msiexec.exe
delete key
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
1244
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD
Blob
040000000100000010000000C5DFB849CA051355EE2DBA1AC33EB0280F00000001000000200000005229BA15B31B0C6F4CCA89C2985177974327D1B689A3B935A0BD975532AF22AB090000000100000054000000305206082B0601050507030106082B0601050507030206082B0601050507030306082B0601050507030406082B06010505070308060A2B0601040182370A030406082B0601050507030606082B060105050703070B000000010000003000000047006C006F00620061006C005300690067006E00200052006F006F00740020004300410020002D0020005200330000005300000001000000230000003021301F06092B06010401A032010130123010060A2B0601040182373C0101030200C0620000000100000020000000CBB522D7B7F127AD6A0113865BDF1CD4102E7D0759AF635A7CF4720DC963C53B1400000001000000140000008FF04B7FA82E4524AE4D50FA639A8BDEE2DD1BBC1D000000010000001000000001728E1ECF7A9D86FB3CEC8948ABA953030000000100000014000000D69B561148F01C77C54578C10926DF5B856976AD190000000100000010000000D0FD3C9C380D7B65E26B9A3FEDD39B8F2000000001000000630300003082035F30820247A003020102020B04000000000121585308A2300D06092A864886F70D01010B0500304C3120301E060355040B1317476C6F62616C5369676E20526F6F74204341202D20523331133011060355040A130A476C6F62616C5369676E311330110603550403130A476C6F62616C5369676E301E170D3039303331383130303030305A170D3239303331383130303030305A304C3120301E060355040B1317476C6F62616C5369676E20526F6F74204341202D20523331133011060355040A130A476C6F62616C5369676E311330110603550403130A476C6F62616C5369676E30820122300D06092A864886F70D01010105000382010F003082010A0282010100CC2576907906782216F5C083B684CA289EFD057611C5AD8872FC460243C7B28A9D045F24CB2E4BE1608246E152AB0C8147706CDD64D1EBF52CA30F823D0C2BAE97D7B614861079BB3B1380778C08E149D26A622F1F5EFA9668DF892795389F06D73EC9CB26590D73DEB0C8E9260E8315C6EF5B8BD20460CA49A628F6693BF6CBC82891E59D8A615737AC7414DC74E03AEE722F2E9CFBD0BBBFF53D00E10633E8822BAE53A63A16738CDD410E203AC0B4A7A1E9B24F902E3260E957CBB904926868E538266075B29F77FF9114EFAE2049FCAD401548D1023161195EB897EFAD77B7649A7ABF5FC113EF9B62FB0D6CE0546916A903DA6EE983937176C6698582170203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E041604148FF04B7FA82E4524AE4D50FA639A8BDEE2DD1BBC300D06092A864886F70D01010B050003820101004B40DBC050AAFEC80CEFF796544549BB96000941ACB3138686280733CA6BE674B9BA002DAEA40AD3F5F1F10F8ABF73674A83C7447B78E0AF6E6C6F03298E333945C38EE4B9576CAAFC1296EC53C62DE4246CB99463FBDC536867563E83B8CF3521C3C968FECEDAC253AACC908AE9F05D468C95DD7A58281A2F1DDECD0037418FED446DD75328977EF367041E15D78A96B4D3DE4C27A44C1B737376F41799C21F7A0EE32D08AD0A1C2CFF3CAB550E0F917E36EBC35749BEE12E2D7C608BC3415113239DCEF7326B9401A899E72C331F3A3B25D28640CE3B2C8678C9612F14BAEEDB556FDF84EE05094DBD28D872CED36250651EEB92978331D9B3B5CA47583F5F
1244
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
SessionHash
591D099AE9C00DC64CDFFE7566029F6E87CAA32359F4FA8BFF7AD87C5D60B66F
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress
C:\Windows\Installer\124cb8.ipi
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\124cb9.rbs
30739171
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\124cb9.rbsLow
992758384
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C14E2
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C5600
166F59DC4C5A5F446AAACEDD192C04CE
02:\Software\Nico Mak Computing\File Association Helper\Enabled
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1412
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WZMSG.EXE
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C14D1
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WZEAY32.DLL
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1460
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WZSEPE32.EXE
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1470
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WZ32.DLL
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1410
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WINZIP32.EXE
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1441
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WZSHLEX1.DLL
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1420
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WZCAB3.DLL
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1443
166F59DC4C5A5F446AAACEDD192C04CE
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C14B3
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WZIMGV32.DLL
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1433
166F59DC4C5A5F446AAACEDD192C04CE
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1492
166F59DC4C5A5F446AAACEDD192C04CE
02:\SOFTWARE\Nico Mak Computing\WinZip\
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1482
166F59DC4C5A5F446AAACEDD192C04CE
00:\WinZip\
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C14A3
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WZGDIP32.DLL
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1493
166F59DC4C5A5F446AAACEDD192C04CE
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C26F2
166F59DC4C5A5F446AAACEDD192C04CE
02:\SOFTWARE\Nico Mak Computing\WinZip\caution\ErrDelEncrytCaution
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1464
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WzPreviewer32.exe
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C26D2
166F59DC4C5A5F446AAACEDD192C04CE
00:\.wjf\AppUserModelID
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C26C2
166F59DC4C5A5F446AAACEDD192C04CE
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C560E
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\UnInstall32.exe
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1465
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WzProdAdv.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1454
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\wzwipe32.exe
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C14E3
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WZWIA32.DLL
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1431
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WZVINFO32.DLL
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C14C0
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WZZPMAIL32.DLL
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2632
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\LdrtBurn32.DLL
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2642
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\LudfWrtr32.DLL
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1481
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WZQKPICK32.EXE
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1404
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\7ZXA32.DLL
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C14F1
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WZFILVW32.OCX
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C14E1
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WZFLDVW32.OCX
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2652
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WzWFR32.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1405
166F59DC4C5A5F446AAACEDD192C04CE
01:\SOFTWARE\Nico Mak Computing\WinZip\WinZip\
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C6403
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\ULCDRDrv32.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1414
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\0100WZ.wzconfig
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1434
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\LDCdBldr32.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1444
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\VirtCDRDrv32.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1422
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WZCKTREE32.DLL
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1445
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WzBanner.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C5621
166F59DC4C5A5F446AAACEDD192C04CE
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C26E2
166F59DC4C5A5F446AAACEDD192C04CE
02:\SOFTWARE\Nico Mak Computing\WinZip\wzshlext\MenuCfgTable
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C5601
166F59DC4C5A5F446AAACEDD192C04CE
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C5611
166F59DC4C5A5F446AAACEDD192C04CE
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1455
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WzExpForSPExtension.exe
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1403
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C14F2
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C14B1
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WZSHLSTB.DLL
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1466
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\MYDSKTOP.WJF
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1446
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\MYDOCS.WJF
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1486
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\USRCOMBO.WJF
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1476
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\MYFAVS.WJF
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1456
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\MYE-MAIL.WJF
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1406
166F59DC4C5A5F446AAACEDD192C04CE
02:\SOFTWARE\Nico Mak Computing\WinZip\Langs\1033
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C561E
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\UnInstall32.exe.mui
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1426
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\LIBDOCS.WJF
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1416
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\LIBALL.WJF
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C14E7
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\wzfilvw32.ocx.mui
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C14F7
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\wzfldvw32.ocx.mui
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1408
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\wzsepe32.exe.mui
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1407
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\winzip32.exe.mui
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1436
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\LIBPICS.WJF
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C14C7
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\WzPreviewer32.exe.mui
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1487
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\wzcab64.dll.mui
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1467
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\wzshlx64.dll.mui
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C14B7
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\wzcab3.dll.mui
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1477
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\wzshlex1.dll.mui
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1428
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\wz32.dll.mui
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1458
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\WzWFR32.dll.mui
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C14D7
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\WzCkTree32.dll.mui
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C14A7
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\wzqkpick32.exe.mui
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1417
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\WzWia32.dll.mui
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1438
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\wzzpmail32.dll.mui
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1418
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\wzwipe32.exe.mui
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1448
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\SMProvider32.dll.mui
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1427
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\wzimgv32.dll.mui
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C56DC
166F59DC4C5A5F446AAACEDD192C04CE
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C562C
166F59DC4C5A5F446AAACEDD192C04CE
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C564C
166F59DC4C5A5F446AAACEDD192C04CE
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C565C
166F59DC4C5A5F446AAACEDD192C04CE
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C567C
166F59DC4C5A5F446AAACEDD192C04CE
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C568C
166F59DC4C5A5F446AAACEDD192C04CE
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C569C
166F59DC4C5A5F446AAACEDD192C04CE
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C56BC
166F59DC4C5A5F446AAACEDD192C04CE
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C56AC
166F59DC4C5A5F446AAACEDD192C04CE
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C561C
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\WinZipExpressForOffice.resources.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2644
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\CloudStorageService.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C4605
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WzWXFd2p32.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C560A
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WXFD2P.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1440
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WzPreloader.exe
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2634
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\CloudStoragePicker.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2673
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Aspose.Words.xml
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C56F8
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\FTPService.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C4696
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WZWXFlf32.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2628
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WzWXFFTP32.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2663
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Aspose.Words.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C26A5
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\LocalService.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2653
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Aspose.Slides.xml
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C26A7
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WzWXFmfire32.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2606
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\MediaFireService.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2643
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Aspose.Slides.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1450
166F59DC4C5A5F446AAACEDD192C04CE
02:\SOFTWARE\Nico Mak Computing\WinZip\WinZip\RunPreLoader
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2633
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Aspose.Pdf.xml
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C14A5
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WzDlg32.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2623
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Aspose.Pdf.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2665
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WebAuthBroker.exe
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C26F6
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WebAuthBroker32.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2625
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\GoogleDriveService.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2613
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Aspose.Cells.xml
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2603
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Aspose.Cells.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2677
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WzWXFssync32.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2647
166F59DC4C5A5F446AAACEDD192C04CE
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2607
166F59DC4C5A5F446AAACEDD192C04CE
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2655
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\SugarSyncService.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2645
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\SkyDriveService.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2635
166F59DC4C5A5F446AAACEDD192C04CE
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2605
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\DropboxService.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2624
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\CloudMeService.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2614
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\BoxService.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2604
166F59DC4C5A5F446AAACEDD192C04CE
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C14B5
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WzSensor32.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C4625
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WzWXFivrs32.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2687
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WzWXFcldme32.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C4686
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WzWXFyhm32.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C4624
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WzWXFwmrk32.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2654
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\CloudStorageService.DesktopExtension.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C4676
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WzWXFxmpp32.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C4666
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WZWXFln32.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C4656
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WZWXFll32.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C4646
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WZWXFlc32.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2612
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\SMProvider32.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C3600
166F59DC4C5A5F446AAACEDD192C04CE
02:\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION\winzip32.exe
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C560B
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WXFWMRK.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2656
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\System.CoreEx.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2676
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\System.Threading.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2667
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WzWXFdbox32.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2637
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WzWXFgdrv32.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2617
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WzWXFskyd32.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C14A4
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WzWXFlkin32.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2615
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\ZipShareService.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2666
166F59DC4C5A5F446AAACEDD192C04CE
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2686
166F59DC4C5A5F446AAACEDD192C04CE
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2627
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WzWXFzshare32.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C4636
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WzWXFgtalk32.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2657
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WzWXFbox32.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1495
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WzZEC32.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2602
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WzWXFfbsm32.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2638
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WzWpfCldPicker32.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C4616
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\IMService.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C4606
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\IMClient.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C0571
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WzWXFtt32.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C5610
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\FAH\FAH.exe
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C46FF
166F59DC4C5A5F446AAACEDD192C04CE
01:\Software\Nico Mak Computing\File Association Helper\Enabled
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C5650
166F59DC4C5A5F446AAACEDD192C04CE
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C5660
166F59DC4C5A5F446AAACEDD192C04CE
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C5630
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\FAH\FAHDll32.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C5640
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\FAH\FAHWindow32.exe
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C5620
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\FAH\FAHConsole.exe
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C566C
166F59DC4C5A5F446AAACEDD192C04CE
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C56CC
166F59DC4C5A5F446AAACEDD192C04CE
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C563C
166F59DC4C5A5F446AAACEDD192C04CE
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C6401
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Utils\WzSysScan\xmllite.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C6402
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Utils\WzSysScan\lang.lng
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C6491
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSSPrivacyProtector.exe
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C64D1
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Utils\WzSysScan\KillWINZIPSSProcesses.exe
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C6490
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Utils\WzSysScan\Microsoft.VC90.ATL.manifest
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C6472
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Utils\WzSysScan\MFC90ESP.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C6460
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Utils\WzSysScan\privprotector.ini
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C6422
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSSSystemCleaner.exe
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C64C1
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Utils\WzSysScan\msvcp90.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C6441
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Utils\WzSysScan\wzpsssys.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C6411
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Utils\WzSysScan\MFC90DEU.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C6420
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Utils\WzSysScan\regclean.ini
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C6452
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSSHelper.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C6471
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Utils\WzSysScan\msvcr90.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C6451
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Utils\WzSysScan\mfc90u.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C6440
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Utils\WzSysScan\MFC90ITA.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C64B1
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Utils\WzSysScan\MFC90FRA.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C6410
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Utils\WzSysScan\client.ini
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C6470
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Utils\WzSysScan\Microsoft.VC90.MFC.manifest
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C6431
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Utils\WzSysScan\MFC90JPN.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C64A0
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Utils\WzSysScan\sysclean.ini
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C6492
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Utils\WzSysScan\aso.ini
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C64E0
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Utils\WzSysScan\atl90.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C6450
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Utils\WzSysScan\asores.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C6482
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Utils\WzSysScan\sqlite3.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C64B0
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Utils\WzSysScan\Microsoft.VC90.CRT.manifest
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C64E1
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Utils\WzSysScan\MFC90ENU.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C6400
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Utils\WzSysScan\MFC90KOR.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C64A1
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Utils\WzSysScan\Microsoft.VC90.MFCLOC.manifest
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C6412
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Utils\WzSysScan\regopt.ini
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C6421
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSSRegistryOptimizer.exe
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C6462
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Utils\WzSysScan\MFC90CHS.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C6432
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Utils\WzSysScan\asohtm.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C6442
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Utils\WzSysScan\MFC90CHT.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C6480
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Utils\WzSysScan\MFC90ESN.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C64C0
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSS.exe
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C64F0
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSSRegClean.exe
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1485
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Utils\WzSysScan\
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C5609
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\FTPService.resources.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1459
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\IMClient.resources.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C147A
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\MediaFireService.resources.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C14B9
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\CloudMeService.resources.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1478
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\WzWXFivrs32.dll.mui
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C145A
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\SkyDriveService.resources.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C144A
166F59DC4C5A5F446AAACEDD192C04CE
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C143A
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\GoogleDriveService.resources.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C142A
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\DropboxService.resources.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C14E9
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\SugarSyncService.resources.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C141A
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\BoxService.resources.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C14A9
166F59DC4C5A5F446AAACEDD192C04CE
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C561B
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\WXFWMRK.resources.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C561A
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\WXFD2P.resources.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1468
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\WzWXFd2p32.dll.mui
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C1498
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\WzWXFwmrk32.dll.mui
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C14D9
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\ZipShareService.resources.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446AAACEDD192C14C9
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\en-US\CloudStoragePicker.resources.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C2692
166F59DC4C5A5F446AAACEDD192C04CE
01:\SOFTWARE\Microsoft\Office\14.0\Office\Preferences\MaximumAttachmentSize
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C56CD
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Office.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C56BD
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Microsoft.Vbe.Interop.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C56AD
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Microsoft.Office.Interop.Word.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C569D
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Microsoft.Office.Interop.PowerPoint.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C568D
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Microsoft.Office.Interop.Excel.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C567D
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\Extensibility.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C566D
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\adxregistrator.exe
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C565D
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\adxloader64.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C564D
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\adxloader.dll.manifest
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C563D
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\adxloader.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C562D
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\AddinExpress.OL.2005.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C561D
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\AddinExpress.MSO.2005.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C26B2
166F59DC4C5A5F446AAACEDD192C04CE
02:\SOFTWARE\Nico Mak Computing\WinZip Express for Photos\
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C26A2
166F59DC4C5A5F446AAACEDD192C04CE
02:\SOFTWARE\Nico Mak Computing\WinZip Express for Explorer\
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\166F59DC4C5A5F446ABACEDD192C560C
166F59DC4C5A5F446AAACEDD192C04CE
C:\Program Files\WinZip\WinZipExpressForOffice.dll
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinZip\
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\WinZip\en-US\
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\WinZip\
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\WinZip\Utils\WzSysScan\
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\WinZip\Utils\
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\WinZip\FAH\
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip
AppUserModelID
WinZipComputing.WinZip32
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C871F46C-FABA-44BC-824D-B8659667E871}
IUtilities
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{60EFEAB1-5E2E-4746-AF0B-2B3F9CA43056}\TypeLib
Version
6.1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{60EFEAB1-5E2E-4746-AF0B-2B3F9CA43056}\TypeLib
{4CD0F855-1E73-474D-A687-400BA2EDD929}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.wzmul
AppUserModelID
WinZipComputing.WinZip32
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WzExpForSPExtension\DefaultIcon
C:\Program Files\WinZip\WzExpForSPExtension.exe
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5FB751EA-1020-46F8-9B86-A1EFA302F16C}
ITreeNode
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.ZipX
AppUserModelID
WinZipComputing.WinZip32
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0647568F-0A42-4001-B474-F6CCC3F6D949}
IFIVDataObject
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EF2CB645-3609-4924-96D0-1284BA71E5BD}\ProxyStubClsid
{00020420-0000-0000-C000-000000000046}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7A01A84C-34E2-4F70-8A67-C6D5BF656A27}\TypeLib
{95A42CAD-E237-4363-BDE9-FFB9E7AED9C8}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7A01A84C-34E2-4F70-8A67-C6D5BF656A27}\TypeLib
Version
6.1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{14E07557-F381-4F68-BBF0-F1F0338EC36A}\TypeLib
{95A42CAD-E237-4363-BDE9-FFB9E7AED9C8}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{14E07557-F381-4F68-BBF0-F1F0338EC36A}\TypeLib
Version
6.1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{416CADDD-071A-4260-B690-94ABA6AD6BBD}
IShellContextMenu
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{60EFEAB1-5E2E-4746-AF0B-2B3F9CA43056}
IFOVDataObject
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{978726F6-DA31-44E6-8C73-299C5CE7367A}\TypeLib
Version
6.1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{978726F6-DA31-44E6-8C73-299C5CE7367A}\TypeLib
{4CD0F855-1E73-474D-A687-400BA2EDD929}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{ECBAAB1C-E9FF-497E-92AD-6D3102C87CF1}
IShellMenuItem
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\WinZip
{E0D79304-84BE-11CE-9641-444553540000}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{60EFEAB1-5E2E-4746-AF0B-2B3F9CA43056}\ProxyStubClsid
{00020420-0000-0000-C000-000000000046}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{43DDC4B2-B21C-466C-AA02-69BD70C26C6D}\ProxyStubClsid32
{00020420-0000-0000-C000-000000000046}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C871F46C-FABA-44BC-824D-B8659667E871}\ProxyStubClsid32
{00020420-0000-0000-C000-000000000046}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.RegFile
AppUserModelID
WinZipComputing.WinZip32
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C871F46C-FABA-44BC-824D-B8659667E871}\TypeLib
Version
6.1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C871F46C-FABA-44BC-824D-B8659667E871}\TypeLib
{95A42CAD-E237-4363-BDE9-FFB9E7AED9C8}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{416CADDD-071A-4260-B690-94ABA6AD6BBD}\ProxyStubClsid
{00020420-0000-0000-C000-000000000046}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{416CADDD-071A-4260-B690-94ABA6AD6BBD}\ProxyStubClsid32
{00020420-0000-0000-C000-000000000046}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.JobFile
AppUserModelID
WinZipComputing.WinZip32
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{ECBAAB1C-E9FF-497E-92AD-6D3102C87CF1}\TypeLib
Version
6.1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{ECBAAB1C-E9FF-497E-92AD-6D3102C87CF1}\TypeLib
{4CD0F855-1E73-474D-A687-400BA2EDD929}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\ShellEx\DragDropHandlers\WinZip
{E0D79305-84BE-11CE-9641-444553540000}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A3018BEB-498D-4F55-8045-16B9272843E5}\ProxyStubClsid32
{00020420-0000-0000-C000-000000000046}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{43DDC4B2-B21C-466C-AA02-69BD70C26C6D}\ProxyStubClsid
{00020420-0000-0000-C000-000000000046}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zip
AppUserModelID
WinZipComputing.WinZip32
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{ECBAAB1C-E9FF-497E-92AD-6D3102C87CF1}\ProxyStubClsid32
{00020420-0000-0000-C000-000000000046}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{416CADDD-071A-4260-B690-94ABA6AD6BBD}\TypeLib
{95A42CAD-E237-4363-BDE9-FFB9E7AED9C8}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{416CADDD-071A-4260-B690-94ABA6AD6BBD}\TypeLib
Version
6.1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{007E4B91-9456-4B04-90FD-DC9BF9E44B65}\ProxyStubClsid
{00020420-0000-0000-C000-000000000046}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.wjf
AppUserModelID
WinZipComputing.WinZip32
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A3018BEB-498D-4F55-8045-16B9272843E5}
_DFileView
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{14E07557-F381-4F68-BBF0-F1F0338EC36A}
_DFileViewEvents
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5FB751EA-1020-46F8-9B86-A1EFA302F16C}\ProxyStubClsid
{00020420-0000-0000-C000-000000000046}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WzExpForSPExtension\shell\open
open
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0647568F-0A42-4001-B474-F6CCC3F6D949}\ProxyStubClsid
{00020420-0000-0000-C000-000000000046}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{60EFEAB1-5E2E-4746-AF0B-2B3F9CA43056}\ProxyStubClsid32
{00020420-0000-0000-C000-000000000046}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{43DDC4B2-B21C-466C-AA02-69BD70C26C6D}
_DFolderViewEvents
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{978726F6-DA31-44E6-8C73-299C5CE7367A}\ProxyStubClsid
{00020420-0000-0000-C000-000000000046}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0647568F-0A42-4001-B474-F6CCC3F6D949}\TypeLib
{95A42CAD-E237-4363-BDE9-FFB9E7AED9C8}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0647568F-0A42-4001-B474-F6CCC3F6D949}\TypeLib
Version
6.1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5FB751EA-1020-46F8-9B86-A1EFA302F16C}\TypeLib
Version
6.1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5FB751EA-1020-46F8-9B86-A1EFA302F16C}\TypeLib
{4CD0F855-1E73-474D-A687-400BA2EDD929}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A3018BEB-498D-4F55-8045-16B9272843E5}\ProxyStubClsid
{00020420-0000-0000-C000-000000000046}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{007E4B91-9456-4B04-90FD-DC9BF9E44B65}
IShellMenuItem
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EF2CB645-3609-4924-96D0-1284BA71E5BD}\TypeLib
{4CD0F855-1E73-474D-A687-400BA2EDD929}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EF2CB645-3609-4924-96D0-1284BA71E5BD}\TypeLib
Version
6.1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.wzcloud
WinZip
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.wzcloud
AppUserModelID
WinZipComputing.WinZip32
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{007E4B91-9456-4B04-90FD-DC9BF9E44B65}\TypeLib
Version
6.1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{007E4B91-9456-4B04-90FD-DC9BF9E44B65}\TypeLib
{95A42CAD-E237-4363-BDE9-FFB9E7AED9C8}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C871F46C-FABA-44BC-824D-B8659667E871}\ProxyStubClsid
{00020420-0000-0000-C000-000000000046}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{978726F6-DA31-44E6-8C73-299C5CE7367A}
_DFolderView
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zipx
AppUserModelID
WinZipComputing.WinZip32
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7A01A84C-34E2-4F70-8A67-C6D5BF656A27}
IListItem
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WzExpForSPExtension\shell
open
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\DragDropHandlers\WinZip
{E0D79305-84BE-11CE-9641-444553540000}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{43DDC4B2-B21C-466C-AA02-69BD70C26C6D}\TypeLib
Version
6.1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{43DDC4B2-B21C-466C-AA02-69BD70C26C6D}\TypeLib
{4CD0F855-1E73-474D-A687-400BA2EDD929}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\DragDropHandlers\WinZip
{E0D79305-84BE-11CE-9641-444553540000}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{ECBAAB1C-E9FF-497E-92AD-6D3102C87CF1}\ProxyStubClsid
{00020420-0000-0000-C000-000000000046}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\ShellEx\ContextMenuHandlers\WinZip
{E0D79304-84BE-11CE-9641-444553540000}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A3018BEB-498D-4F55-8045-16B9272843E5}\TypeLib
Version
6.1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A3018BEB-498D-4F55-8045-16B9272843E5}\TypeLib
{95A42CAD-E237-4363-BDE9-FFB9E7AED9C8}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7A01A84C-34E2-4F70-8A67-C6D5BF656A27}\ProxyStubClsid
{00020420-0000-0000-C000-000000000046}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WzExpForSPExtension
URL Protocol
C:\Program Files\WinZip\WzExpForSPExtension.exe
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WzExpForSPExtension
URL:WzExpForSPExtension Protocol
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{14E07557-F381-4F68-BBF0-F1F0338EC36A}\ProxyStubClsid32
{00020420-0000-0000-C000-000000000046}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WzExpForSPExtension\shell\open\command
"C:\Program Files\WinZip\WzExpForSPExtension.exe" "%1"
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EF2CB645-3609-4924-96D0-1284BA71E5BD}
IShellContextMenu
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{EF2CB645-3609-4924-96D0-1284BA71E5BD}\ProxyStubClsid32
{00020420-0000-0000-C000-000000000046}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{007E4B91-9456-4B04-90FD-DC9BF9E44B65}\ProxyStubClsid32
{00020420-0000-0000-C000-000000000046}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{978726F6-DA31-44E6-8C73-299C5CE7367A}\ProxyStubClsid32
{00020420-0000-0000-C000-000000000046}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5FB751EA-1020-46F8-9B86-A1EFA302F16C}\ProxyStubClsid32
{00020420-0000-0000-C000-000000000046}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{14E07557-F381-4F68-BBF0-F1F0338EC36A}\ProxyStubClsid
{00020420-0000-0000-C000-000000000046}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7A01A84C-34E2-4F70-8A67-C6D5BF656A27}\ProxyStubClsid32
{00020420-0000-0000-C000-000000000046}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{0647568F-0A42-4001-B474-F6CCC3F6D949}\ProxyStubClsid32
{00020420-0000-0000-C000-000000000046}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\WinZip
{E0D79304-84BE-11CE-9641-444553540000}
1244
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office\14.0\Office\Preferences
MaximumAttachmentSize
0
1244
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Nico Mak Computing\File Association Helper
Enabled
1
1244
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office\15.0\Office\Preferences
MaximumAttachmentSize
0
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\Langs
1033
en-US
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\Langs
InstalledUILangID
1033
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip Express\Office\Langs
1033
en-US
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip Express\Office\Langs
InstalledUILangID
1033
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WinZip
RunPreLoader
20
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WinZip
Adjustable
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WinZip
CheckOutIconOnly
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WinZip
DefaultCompressionMethod
0
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WinZip
AltDrag
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WinZip
Setup
0
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WinZip
ProductCode
{CD95F661-A5C4-44F5-A6AA-ECDD91C240EC}
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WinZip
ExtractSkipOlder
0
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WinZip
newinstance
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WinZip
SpanDefault
0
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WinZip
ExeBits
32
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WinZip
ReuseWindows
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WinZip
IBS
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WinZip
Version
19.5.11532
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WinZip
DialogSplitFactor
2
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WinZip
AnimatedBusy
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WinZip
AlwaysOnTop
0
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WinZip
Wizard
0
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.BHX
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
shlExt
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.ISO
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.7Z
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.UUE
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.HQX
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.XXE
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.TBZ2
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.BZ
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.BZ2
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.IMG
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.TGZ
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.Z
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.RAR
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.TAZ
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.TAR
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.CAB
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.GZ
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.LZH
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
assoc
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.LHA
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.TZ
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.UU
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.MIM
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.ZIPX
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.B64
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.ZIP
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.TBZ
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\winzip32.exe
C:\Program Files\WinZip\winzip32.exe
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\UpdateCheck
AutoMode
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\UpdateCheck
CurrentPeriod
7
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\UpdateCheck
AskFirst
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\UpdateCheck
Period
7
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\wzshlext
MenuCfgTable
22222222222222222222
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\wzshlext
ShellExtensionSubMenu
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\wzshlext
CommentCheckRemovable
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\wzshlext
CommentCheckFixed
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\wzshlext
CabCheckFixed
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\wzshlext
CabCheckOther
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\wzshlext
CommentCheckOther
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\wzshlext
CabCheckRemovable
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\wzshlext
DropDialogExplorer
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\wzshlext
AddToFolder
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\wzshlext
MenuBitmaps
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\wzshlext
DropDialogWinzip
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\ListView
ListFormat1
4
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\ListView
GridLines
0
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\ListView
PathMode
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\ListView
FullRowSelect
0
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\Programs
zip2exe
C:\Program Files\WinZip\WZSEPE32.EXE
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\Programs
viewer
C:\Windows\NOTEPAD.EXE
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\Programs
vviewer
C:\Windows\NOTEPAD.EXE
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\Programs
zip2exe_init
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
{E0D79305-84BE-11CE-9641-444553540000}
WinZip
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
{E0D79306-84BE-11CE-9641-444553540000}
WinZip
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
{E0D79307-84BE-11CE-9641-444553540000}
WinZip
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
{E0D79304-84BE-11CE-9641-444553540000}
WinZip
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\caution
ErrDelEncrytCaution
0
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WinIni
win32_version
6.3-19.5
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WinIni
Setup
0
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WXF\WzWXFbox\Default
WritableRootFolder
\
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WXF\WzWXFbox\Default
MaxUploadSizeMB
0
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CD95F661-A5C4-44F5-A6AA-ECDD91C240EC}
UninstallLocation
C:\Program Files\WinZip\
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CD95F661-A5C4-44F5-A6AA-ECDD91C240EC}
DisplayIcon
C:\Program Files\WinZip\WINZIP32.EXE,0
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WXF\WzWXFssync\Default
MaxUploadSizeMB
0
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WXF\WzWXFssync\Default
WritableRootFolder
\
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip Express\Office
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip
x-at
nkln
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\File Association Helper
Enabled
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WXF\WzWXFzshare\Default
WritableRootFolder
\
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WXF\WzWXFzshare\Default
MaxUploadSizeMB
0
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip Express\Explorer
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WXF\WzWXFcldme\Default
MaxUploadSizeMB
0
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WXF\WzWXFcldme\Default
WritableRootFolder
\
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WXF\WzWXFskyd\Default
MaxUploadSizeMB
0
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WXF\WzWXFskyd\Default
WritableRootFolder
\
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip Express for Explorer
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip Express for Photos
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WXF\WzWXFgdrv\Default
WritableRootFolder
\
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WXF\WzWXFgdrv\Default
MaxUploadSizeMB
0
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\winzip.exe
C:\Program Files\WinZip\winzip32.exe
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\Statistics
Collect
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WXF\WzWXFdbox\Default
MaxUploadSizeMB
0
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WXF\WzWXFdbox\Default
WritableRootFolder
\
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip Express for Office
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WXF\WzWXFmfire\Default
MaxUploadSizeMB
0
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WXF\WzWXFmfire\Default
WritableRootFolder
\
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\Policies
DisableFAH
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WXF
DefaultMaxParallel
2
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\Statistics
UsageCollectLock
0
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\Splitter
Enabled
1
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION
winzip32.exe
8000
1244
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip Express\Photos
1892
MsiExec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D4C7D00B-96C6-4C4B-AFA4-91DB66FF7AC5}\1.0
FAHDll 1.0 Library
1892
MsiExec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D4C7D00B-96C6-4C4B-AFA4-91DB66FF7AC5}\1.0\FLAGS
0
1892
MsiExec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D4C7D00B-96C6-4C4B-AFA4-91DB66FF7AC5}\1.0\0\win32
C:\Program Files\File Association Helper\FAHDll.dll
1892
MsiExec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D4C7D00B-96C6-4C4B-AFA4-91DB66FF7AC5}\1.0\HELPDIR
C:\Program Files\File Association Helper
1892
MsiExec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AB5F401F-E166-43B0-A845-ACB9B0B238BD}
IContextMenuExt
1892
MsiExec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AB5F401F-E166-43B0-A845-ACB9B0B238BD}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
1892
MsiExec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AB5F401F-E166-43B0-A845-ACB9B0B238BD}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
1892
MsiExec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AB5F401F-E166-43B0-A845-ACB9B0B238BD}\TypeLib
{D4C7D00B-96C6-4C4B-AFA4-91DB66FF7AC5}
1892
MsiExec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AB5F401F-E166-43B0-A845-ACB9B0B238BD}\TypeLib
Version
1.0
1892
MsiExec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D5CF14A2-B3CA-49DC-8E3E-0BB233B26D09}
ContextMenuExt
1892
MsiExec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D5CF14A2-B3CA-49DC-8E3E-0BB233B26D09}\InprocServer32
C:\Program Files\File Association Helper\FAHDll.dll
1892
MsiExec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D5CF14A2-B3CA-49DC-8E3E-0BB233B26D09}\InprocServer32
ThreadingModel
Apartment
1892
MsiExec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D5CF14A2-B3CA-49DC-8E3E-0BB233B26D09}\TypeLib
{D4C7D00B-96C6-4C4B-AFA4-91DB66FF7AC5}
1892
MsiExec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\FileAssociationHelper
{D5CF14A2-B3CA-49DC-8E3E-0BB233B26D09}
840
svchost.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\DeviceClasses
_IndexName_
FileIdIndex-{e1a82db4-a9f0-11e7-b142-806e6f6e6963}
840
svchost.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CoDeviceInstallers
_ObjectId_
BD00000000000000
840
svchost.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class
CurrentLru
6F03000000000000
840
svchost.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CoDeviceInstallers
_ObjectLru_
6F03000000000000
840
svchost.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CoDeviceInstallers
_FileId_
9043000000000500
840
svchost.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CoDeviceInstallers
_Usn_
7823BA0000000000
840
svchost.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CoDeviceInstallers
_UsnJournalId_
CAF752A8FD3DD301
840
svchost.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CoDeviceInstallers
AeFileID
300030003000300037003900370065006500350033006600340039003700330062003400330035003900330032006300350037003300660030003400310033006100660064003500390037003700620061006600300065000000
840
svchost.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\CoDeviceInstallers
AeProgramID
300030003000300064006100330039006100330065006500350065003600620034006200300064003300320035003500620066006500660039003500360030003100380039003000610066006400380030003700300039000000
840
svchost.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1302019708-1500728564-335382590-1000
RefCount
3
840
svchost.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1302019708-1500728564-335382590-1000
RefCount
2
840
svchost.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class
CurrentLru
7203000000000000
840
svchost.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanServer\ShareProviders
ObjectId
BE00000000000000
840
svchost.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanServer\ShareProviders
ObjectLru
7203000000000000
840
svchost.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanServer\ShareProviders
BE
BE00000000000000
840
svchost.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class
CurrentLru
7503000000000000
840
svchost.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanServer\ShareProviders
AeFileID
300030003000300064006300660036006300630037006100620066003700620063003300610034006600340039006600390065003600630032006500650063003300340030003500330035003200340062003800350034000000
840
svchost.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanServer\ShareProviders
AeProgramID
300030003000300064006100330039006100330065006500350065003600620034006200300064003300320035003500620066006500660039003500360030003100380039003000610066006400380030003700300039000000
840
svchost.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class
CurrentLru
7803000000000000
840
svchost.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class
CurrentLru
7B03000000000000
2824
FAHWindow.exe
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\File Association Helper
version
1.2.225.65451
2824
FAHWindow.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2824
FAHWindow.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3928
FAHConsole.exe
delete key
HKEY_CURRENT_USER\Software\Nico Mak Computing\File Association Helper
3928
FAHConsole.exe
delete key
HKEY_CURRENT_USER\Software\Nico Mak Computing
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\Common\Email\Share
WinZip
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.wzmul
WinZip.RegFile
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.RegFile
WinZip Multi-User Registration File
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.RegFile\DefaultIcon
C:\Program Files\WinZip\WinZip32.exe,0
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.RegFile\shell\open
Register &WinZip
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.RegFile\shell\open\command
C:\Program Files\WinZip\WinZip32.exe "%1"
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.RegFile\shell
open
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WinIni
win32_version
6.3-19.5
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip
x-at
nkln
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\fm
.BHX
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\fm
shlExt
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\fm
.ISO
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\fm
.7Z
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\fm
.UUE
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\fm
.HQX
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\fm
.XXE
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\fm
.TBZ2
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\fm
.BZ
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\fm
.BZ2
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\fm
.IMG
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\fm
.TGZ
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\fm
.Z
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\fm
.RAR
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\fm
.TAZ
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\fm
.TAR
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\fm
.CAB
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\fm
.GZ
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\fm
.LZH
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\fm
assoc
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\fm
.LHA
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\fm
.TZ
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\fm
.UU
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\fm
.MIM
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\fm
.ZIPX
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\fm
.B64
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\fm
.ZIP
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\fm
.TBZ
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\programs
zip2exe
C:\Program Files\WinZip\WZSEPE32.EXE
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\programs
viewer
C:\Windows\NOTEPAD.EXE
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\programs
vviewer
C:\Windows\NOTEPAD.EXE
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\programs
zip2exe_init
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WinZip
RunPreLoader
20
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WinZip
Adjustable
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WinZip
CheckOutIconOnly
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WinZip
DefaultCompressionMethod
0
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WinZip
AltDrag
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WinZip
Setup
0
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WinZip
ProductCode
{CD95F661-A5C4-44F5-A6AA-ECDD91C240EC}
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WinZip
ExtractSkipOlder
0
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WinZip
newinstance
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WinZip
SpanDefault
0
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WinZip
ExeBits
32
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WinZip
ReuseWindows
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WinZip
IBS
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WinZip
Version
19.5.11532
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WinZip
DialogSplitFactor
2
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WinZip
AnimatedBusy
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WinZip
AlwaysOnTop
0
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WinZip
Wizard
0
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WinIni
Setup
0
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\wzshlext
MenuCfgTable
22222222222222222222
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\wzshlext
ShellExtensionSubMenu
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\wzshlext
CommentCheckRemovable
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\wzshlext
CommentCheckFixed
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\wzshlext
CabCheckFixed
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\wzshlext
CabCheckOther
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\wzshlext
CommentCheckOther
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\wzshlext
CabCheckRemovable
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\wzshlext
DropDialogExplorer
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\wzshlext
AddToFolder
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\wzshlext
MenuBitmaps
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\wzshlext
DropDialogWinzip
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\ListView
ListFormat1
4
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\ListView
GridLines
0
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\ListView
PathMode
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\ListView
FullRowSelect
0
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\Splitter
Enabled
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\UpdateCheck
AutoMode
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\UpdateCheck
CurrentPeriod
7
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\UpdateCheck
AskFirst
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\UpdateCheck
Period
7
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\Statistics
Collect
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\Statistics
UsageCollectLock
0
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WXF
DefaultMaxParallel
2
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WXF\WzWXFbox\Default
WritableRootFolder
\
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WXF\WzWXFbox\Default
MaxUploadSizeMB
0
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WXF\WzWXFcldme\Default
MaxUploadSizeMB
0
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WXF\WzWXFcldme\Default
WritableRootFolder
\
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WXF\WzWXFdbox\Default
MaxUploadSizeMB
0
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WXF\WzWXFdbox\Default
WritableRootFolder
\
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WXF\WzWXFgdrv\Default
WritableRootFolder
\
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WXF\WzWXFgdrv\Default
MaxUploadSizeMB
0
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WXF\WzWXFmfire\Default
MaxUploadSizeMB
0
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WXF\WzWXFmfire\Default
WritableRootFolder
\
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WXF\WzWXFskyd\Default
MaxUploadSizeMB
0
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WXF\WzWXFskyd\Default
WritableRootFolder
\
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WXF\WzWXFssync\Default
MaxUploadSizeMB
0
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WXF\WzWXFssync\Default
WritableRootFolder
\
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WXF\WzWXFzshare\Default
WritableRootFolder
\
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WXF\WzWXFzshare\Default
MaxUploadSizeMB
0
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\WinZip Computing
WinZip Computing
Please look in the Nico Mak Computing section for WinZip keys, values, and settings.
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\Splitter
ActionPane
1,1,1,1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\Splitter
FilesPane
1,1,1,1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\ListView
ListFormat1
4,4,4,4
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\ListView
PathMode
1,1,1,1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\Splitter
ListPane
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\Splitter
TreePane
0
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\Splitter
Movable
0
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\Splitter
StatusBar
0
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.ZIP
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.ZIPX
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.LHA
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.LZH
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.TAR
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.TAZ
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.TGZ
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.TZ
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.GZ
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.Z
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\fm
.XZ
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.XZ
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\fm
.TXZ
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.TXZ
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.CAB
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.UU
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.UUE
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.XXE
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.B64
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.HQX
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.BHX
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.MIM
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.BZ2
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.BZ
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.TBZ
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.TBZ2
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.RAR
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.7Z
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\fm
.ISO
0
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.ISO
0
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\fm
.IMG
0
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.IMG
0
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\fm
.VHD
0
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.VHD
0
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\fm
.VMDK
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
.VMDK
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\UpdateCheck
NoUpdateChecking
0
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\UpdateCheck
NoUpdateChecking
0
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinZip
DisplayName
WinZip
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinZip
UninstallString
"C:\Program Files\WinZip\WINZIP32.EXE" /uninstall
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinZip
DisplayIcon
C:\PROGRA~1\WINZIP\WINZIP32.EXE,0
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinZip
InstallLocation
C:\Program Files\WinZip\
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinZip
Publisher
WinZip Computing, S.L.
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinZip
VersionMajor
19
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinZip
VersionMinor
5
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinZip
DisplayVersion
19.5 (11532) - 32-bit
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinZip
HelpLink
HTTP://www.winzip.com/wzgate.cgi?lang=EN&x-at=nkln&url=www.winzip.com/xsupport.htm&param=mah%3D229ACC476490FFE566A9442A3CE4371D31740ADD%26wzbits%3D32%26osbits%3D32
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinZip
URLInfoAbout
HTTP://www.winzip.com/wzgate.cgi?lang=EN&x-at=nkln&url=www.winzip.com/&param=ver%3D19.5.11532.0%26vid%3Dnkln%26x-at%3Dnkln%26mah%3D229ACC476490FFE566A9442A3CE4371D31740ADD%26wzbits%3D32%26osbits%3D32
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinZip
URLUpdateInfo
HTTP://www.winzip.com/wzgate.cgi?lang=EN&x-at=nkln&url=www.winzip.com/&param=ver%3D19.5.11532.0%26vid%3Dnkln%26x-at%3Dnkln%26mah%3D229ACC476490FFE566A9442A3CE4371D31740ADD%26wzbits%3D32%26osbits%3D32
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WinZip
DefaultTypeZipX
0
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WinZip
RecycleBin
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WinZip
RecycleBin
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\Programs
zip2exe_init
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\programs
zip2exe
C:\Program Files\WinZip\wzsepe32.exe
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\Programs
zip2exe
C:\Program Files\WinZip\wzsepe32.exe
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\caution
ErrDelEncrytCaution
0
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\caution
ErrDelEncrytCaution
0
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\caution
ErrDelFileCaution
0
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\caution
ErrDelFileCaution
0
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\wzshlext
MenuCfgTable
22222222222222222222
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WinZip
UseMapi
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WinZip
DialogSplitFactor
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WinZip
DialogSplitFactor
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WinZip
DialogSplitIndex
0
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WinZip
DialogSplitIndex
0
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WinZip
UserSplitSize
1048576
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WinZip
UserSplitSize
1048576
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WinZip
EmailOption
1
860
WINZIP32.EXE
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000000-0000-0000-0000-000000000000}
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WinIni
win32_version
6.3-19.5
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WinZip
StoreExtendedTimestamps
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WinZip
StoreExtendedTimestamps
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\Programs
vviewer
C:\Windows\NOTEPAD.EXE
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\ListView
FullRowSelect
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\ListView
FullRowSelect
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\ListView
ThumbLoadDelay
50
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\ListView
ThumbLoadDelay
50
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\ListView
Col_Name
2,L,216,T
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\ListView
Col_Name
2,L,216,T
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\ListView
Col_Type
3,L,120,T
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\ListView
Col_Type
3,L,120,T
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\ListView
Col_Date
4,L,120,T
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\ListView
Col_Date
4,L,120,T
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\ListView
Col_Size
5,R,48,T
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\ListView
Col_Size
5,R,48,T
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\ListView
Col_Ratio
6,R,-2,T
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\ListView
Col_Ratio
6,R,-2,T
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\ListView
Col_Packed
7,R,54,T
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\ListView
Col_Packed
7,R,54,T
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\ListView
Col_CRC
8,L,-1,F
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\ListView
Col_CRC
8,L,-1,F
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\ListView
Col_Attrib
9,L,-2,F
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\ListView
Col_Attrib
9,L,-2,F
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\ListView
Col_Path
10,L,-2,F
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\ListView
Col_Path
10,L,-2,F
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\ListView
Col_Encrypt
1,L,18,T
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\ListView
Col_Encrypt
1,L,18,T
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\ListView
Col_CheckBox
0,L,30,T
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\ListView
Col_CheckBox
0,L,30,T
860
WINZIP32.EXE
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\ShellEx\DragDropHandlers\{BD472F60-27FA-11cf-B8B4-444553540000}
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
assoc
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\fm
shlExt
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\wzshlext
MenuBitmaps
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\wzshlext
ShellExtensionSubMenu
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\wzshlext
AddToFolder
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\wzshlext
CabCheckFixed
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\wzshlext
CabCheckRemovable
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\wzshlext
CabCheckOther
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\wzshlext
CommentCheckFixed
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\wzshlext
CommentCheckRemovable
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\wzshlext
CommentCheckOther
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip
WinZip File
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip\shell\open\command
"C:\Program Files\WinZip\WINZIP32.EXE" "%1"
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip\shell\print\command
"C:\Program Files\WinZip\WINZIP32.EXE" /print /ni "%1"
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip\shell\open
Open with &WinZip
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip\DefaultIcon
"C:\Program Files\WinZip\WINZIP32.EXE",2
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip
AppUserModelID
WinZipComputing.Winzip32
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zip\ShellEx\{8895B1C6-B41F-4C1C-A562-0D564250836F}
{E0D7930A-84BE-11CE-9641-444553540002}
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip\shellex\{8895B1C6-B41F-4C1C-A562-0D564250836F}
{E0D7930A-84BE-11CE-9641-444553540002}
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.ZipX
WinZip Zipx File
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.ZipX\shell\open\command
"C:\Program Files\WinZip\WINZIP32.EXE" "%1"
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.ZipX\shell\print\command
"C:\Program Files\WinZip\WINZIP32.EXE" /print /ni "%1"
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.ZipX\shell\open
Open with &WinZip
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.ZipX\DefaultIcon
"C:\Program Files\WinZip\WINZIP32.EXE",2
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.ZipX
AppUserModelID
WinZipComputing.Winzip32
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zipx\ShellEx\{8895B1C6-B41F-4C1C-A562-0D564250836F}
{E0D7930A-84BE-11CE-9641-444553540002}
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.ZipX\ShellEx\{8895B1C6-B41F-4C1C-A562-0D564250836F}
{E0D7930A-84BE-11CE-9641-444553540002}
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.wjf
WinZip.JobFile
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.JobFile
WinZip Job File
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.JobFile\DefaultIcon
"C:\Program Files\WinZip\WINZIP32.EXE",-22
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.JobFile\shell\open
Run with &WinZip
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.JobFile\shell\open\command
"C:\Program Files\WinZip\WINZIP32.EXE" /runjobfile "%1"
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.JobFile\shell\edit
&Edit with WinZip
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.JobFile\shell\edit\command
"C:\Program Files\WinZip\WINZIP32.EXE" /editjobfile "%1"
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.JobFile\shell
open
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.JobFile
AppUserModelID
WinZipComputing.Winzip32
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.RegFile\DefaultIcon
"C:\Program Files\WinZip\WINZIP32.EXE",2
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.RegFile\shell\open\command
"C:\Program Files\WinZip\WINZIP32.EXE" "%1"
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.wzconfig
WinZip.SetupConfig
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.SetupConfig
WinZip Configuration File
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.SetupConfig\DefaultIcon
"C:\Program Files\WinZip\WINZIP32.EXE",-22
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.SetupConfig\shell\open
Configure WinZip
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.SetupConfig\shell\open\command
"C:\Program Files\WinZip\WINZIP32.EXE" /loadconfig "%1"
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.SetupConfig\shell
open
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.wztheme
WinZip.Theme
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.Theme
WinZip Theme Installation File
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.Theme\DefaultIcon
"C:\Program Files\WinZip\WINZIP32.EXE",-22
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.Theme\shell\open
Install WinZip theme
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.Theme\shell\open\command
"C:\Program Files\WinZip\WINZIP32.EXE" /installtheme "%1"
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.Theme\shell
open
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
57
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\winzip.exe
C:\Program Files\WinZip\winzip32.exe
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\winzip32.exe
C:\Program Files\WinZip\winzip32.exe
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E0D79304-84BE-11CE-9641-444553540000}
WinZip
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E0D79304-84BE-11CE-9641-444553540000}\InProcServer32
C:\Program Files\WinZip\WZSHLSTB.DLL
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E0D79304-84BE-11CE-9641-444553540000}\InProcServer32
ThreadingModel
Apartment
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\WinZip
{E0D79304-84BE-11CE-9641-444553540000}
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\ShellEx\ContextMenuHandlers\WinZip
{E0D79304-84BE-11CE-9641-444553540000}
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\WinZip
{E0D79304-84BE-11CE-9641-444553540000}
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E0D79305-84BE-11CE-9641-444553540000}
WinZip
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E0D79305-84BE-11CE-9641-444553540000}\InProcServer32
C:\Program Files\WinZip\WZSHLSTB.DLL
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E0D79305-84BE-11CE-9641-444553540000}\InProcServer32
ThreadingModel
Apartment
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\DragDropHandlers\WinZip
{E0D79305-84BE-11CE-9641-444553540000}
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Drive\shellex\DragDropHandlers\WinZip
{E0D79305-84BE-11CE-9641-444553540000}
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\ShellEx\DragDropHandlers\WinZip
{E0D79305-84BE-11CE-9641-444553540000}
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E0D79306-84BE-11CE-9641-444553540000}
WinZip
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E0D79306-84BE-11CE-9641-444553540000}\InProcServer32
C:\Program Files\WinZip\WZSHLSTB.DLL
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E0D79306-84BE-11CE-9641-444553540000}\InProcServer32
ThreadingModel
Apartment
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip\shellex\DropHandler
{E0D79306-84BE-11CE-9641-444553540000}
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.ZipX\ShellEx\DropHandler
{E0D79306-84BE-11CE-9641-444553540000}
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E0D79307-84BE-11CE-9641-444553540000}
WinZip
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E0D79307-84BE-11CE-9641-444553540000}\InProcServer32
C:\Program Files\WinZip\WZSHLSTB.DLL
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E0D79307-84BE-11CE-9641-444553540000}\InProcServer32
ThreadingModel
Apartment
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zip\ShellEx\{00021500-0000-0000-c000-000000000046}
{E0D79307-84BE-11CE-9641-444553540000}
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.zipx\ShellEx\{00021500-0000-0000-c000-000000000046}
{E0D79307-84BE-11CE-9641-444553540000}
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WinZip
ExeBits
32
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WinZip
ShowTips
1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WinZip
ShowTips
1
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WinZip
LastTip
0
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WinZip
LastTip
0
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WinZip
VersionDate
5/15/2019
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WinZip
VersionDate
5/15/2019
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WinZip
Setup
0
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
58
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\WinZip\WinIni
Setup
0
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\WinZip
DefaultIcon
C:\Program Files\WinZip\wzwia32.dll,0
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\WinZip
Action
Zip from camera
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\WinZip
Provider
WinZip
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\WinZip
ProgID
WinZip.AutoplayHandler
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\WPD\Source\{EF2107D5-A52A-4243-A26B-62D4176D7603}
WinZip
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.AutoplayHandler\CLSID
{784C04A3-2E5A-4E7C-A7F7-7D97E27859AD}
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.AutoplayHandler\CurVer
WinZip.AutoplayHandler.1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WinZip.AutoplayHandler.1\CLSID
{784C04A3-2E5A-4E7C-A7F7-7D97E27859AD}
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{784C04A3-2E5A-4E7C-A7F7-7D97E27859AD}
WinZip Autoplay
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{784C04A3-2E5A-4E7C-A7F7-7D97E27859AD}\LocalServer32
C:\Program Files\WinZip\WINZIP32.EXE
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{784C04A3-2E5A-4E7C-A7F7-7D97E27859AD}\ProgID
WinZip.AutoplayHandler.1
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{784C04A3-2E5A-4E7C-A7F7-7D97E27859AD}\VersionIndependentProgID
WinZip.AutoplayHandler
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{784C04A3-2E5A-4E7C-A7F7-7D97E27859AD}
AppID
{784C04A3-2E5A-4E7C-A7F7-7D97E27859AD}
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{784C04A3-2E5A-4E7C-A7F7-7D97E27859AD}
RunAs
Interactive User
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\WINZIP32.EXE
AppID
{784C04A3-2E5A-4E7C-A7F7-7D97E27859AD}
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\Common\Email\Share
WinZip
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Nico Mak Computing\Common\Email\Services
<?xml version="1.0" encoding="UTF-8"?><mailservices default="Gmail"><mailservice name="Gmail" login="yes" encryption="tls"><smtp server="smtp.gmail.com" port="587"/><domains>gmail.com</domains></mailservice><mailservice name="Hotmail" login="yes" encryption="tls"><smtp server="smtp.live.com" port="587"/><domains>hotmail.*;live.*;msnhotmail.com</domains></mailservice><mailservice name="Yahoo!" login="yes" encryption="none"><smtp server="plus.smtp.mail.yahoo.com" port="465"/><domains>yahoo.com;sbcglobal.com</domains></mailservice><mailservice name="Outlook.com" login="yes" encryption="tls"><smtp server="smtp-mail.outlook.com" port="587"/><domains>outlook.com</domains></mailservice></mailservices>
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\Common\Email\Services
<?xml version="1.0" encoding="UTF-8"?><mailservices default="Gmail"><mailservice name="Gmail" login="yes" encryption="tls"><smtp server="smtp.gmail.com" port="587"/><domains>gmail.com</domains></mailservice><mailservice name="Hotmail" login="yes" encryption="tls"><smtp server="smtp.live.com" port="587"/><domains>hotmail.*;live.*;msnhotmail.com</domains></mailservice><mailservice name="Yahoo!" login="yes" encryption="none"><smtp server="plus.smtp.mail.yahoo.com" port="465"/><domains>yahoo.com;sbcglobal.com</domains></mailservice><mailservice name="Outlook.com" login="yes" encryption="tls"><smtp server="smtp-mail.outlook.com" port="587"/><domains>outlook.com</domains></mailservice></mailservices>
860
WINZIP32.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
59
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WinZip
RibbonState
3C7369713A637573746F6D554920786D6C6E733A7369713D22687474703A2F2F736368656D61732E6D6963726F736F66742E636F6D2F77696E646F77732F323030392F726962626F6E2F716174223E3C7369713A726962626F6E206D696E696D697A65643D2274727565223E3C7369713A71617420706F736974696F6E3D2230223E3C7369713A736861726564436F6E74726F6C733E3C7369713A636F6E74726F6C206964513D227369713A3530303030222076697369626C653D22747275652220617267756D656E743D2230222F3E3C7369713A636F6E74726F6C206964513D227369713A3439383430222076697369626C653D22747275652220617267756D656E743D2230222F3E3C7369713A636F6E74726F6C206964513D227369713A3439383635222076697369626C653D22747275652220617267756D656E743D2230222F3E3C2F7369713A736861726564436F6E74726F6C733E3C2F7369713A7161743E3C2F7369713A726962626F6E3E3C2F7369713A637573746F6D55493E0D0A
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WinZip
LastDPI
100
860
WINZIP32.EXE
write
HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\WinZip
Orientation
2

Files activity

Executable files
62
Suspicious files
12
Text files
140
Unknown types
13

Dropped files

PID
Process
Filename
Type
1256
WinZIP_v19.0_Web_Installer.exe
C:\Users\admin\AppData\Local\Temp\ish1183343\wnzpw.dll
executable
MD5: 78b37e556c96e68ad42daeb97e47a50c
SHA256: 430d0180f52f779038ecfccca2f59dd116e79a09ed9f95969d03f7b1c1aa084e
1244
msiexec.exe
C:\Program Files\WinZip\en-US\wzshlex1.dll.mui
executable
MD5: 42ff385922a87b62bb343459f3b18624
SHA256: fb5e92ba7b588cf20dba59fe388ec06ff1bcf279eeb038b30d9d7002c79e5740
1244
msiexec.exe
C:\Program Files\WinZip\WZFILVW32.OCX
executable
MD5: 6dd4465a5d0afea788babc36b82119d2
SHA256: 6aa64c857f4b4a26c0b3d6c680011c5011d2e75090786da54bab4f6650fefc65
1244
msiexec.exe
C:\Program Files\WinZip\en-US\WzWia32.dll.mui
executable
MD5: 387e53982bcfebe3f9d20d6f7f44db7e
SHA256: 3c8d283dca845b1dd520c1e26fa97830daf5589a81fadfa79d048a5ebb806b9d
1244
msiexec.exe
C:\Program Files\WinZip\WZSHLSTB.DLL
executable
MD5: af13a804b8701db3350856338d74cfcf
SHA256: 236ab6b574ddff81f3be7672f6d4766f6af2d618fa7adc85329036d3d60def9b
1244
msiexec.exe
C:\Program Files\WinZip\WZVINFO32.DLL
executable
MD5: e603fe8bd22fc0d9cffa444ae0a21122
SHA256: 2db9dfc2e6cd2f64842687b9c7cb62164aef01e9f309eb00adc55b73bdd4203c
1244
msiexec.exe
C:\Program Files\WinZip\WZCAB3.DLL
executable
MD5: deb7cfab12a2a58bad1442faba178f01
SHA256: e2484933aa81acdab719f49b2b9ac7407298118e6795402f753c19237a92ad57
1244
msiexec.exe
C:\Program Files\WinZip\en-US\wzfilvw32.ocx.mui
executable
MD5: 02f1cb5658edbb31db23c56d29e4467a
SHA256: 9c8f8d66fd54bdf6cc2044742b53ca61b4c70107a6c403dab9f3af84d941c941
1244
msiexec.exe
C:\Windows\Installer\MSIBA88.tmp
executable
MD5: 1561715dee4460a87205e5e5adcb1bdc
SHA256: 46dd4ebb8e6c3d2f9c912a348191b234395f104fdf5a08472b2b4398c5cf2336
1244
msiexec.exe
C:\Program Files\WinZip\en-US\wzwipe32.exe.mui
executable
MD5: e615306fdd61bed4aa130bba6554d97d
SHA256: 38f1af6d39caf5f9a9158b34c27433533a78ddacad4732dfb4addbaabb7ba5ee
1244
msiexec.exe
C:\Windows\Installer\MSIB9D9.tmp
executable
MD5: 7b9227c38c91ab1808c7c4d16b45c4b9
SHA256: da4f3fc374d2c544e8444897a594234d991515630e31fa9f08513ba28ff737db
1244
msiexec.exe
C:\Program Files\WinZip\en-US\WzCkTree32.dll.mui
executable
MD5: 65811bf462fa03cc32f5b3a8fd099a41
SHA256: 74e54e79e37652a6e1a8ad373b38b678f2ee0b1174c448353c4f1dc2ceb26b4f
1244
msiexec.exe
C:\Program Files\WinZip\en-US\wz32.dll.mui
executable
MD5: b5b59e39b617915762c330b0f1bcf514
SHA256: d89ef3529dfdaada92835f2776c1f6791a1946f38f761df6c1287677c244f860
1244
msiexec.exe
C:\Program Files\WinZip\WZSHLEX1.DLL
executable
MD5: a9ac9ed5d219fa909fb241bb7aee6ef4
SHA256: 9dbfd10e072a297f0e98bb860cf9004b75b342fe57a1da536a2d3422034b778e
1244
msiexec.exe
C:\Windows\Installer\MSIB793.tmp
executable
MD5: 1561715dee4460a87205e5e5adcb1bdc
SHA256: 46dd4ebb8e6c3d2f9c912a348191b234395f104fdf5a08472b2b4398c5cf2336
1244
msiexec.exe
C:\Program Files\WinZip\en-US\wzqkpick32.exe.mui
executable
MD5: a264309e4b10046bf22a1718305dfcbe
SHA256: d50778479d907230176a249dcf06a02cd1f85a4d75cac4e354261147df785c88
1244
msiexec.exe
C:\Program Files\WinZip\en-US\wzzpmail32.dll.mui
executable
MD5: 378c6cb47dd8204b52f80d3414afda34
SHA256: bdbc97e178510e2d75b20f1fd74d051e846d18d73e4e85931422ed12f6c4147e
1244
msiexec.exe
C:\Program Files\WinZip\WINZIP32.EXE
executable
MD5: 9b51c43b7e058b8f53b6f876aa832dbc
SHA256: 72a54ccbc5603f00faf0d479b74b0f977f5374c8e6561e57cacb27f0e93b637a
1244
msiexec.exe
C:\Windows\Installer\124cb5.msi
executable
MD5: a39b6fd1dd0bca99de70a9fe95a14c68
SHA256: 3f1edf0cbd18bfda1f3f4b3179141f58b3103c8b370dd7ce41a0e9cc5458391e
1244
msiexec.exe
C:\Program Files\WinZip\en-US\wzimgv32.dll.mui
executable
MD5: b027aedc6c5da18cb3570cf521367349
SHA256: ccca4c8a813fce45358024882d30854a48fe4bf5f6ed92b7c98a41bd3392e602
1244
msiexec.exe
C:\Program Files\WinZip\WzBanner.dll
executable
MD5: 40b2c6141346a48fafcb7fc35f8ac0e6
SHA256: e208cc010ae4b4c566db5b0a0ff7e3d1005caa639d50a3bf0365680db66c7129
1244
msiexec.exe
C:\Program Files\WinZip\WZ32.DLL
executable
MD5: fbe59a5fce50cf5a0ef1982965e84508
SHA256: 7e4fda27f803cc82304c59bcea2a2b9358e5e9b08bd10dceda22249293ed50c3
1244
msiexec.exe
C:\Program Files\File Association Helper\UpdateHelper.exe
executable
MD5: 116b897fe6c205acda12fcad99620fe9
SHA256: d9836b83aae815d52dd3b488d45f2241db24c7a8b659a979630eccdb117ef64e
1244
msiexec.exe
C:\Program Files\WinZip\en-US\wzshlx64.dll.mui
executable
MD5: d71a5eca4c47269f9ae219a7f408bf0d
SHA256: 01f59d637b62af8409c79413c9051e6a4ad145dd5772a0a33482490d0f1d75b2
1244
msiexec.exe
C:\Program Files\WinZip\Utils\WzSysScan\KillWINZIPSSProcesses.exe
executable
MD5: febb264a453fbc414d7333a881588822
SHA256: 6e6307057355944e937fddd410a1ad6f369f21c7526967da1c97aba147740e11
1244
msiexec.exe
C:\Program Files\WinZip\WZZPMAIL32.DLL
executable
MD5: ad093aabe461185c0360c31d5b7f05f6
SHA256: e77cbe4ad33635864191c76a6984ef683886ec412428bf2b7550da6200245876
1244
msiexec.exe
C:\Program Files\File Association Helper\FAHDll.dll
executable
MD5: 34608591ac228bf2f3e2a67e3ae9bf95
SHA256: 77c5b48603ddd78160f230e7f7710e213c587350ced4c7aa6f38cc00cd662043
1244
msiexec.exe
C:\Program Files\WinZip\en-US\wzcab64.dll.mui
executable
MD5: 4b4863801cf429275fc39875e2cf60a3
SHA256: f1fe72a785419c97942c5e56a8e92a4145c9a645362c15b69ca651352dc45f9b
1244
msiexec.exe
C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSSPrivacyProtector.exe
executable
MD5: 5b93b13f808e4b05a38a3498d9c9b6d4
SHA256: 6b4c7c4d9075b7958231bcd56c4d6e467cf2c8067ac0cdd5d8ea6de235ab3eaf
1244
msiexec.exe
C:\Program Files\WinZip\WZSEPE32.EXE
executable
MD5: 5574658aeb4c4a0da785f944bb55022b
SHA256: 757104663be2f46dd0a99c2a05dd9c3222cf87999c242d705d1c3419aaf11530
1244
msiexec.exe
C:\Program Files\File Association Helper\FAHConsole.exe
executable
MD5: addc85e83be3cb8f317ad4b27ad5b755
SHA256: c00860715774f26dd3b7f273388ffd043345368265d9fd6ed4cdad713cdc5337
1244
msiexec.exe
C:\Program Files\WinZip\en-US\wzcab3.dll.mui
executable
MD5: 85cef9192427287bfe168d4b6aa903af
SHA256: 2b4cc054ecca4669316d641859b0b45d4a5ec68216aa0a5a1412f4cdc52127b2
1244
msiexec.exe
C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSSSystemCleaner.exe
executable
MD5: a4635f5fe8bc9d86366a3153b1345c43
SHA256: 702edd1269b5d2d5c0fe5f7e9c7e3924ff0217e93bac99b4da4f1a6e50f29676
1244
msiexec.exe
C:\Program Files\WinZip\WZQKPICK32.EXE
executable
MD5: 2e0e7c552e4bae1f5f9bd360140717cd
SHA256: c8a8e144a6e0e72e46acdba1b23cb181b63e81447209952fae5e16ffc4e256bf
1244
msiexec.exe
C:\Program Files\File Association Helper\FAHWindow.exe
executable
MD5: 6253b084facce6065d13703f700b2ea1
SHA256: cd03b2dd19320695f17d010699751801c4b5faefbb232137a5db26fc2b004355
1244
msiexec.exe
C:\Program Files\WinZip\en-US\winzip32.exe.mui
executable
MD5: 6b241a5e45228554164b6f692aba67f7
SHA256: 094c9a6b775b7fb08c31e09ea9c01d599b1fe00b61fe209d73e680e7bb6eaf76
1244
msiexec.exe
C:\Program Files\WinZip\Utils\WzSysScan\msvcp90.dll
executable
MD5: 871f979d70414c900b35e56222932daf
SHA256: 91fd46d7335c9990a20f215b9f6f53bc59551420a9c99ad8110ae2f9ff7598f0
1244
msiexec.exe
C:\Program Files\WinZip\WZFLDVW32.OCX
executable
MD5: cc25881a9736331f786e3c149ab9320a
SHA256: 36b2bfc6b3cc68d99ae60bad3f567506e5b1ff6c0374820b400f4a4b07b156c7
1244
msiexec.exe
C:\Program Files\File Association Helper\FAH.exe
executable
MD5: aebd747d4bcceef6daf5a8e24e1459c4
SHA256: eb0e54fbca5f3a4868fc3b4eae8b685f0cbbc0f152239f5bfcbb42249c05f865
1244
msiexec.exe
C:\Program Files\WinZip\en-US\WzPreviewer32.exe.mui
executable
MD5: 95c9367b77914cc7cf35060c997266b1
SHA256: 665763affa59549c0f694a7b69de90890835a6999ae14b139b6f4647d40102e5
1244
msiexec.exe
C:\Program Files\WinZip\Utils\WzSysScan\wzpsssys.dll
executable
MD5: f12506ef60ca5e483edcdc4ea90cdbe2
SHA256: b7725dc2c768c931ba42243d796cbcb629334b4696c7e274c9753a9478e7e7bb
1244
msiexec.exe
C:\Program Files\WinZip\WZCKTREE32.DLL
executable
MD5: 7a19a15c003bcdfaa9b63d4fbb10ee1a
SHA256: 7ad67491b791a3d464be3cec8d68c6ae1f7822689534481c53f0d426a194d4b3
1244
msiexec.exe
C:\Windows\Installer\124cb1.msi
executable
MD5: a39b6fd1dd0bca99de70a9fe95a14c68
SHA256: 3f1edf0cbd18bfda1f3f4b3179141f58b3103c8b370dd7ce41a0e9cc5458391e
1244
msiexec.exe
C:\Program Files\WinZip\WzPreviewer32.exe
executable
MD5: 9f74d46e9786ca3fb4f48289724098c5
SHA256: 0b343513b27baf55dd7c2264a3f9fa04c7cbf5830814e39e5d84048d0b721d5f
1244
msiexec.exe
C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSSHelper.dll
executable
MD5: 29471efc62e40020408fa033531a6795
SHA256: a066c45508666a4f2922ab51a85d3a9e1f2b6dcbf47bd61669c3bf9c728a6cc3
1244
msiexec.exe
C:\Program Files\WinZip\WZMSG.EXE
executable
MD5: 496466dfaca309d98bcf74dead419b75
SHA256: 65a620a87053aee0df5d6574f4d6a02369ea39553561041aa8cd096b7acecab9
2856
WinZIP_v19.0_Web_Installer.exe
C:\Users\admin\AppData\Local\Temp\is360511915\54FE1FCB_stp\FAH32.msi
executable
MD5: a39b6fd1dd0bca99de70a9fe95a14c68
SHA256: 3f1edf0cbd18bfda1f3f4b3179141f58b3103c8b370dd7ce41a0e9cc5458391e
1244
msiexec.exe
C:\Program Files\WinZip\en-US\wzfldvw32.ocx.mui
executable
MD5: 8ac1ebbd81044703bb3398d6623d852b
SHA256: 87f69f101ecdb15fefa6d1185618404ae2c66ffed1e58bd343e5b283d633c42b
1244
msiexec.exe
C:\Program Files\WinZip\Utils\WzSysScan\msvcr90.dll
executable
MD5: 4d03ca609e68f4c90cf66515218017f8
SHA256: cf420aced0d810e1d75f6811dd986f2d9fded2fbb8d61fc9a7024520c475febb
1244
msiexec.exe
C:\Program Files\WinZip\WZEAY32.DLL
executable
MD5: b87077cdbe4748532415b3938a45249e
SHA256: 4e191fe7db52df7be3c1c195d76ebe3eb7477afcc53e5f729b6a37bb4f1b85b7
2856
WinZIP_v19.0_Web_Installer.exe
C:\Users\admin\AppData\Local\Temp\ICReinstall_WinZIP_v19.0_Web_Installer.exe
executable
MD5: f62e7667e988a9cbdbb16aefe0c1e5ba
SHA256: 4d753499dfc07886971875252cee1be36d5792fdbab679c69531df208d3b583b
1244
msiexec.exe
C:\Program Files\WinZip\WZGDIP32.DLL
executable
MD5: 7d70fb0032cfe3ccc3dd761b436df2d1
SHA256: d74661bc9af60fa0a8401c6df5703c2ed6ee87536d58ffa0175a880d89bc5e26
1244
msiexec.exe
C:\Program Files\WinZip\Utils\WzSysScan\mfc90u.dll
executable
MD5: a76104d8d9aba3670fd3cea603d70ada
SHA256: 443fd2e5fce845e3e682f6057081b8209e4b7d1f50e2938f7cfc003f2a6b1a01