General Info

File name

PADK502.swf

Full analysis
https://app.any.run/tasks/b6e00dc2-66d6-40de-94c8-0d21829f17d1
Verdict
Malicious activity
Analysis date
5/15/2019, 11:08:19
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-shockwave-flash
File info:
Macromedia Flash data (compressed), version 10
MD5

e79cf4c5c86dbc2f73bcde1278200e03

SHA1

bdaef65e1976349fc8792f1d1d6cb0c092c39612

SHA256

556d83af693316581f10690966943863dd05ca3ffefc97424bb8f087d2fb5e50

SSDEEP

384:1ENPr4gA/BtrNmp8dssbesk5mzaIWhcvYqGGQqUFcc75sIhfbJfUy5+:1ENPs/XRmSdgs+IcgYqGDqhcKiJfB+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
300 seconds
Additional time used
240 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (73.0.3683.75)
  • Google Update Helper (1.3.33.23)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 65.0.2 (x86 en-US) (65.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Application was dropped or rewritten from another process
  • FlashPlayerUpdateService.exe (PID: 2912)
  • 4D8D4B61-8366-40E4-AD80-4F50E7E2AC27 (PID: 2576)
  • FlashPlayerUpdateService.exe (PID: 1520)
  • FlashPlayerUpdateService.exe (PID: 1244)
  • gccheck_small.exe (PID: 2724)
  • flashplayer32ax_ra_install[1].exe (PID: 3456)
  • gtcheck.exe (PID: 1860)
  • gccheck_small.exe (PID: 1900)
  • flashplayer32ax_ra_install[1].exe (PID: 2820)
Loads the Task Scheduler COM API
  • FlashPlayerUpdateService.exe (PID: 1244)
  • FlashPlayerUpdateService.exe (PID: 2912)
Loads dropped or rewritten executable
  • 4D8D4B61-8366-40E4-AD80-4F50E7E2AC27 (PID: 2576)
  • iexplore.exe (PID: 3680)
Changes settings of System certificates
  • flashplayer32ax_ra_install[1].exe (PID: 3456)
Starts CMD.EXE for commands execution
  • 4D8D4B61-8366-40E4-AD80-4F50E7E2AC27 (PID: 2576)
Creates a software uninstall entry
  • 4D8D4B61-8366-40E4-AD80-4F50E7E2AC27 (PID: 2576)
Modifies the open verb of a shell class
  • 4D8D4B61-8366-40E4-AD80-4F50E7E2AC27 (PID: 2576)
Disables SEHOP
  • 4D8D4B61-8366-40E4-AD80-4F50E7E2AC27 (PID: 2576)
Starts application with an unusual extension
  • flashplayer32ax_ra_install[1].exe (PID: 3456)
Adds / modifies Windows certificates
  • flashplayer32ax_ra_install[1].exe (PID: 3456)
Removes files from Windows directory
  • 4D8D4B61-8366-40E4-AD80-4F50E7E2AC27 (PID: 2576)
Reads internet explorer settings
  • flashplayer32ax_ra_install[1].exe (PID: 2820)
Executable content was dropped or overwritten
  • 4D8D4B61-8366-40E4-AD80-4F50E7E2AC27 (PID: 2576)
  • flashplayer32ax_ra_install[1].exe (PID: 2820)
  • iexplore.exe (PID: 1088)
  • iexplore.exe (PID: 3336)
Creates files in the Windows directory
  • 4D8D4B61-8366-40E4-AD80-4F50E7E2AC27 (PID: 2576)
Application launched itself
  • flashplayer32ax_ra_install[1].exe (PID: 2820)
Creates files in the user directory
  • flashplayer32ax_ra_install[1].exe (PID: 2820)
Reads internet explorer settings
  • iexplore.exe (PID: 3680)
  • iexplore.exe (PID: 1892)
  • iexplore.exe (PID: 392)
  • iexplore.exe (PID: 1088)
Application launched itself
  • iexplore.exe (PID: 4076)
  • iexplore.exe (PID: 3336)
Reads Internet Cache Settings
  • iexplore.exe (PID: 3680)
  • iexplore.exe (PID: 1892)
  • iexplore.exe (PID: 1088)
  • iexplore.exe (PID: 392)
Creates files in the user directory
  • iexplore.exe (PID: 3680)
  • iexplore.exe (PID: 3336)
  • FlashUtil32_26_0_0_131_ActiveX.exe (PID: 1812)
  • iexplore.exe (PID: 1088)
Changes internet zones settings
  • iexplore.exe (PID: 4076)
  • iexplore.exe (PID: 3336)
Changes settings of System certificates
  • iexplore.exe (PID: 3336)
Reads settings of System Certificates
  • iexplore.exe (PID: 3336)
Adds / modifies Windows certificates
  • iexplore.exe (PID: 3336)
Dropped object may contain Bitcoin addresses
  • iexplore.exe (PID: 1088)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.swf
|   Macromedia Flash Player Compressed Movie (100%)
EXIF
Flash
FlashVersion:
10
Compressed:
true
ImageWidth:
660
ImageHeight:
390
FrameRate:
1
FrameCount:
1
Duration:
1.00 s
FlashAttributes:
ActionScript3
Composite
ImageSize:
660x390
Megapixels:
0.257

Screenshots

Processes

Total processes
66
Monitored processes
19
Malicious processes
4
Suspicious processes
0

Behavior graph

+
drop and start start drop and start drop and start drop and start drop and start drop and start iexplore.exe iexplore.exe no specs iexplore.exe flashutil32_26_0_0_131_activex.exe no specs flashplayer32ax_ra_install[1].exe flashplayer32ax_ra_install[1].exe gtcheck.exe no specs gccheck_small.exe no specs gccheck_small.exe no specs 4d8d4b61-8366-40e4-ad80-4f50e7e2ac27 flashplayerupdateservice.exe no specs flashplayerupdateservice.exe no specs flashplayerupdateservice.exe no specs cmd.exe no specs iexplore.exe explorer.exe no specs explorer.exe no specs iexplore.exe iexplore.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3336
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" C:\Users\admin\AppData\Local\Temp\PADK502.swf
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
1
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\cryptbase.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\ieui.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\url.dll
c:\windows\system32\version.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\msfeeds.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\ehstorshell.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\slc.dll
c:\windows\system32\wship6.dll
c:\windows\system32\imageres.dll
c:\windows\system32\fwpuclnt.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\naturallanguage6.dll
c:\windows\system32\nlsdata0009.dll
c:\windows\system32\nlslexicons0009.dll
c:\windows\system32\tquery.dll
c:\windows\system32\structuredquery.dll
c:\windows\system32\secur32.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\mlang.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\credssp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\wpc.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll
c:\windows\system32\actxprxy.dll
c:\windows\system32\shdocvw.dll
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\h6qnmhe9\flashplayer32ax_ra_install[1].exe
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\mpr.dll

PID
392
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3336 CREDAT:79873
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
No indicators
Parent process
iexplore.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\comdlg32.dll
c:\program files\internet explorer\ieshims.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rsaenh.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mlang.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\apphelp.dll
c:\program files\java\jre1.8.0_92\bin\ssv.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\version.dll
c:\progra~1\micros~1\office14\urlredir.dll
c:\windows\system32\secur32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\progra~1\micros~1\office14\msohev.dll
c:\program files\java\jre1.8.0_92\bin\jp2ssv.dll
c:\program files\java\jre1.8.0_92\bin\msvcr100.dll
c:\program files\java\jre1.8.0_92\bin\deploy.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\winmm.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\wdmaud.drv
c:\windows\system32\ksuser.dll
c:\windows\system32\avrt.dll
c:\windows\system32\audioses.dll
c:\windows\system32\msacm32.drv
c:\windows\system32\msacm32.dll
c:\windows\system32\midimap.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\wintrust.dll

PID
1088
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3336 CREDAT:203009
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
iexplore.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\comdlg32.dll
c:\program files\internet explorer\ieshims.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\cryptsp.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\mlang.dll
c:\windows\system32\uxtheme.dll
c:\program files\java\jre1.8.0_92\bin\ssv.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\version.dll
c:\progra~1\micros~1\office14\urlredir.dll
c:\windows\system32\secur32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\progra~1\micros~1\office14\msohev.dll
c:\program files\java\jre1.8.0_92\bin\jp2ssv.dll
c:\program files\java\jre1.8.0_92\bin\msvcr100.dll
c:\program files\java\jre1.8.0_92\bin\deploy.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\winmm.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\wdmaud.drv
c:\windows\system32\ksuser.dll
c:\windows\system32\avrt.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\wship6.dll
c:\windows\system32\audioses.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\msacm32.drv
c:\windows\system32\msacm32.dll
c:\windows\system32\midimap.dll
c:\windows\system32\jscript.dll
c:\windows\system32\iepeers.dll
c:\windows\system32\winspool.drv
c:\windows\system32\imgutil.dll
c:\windows\system32\pngfilt.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\feclient.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\credssp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\p2pcollab.dll
c:\windows\system32\qagentrt.dll
c:\windows\system32\fveui.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\macromed\flash\flash32_26_0_0_131.ocx
c:\windows\system32\dsound.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\mscms.dll
c:\windows\system32\dinput8.dll
c:\windows\system32\t2embed.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\dxtrans.dll
c:\windows\system32\atl.dll
c:\windows\system32\ddrawex.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\windows\system32\dxtmsft.dll
c:\windows\system32\wpc.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll

PID
1812
CMD
C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exe -Embedding
Path
C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Adobe Systems Incorporated
Description
Adobe® Flash® Player Installer/Uninstaller 26.0 r0
Version
26,0,0,131
Modules
Image
c:\windows\system32\macromed\flash\flashutil32_26_0_0_131_activex.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\secur32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\version.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\riched20.dll
c:\windows\system32\cryptui.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\ws2help.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\psapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\macromed\flash\flashutil32_26_0_0_131_activex.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\dinput8.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mlang.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll

PID
2820
CMD
"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\flashplayer32ax_ra_install[1].exe"
Path
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\flashplayer32ax_ra_install[1].exe
Indicators
Parent process
iexplore.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Adobe Inc
Description
Adobe Download Manager
Version
2.0.0.363s
Modules
Image
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\h6qnmhe9\flashplayer32ax_ra_install[1].exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\system32\winmm.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\mpr.dll
c:\windows\system32\oledlg.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\msi.dll
c:\windows\system32\webio.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\winspool.drv
c:\windows\system32\samcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleaccrc.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\psapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\propsys.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mlang.dll
c:\windows\system32\jscript.dll
c:\windows\system32\dxtrans.dll
c:\windows\system32\atl.dll
c:\windows\system32\ddrawex.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\dxtmsft.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\credssp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\schannel.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\userenv.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\iepeers.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\imgutil.dll
c:\windows\system32\pngfilt.dll
c:\windows\system32\samlib.dll
c:\users\admin\appdata\local\adobe\950ee43e-8831-4f28-9d72-2ad52b1a19c1\gccheck_small.exe
c:\windows\system32\imagehlp.dll
c:\program files\internet explorer\iexplore.exe

PID
3456
CMD
"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\flashplayer32ax_ra_install[1].exe" --pipename={54D7EBDD-3DEA-477B-B1B1-56F424721303} --pid=2820
Path
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\flashplayer32ax_ra_install[1].exe
Indicators
Parent process
flashplayer32ax_ra_install[1].exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Adobe Inc
Description
Adobe Download Manager
Version
2.0.0.363s
Modules
Image
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\h6qnmhe9\flashplayer32ax_ra_install[1].exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\system32\winmm.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\mpr.dll
c:\windows\system32\oledlg.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\msi.dll
c:\windows\system32\webio.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\winspool.drv
c:\windows\system32\samcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleaccrc.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\psapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\adobe\950ee43e-8831-4f28-9d72-2ad52b1a19c1\gtcheck.exe
c:\users\admin\appdata\local\adobe\950ee43e-8831-4f28-9d72-2ad52b1a19c1\50b9a6d2-e1ba-4023-808d-1abce0bff518\4d8d4b61-8366-40e4-ad80-4f50e7e2ac27

PID
1860
CMD
"C:\Users\admin\AppData\Local\Adobe\950EE43E-8831-4F28-9D72-2AD52B1A19C1\gtcheck.exe"
Path
C:\Users\admin\AppData\Local\Adobe\950EE43E-8831-4F28-9D72-2AD52B1A19C1\gtcheck.exe
Indicators
No indicators
Parent process
flashplayer32ax_ra_install[1].exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\adobe\950ee43e-8831-4f28-9d72-2ad52b1a19c1\gtcheck.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll

PID
2724
CMD
"C:\Users\admin\AppData\Local\Adobe\950EE43E-8831-4F28-9D72-2AD52B1A19C1\gccheck_small.exe" -chromeEligibilityTest -shellMode:standard
Path
C:\Users\admin\AppData\Local\Adobe\950EE43E-8831-4F28-9D72-2AD52B1A19C1\gccheck_small.exe
Indicators
No indicators
Parent process
flashplayer32ax_ra_install[1].exe
User
admin
Integrity Level
MEDIUM
Exit code
2
Version:
Company
Google Inc.
Description
Google Chrome Pre-Install
Version
1.0
Modules
Image
c:\users\admin\appdata\local\adobe\950ee43e-8831-4f28-9d72-2ad52b1a19c1\gccheck_small.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\version.dll
c:\windows\system32\winmm.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
1900
CMD
"C:\Users\admin\AppData\Local\Adobe\950EE43E-8831-4F28-9D72-2AD52B1A19C1\gccheck_small.exe" -canOfferReactivation -shellMode:standard -brandCode:AFRC
Path
C:\Users\admin\AppData\Local\Adobe\950EE43E-8831-4F28-9D72-2AD52B1A19C1\gccheck_small.exe
Indicators
No indicators
Parent process
flashplayer32ax_ra_install[1].exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome Pre-Install
Version
1.0
Modules
Image
c:\users\admin\appdata\local\adobe\950ee43e-8831-4f28-9d72-2ad52b1a19c1\gccheck_small.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\version.dll
c:\windows\system32\winmm.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
2576
CMD
"C:\Users\admin\AppData\Local\Adobe\950EE43E-8831-4F28-9D72-2AD52B1A19C1\50B9A6D2-E1BA-4023-808D-1ABCE0BFF518\4D8D4B61-8366-40E4-AD80-4F50E7E2AC27" -install -iv 8 -au 1
Path
C:\Users\admin\AppData\Local\Adobe\950EE43E-8831-4F28-9D72-2AD52B1A19C1\50B9A6D2-E1BA-4023-808D-1ABCE0BFF518\4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
Indicators
Parent process
flashplayer32ax_ra_install[1].exe
User
admin
Integrity Level
HIGH
Exit code
3
Version:
Company
Adobe
Description
Adobe® Flash® Player Installer/Uninstaller 32.0 r0
Version
32,0,0,192
Modules
Image
c:\users\admin\appdata\local\adobe\950ee43e-8831-4f28-9d72-2ad52b1a19c1\50b9a6d2-e1ba-4023-808d-1abce0bff518\4d8d4b61-8366-40e4-ad80-4f50e7e2ac27
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\secur32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\version.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\riched20.dll
c:\windows\system32\cryptui.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\ws2help.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\psapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\macromed\temp\{3b8771b9-6dd8-4112-8307-d8ef977dc37a}\fpb.tmp
c:\windows\system32\macromed\temp\{ce000d88-e414-437b-9963-06c32ec899d0}\fpb.tmp
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\dinput8.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\macromed\flash\flash32_26_0_0_131.ocx
c:\windows\system32\winmm.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\dsound.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\mscms.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\macromed\flash\flashutil32_32_0_0_192_activex.exe
c:\windows\system32\macromed\flash\flash32_32_0_0_192.ocx
c:\windows\system32\sspicli.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\macromed\flash\flashplayerupdateservice.exe
c:\windows\system32\propsys.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\mssprxy.dll

PID
2912
CMD
C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe -uninstall
Path
C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Indicators
No indicators
Parent process
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Adobe
Description
Adobe® Flash® Player Update Service 32.0 r0
Version
32,0,0,192
Modules
Image
c:\windows\system32\macromed\flash\flashplayerupdateservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\webio.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\sspicli.dll

PID
1244
CMD
C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe -uninstall
Path
C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Indicators
No indicators
Parent process
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Adobe
Description
Adobe® Flash® Player Update Service 32.0 r0
Version
32,0,0,192
Modules
Image
c:\windows\system32\macromed\flash\flashplayerupdateservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\sspicli.dll

PID
1520
CMD
C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe -setNotifyAutoUpdate
Path
C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Indicators
No indicators
Parent process
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Adobe
Description
Adobe® Flash® Player Update Service 32.0 r0
Version
32,0,0,192
Modules
Image
c:\windows\system32\macromed\flash\flashplayerupdateservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\webio.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll

PID
764
CMD
"C:\Windows\system32\cmd.exe" /c del "C:\Users\admin\AppData\Local\Adobe\950EE43E-8831-4F28-9D72-2AD52B1A19C1\50B9A6D2-E1BA-4023-808D-1ABCE0BFF518\4D8D4B61-8366-40E4-AD80-4F50E7E2AC27" >> NUL
Path
C:\Windows\system32\cmd.exe
Indicators
No indicators
Parent process
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
3680
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3336 CREDAT:137477
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
iexplore.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\comdlg32.dll
c:\program files\internet explorer\ieshims.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\cryptsp.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\version.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\wship6.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mlang.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\fwpuclnt.dll
c:\program files\java\jre1.8.0_92\bin\ssv.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\progra~1\micros~1\office14\urlredir.dll
c:\windows\system32\secur32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\progra~1\micros~1\office14\msohev.dll
c:\program files\java\jre1.8.0_92\bin\jp2ssv.dll
c:\program files\java\jre1.8.0_92\bin\msvcr100.dll
c:\program files\java\jre1.8.0_92\bin\deploy.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\sxs.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\credssp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\p2pcollab.dll
c:\windows\system32\qagentrt.dll
c:\windows\system32\fveui.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\iepeers.dll
c:\windows\system32\winspool.drv
c:\windows\system32\jscript.dll
c:\windows\system32\macromed\flash\flash32_32_0_0_192.ocx
c:\windows\system32\winmm.dll
c:\windows\system32\dsound.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\mscms.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\dinput8.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\t2embed.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\imgutil.dll
c:\windows\system32\pngfilt.dll
c:\windows\system32\dxtrans.dll
c:\windows\system32\atl.dll
c:\windows\system32\ddrawex.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\windows\system32\dxtmsft.dll

PID
2844
CMD
explorer.exe
Path
C:\Windows\explorer.exe
Indicators
No indicators
Parent process
flashplayer32ax_ra_install[1].exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Explorer
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\slc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\propsys.dll

PID
2908
CMD
"C:\Windows\explorer.exe"
Path
C:\Windows\explorer.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
1
Version:
Company
Microsoft Corporation
Description
Windows Explorer
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\slc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\actxprxy.dll

PID
4076
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" -nohome
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\cryptbase.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\ieui.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\clbcatq.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\url.dll
c:\windows\system32\version.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\propsys.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\msfeeds.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\mlang.dll

PID
1892
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:4076 CREDAT:71937
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
No indicators
Parent process
iexplore.exe
User
admin
Integrity Level
LOW
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\comdlg32.dll
c:\program files\internet explorer\ieshims.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rsaenh.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mlang.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\apphelp.dll
c:\program files\java\jre1.8.0_92\bin\ssv.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\version.dll
c:\progra~1\micros~1\office14\urlredir.dll
c:\windows\system32\secur32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\progra~1\micros~1\office14\msohev.dll
c:\program files\java\jre1.8.0_92\bin\jp2ssv.dll
c:\program files\java\jre1.8.0_92\bin\msvcr100.dll
c:\program files\java\jre1.8.0_92\bin\deploy.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\sxs.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\iepeers.dll
c:\windows\system32\winspool.drv
c:\windows\system32\msimtf.dll
c:\windows\system32\jscript.dll
c:\windows\system32\imgutil.dll
c:\windows\system32\pngfilt.dll
c:\windows\system32\msimg32.dll

Registry activity

Total events
2710
Read events
2067
Write events
491
Delete events
152

Modification events

PID
Process
Operation
Key
Name
Value
392
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Type
3
392
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Count
1
392
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Time
E307050003000F000900080027009702
392
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
LoadTime
23
392
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Type
3
392
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Count
1
392
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Time
E307050003000F00090008002700C502
392
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
LoadTime
477
392
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Type
3
392
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Count
1
392
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Time
E307050003000F00090008002800A300
392
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
LoadTime
61
392
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
392
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
392
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019051520190516
CachePath
%USERPROFILE%\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019051520190516
392
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019051520190516
CachePrefix
:2019051520190516:
392
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019051520190516
CacheLimit
8192
392
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019051520190516
CacheOptions
11
392
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019051520190516
CacheRepair
0
392
iexplore.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019032320190324
392
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
392
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000072000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MacromediaFlashPaper.MacromediaFlashPaper\shell\open\command
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MacromediaFlashPaper.MacromediaFlashPaper\shell\open
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MacromediaFlashPaper.MacromediaFlashPaper\shell
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MacromediaFlashPaper.MacromediaFlashPaper\DefaultIcon
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{57A0E746-3863-4D20-A811-950C84F1DB9B}\1.1\0\win32
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{57A0E746-3863-4D20-A811-950C84F1DB9B}\1.1\0
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{57A0E746-3863-4D20-A811-950C84F1DB9B}\1.1\HELPDIR
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{57A0E746-3863-4D20-A811-950C84F1DB9B}\1.1\FLAGS
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{57A0E746-3863-4D20-A811-950C84F1DB9B}\1.1
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{57A0E746-3863-4D20-A811-950C84F1DB9B}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{57A0E747-3863-4D20-A811-950C84F1DB9B}\TypeLib
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{57A0E747-3863-4D20-A811-950C84F1DB9B}\ProxyStubClsid32
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{57A0E747-3863-4D20-A811-950C84F1DB9B}\ProxyStubClsid
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{57A0E747-3863-4D20-A811-950C84F1DB9B}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{307F64C0-621D-4D56-BBC6-91EFC13CE40D}\TypeLib
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{307F64C0-621D-4D56-BBC6-91EFC13CE40D}\ProxyStubClsid32
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{307F64C0-621D-4D56-BBC6-91EFC13CE40D}\ProxyStubClsid
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{307F64C0-621D-4D56-BBC6-91EFC13CE40D}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MacromediaFlashPaper.MacromediaFlashPaper\CLSID
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MacromediaFlashPaper.MacromediaFlashPaper
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FlashFactory.FlashFactory.1\CLSID
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FlashFactory.FlashFactory.1
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.1\CLSID
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.1
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FlashFactory.FlashFactory\CLSID
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FlashFactory.FlashFactory\CurVer
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FlashFactory.FlashFactory
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.3\CLSID
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.3
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.4\CLSID
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.4
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.5\CLSID
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.5
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.6\CLSID
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.6
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.7\CLSID
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.7
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.8\CLSID
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.8
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.9\CLSID
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.9
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.10\CLSID
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.10
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.11\CLSID
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.11
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.12\CLSID
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.12
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.13\CLSID
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.13
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.14\CLSID
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.14
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.15\CLSID
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.15
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.16\CLSID
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.16
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.17\CLSID
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.17
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.18\CLSID
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.18
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.19\CLSID
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.19
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.20\CLSID
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.20
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.21\CLSID
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.21
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.22\CLSID
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.22
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.23\CLSID
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.23
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.24\CLSID
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.24
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.25\CLSID
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.25
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.26\CLSID
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.26
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash\CLSID
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash\CurVer
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Programmable
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Control
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus\1
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\EnableFullPage\.spl
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\EnableFullPage\.swf
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\EnableFullPage\.mfp
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\EnableFullPage
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Implemented Categories\{31CAF6E4-D6AA-4090-A050-A5AC8972E9EF}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Implemented Categories\{59FB2056-D625-48D0-A944-1A85B5AB2640}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Implemented Categories
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Programmable
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Control
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.spl
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.mfp
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{D27CDB70-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\NavigatorPluginsList\Shockwave Flash
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0\0\win32
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0\0
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0\HELPDIR
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0\FLAGS
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D27CDB6C-AE6D-11CF-96B8-444553540000}\TypeLib
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D27CDB6C-AE6D-11CF-96B8-444553540000}\ProxyStubClsid32
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D27CDB6C-AE6D-11CF-96B8-444553540000}\ProxyStubClsid
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D27CDB6C-AE6D-11CF-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D27CDB6D-AE6D-11CF-96B8-444553540000}\TypeLib
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D27CDB6D-AE6D-11CF-96B8-444553540000}\ProxyStubClsid32
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D27CDB6D-AE6D-11CF-96B8-444553540000}\ProxyStubClsid
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D27CDB6D-AE6D-11CF-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{86230738-D762-4C50-A2DE-A753E5B1686F}\TypeLib
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{86230738-D762-4C50-A2DE-A753E5B1686F}\ProxyStubClsid32
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{86230738-D762-4C50-A2DE-A753E5B1686F}\ProxyStubClsid
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{86230738-D762-4C50-A2DE-A753E5B1686F}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0\HELPDIR
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0\FLAGS
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0\0\win32
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0\0
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FAF199D2-BFA7-4394-A4DE-044A08E59B32}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager
AllowProtectedRenames
1
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager
PendingFileRenameOperations
\??\C:\Windows\system32\Macromed\Flash\Flash32_26_0_0_131.ocx
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashUtil32_26_0_0_131_ActiveX.exe
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}
FlashBroker
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32
C:\Windows\system32\Macromed\Flash\FlashUtil32_32_0_0_192_ActiveX.exe
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib
{FAB3E735-69C7-453B-A446-B6823C6DF1C9}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}
LocalizedString
@C:\Windows\system32\Macromed\Flash\FlashUtil32_32_0_0_192_ActiveX.exe,-101
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation
Enabled
1
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}
IFlashBroker6
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib
{FAB3E735-69C7-453B-A446-B6823C6DF1C9}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib
Version
1.0
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0
FlashBroker
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0\FLAGS
0
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0\HELPDIR
C:\Windows\system32\Macromed\Flash\FlashUtil32_32_0_0_192_ActiveX.exe
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0\0\win32
C:\Windows\system32\Macromed\Flash\FlashUtil32_32_0_0_192_ActiveX.exe
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FAF199D2-BFA7-4394-A4DE-044A08E59B32}
Policy
3
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FAF199D2-BFA7-4394-A4DE-044A08E59B32}
AppPath
C:\Windows\system32\Macromed\Flash
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FAF199D2-BFA7-4394-A4DE-044A08E59B32}
AppName
FlashUtil32_32_0_0_192_ActiveX.exe
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\FlashPlayer\SafeVersions
6.0
4294967295
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\FlashPlayer\SafeVersions
7.0
4294967295
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\FlashPlayer\SafeVersions
8.0
4294967295
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\FlashPlayer\SafeVersions
9.0
4294967295
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\FlashPlayer\SafeVersions
10.0
4294967295
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\FlashPlayer\SafeVersions
11.0
4294967295
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\FlashPlayer\SafeVersions
12.0
4294967295
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\FlashPlayer\SafeVersions
13.0
4294967295
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\FlashPlayer\SafeVersions
14.0
4294967295
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\FlashPlayer\SafeVersions
15.0
4294967295
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\FlashPlayer\SafeVersions
16.0
4294967295
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\FlashPlayer\SafeVersions
17.0
4294967295
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\FlashPlayer\SafeVersions
18.0
4294967295
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\FlashPlayer\SafeVersions
19.0
4294967295
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\FlashPlayer\SafeVersions
20.0
4294967295
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\FlashPlayer\SafeVersions
21.0
4294967295
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\FlashPlayer\SafeVersions
22.0
4294967295
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\FlashPlayer\SafeVersions
23.0
4294967295
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\FlashPlayer\SafeVersions
24.0
4294967295
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\FlashPlayer\SafeVersions
25.0
4294967295
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\FlashPlayer\SafeVersions
26.0
4294967295
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\FlashPlayer\SafeVersions
27.0
4294967295
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\FlashPlayer\SafeVersions
28.0
4294967295
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\FlashPlayer\SafeVersions
29.0
4294967295
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\FlashPlayer\SafeVersions
30.0
4294967295
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\FlashPlayer\SafeVersions
31.0
4294967295
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\FlashPlayer\SafeVersions
32.0
192
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MacromediaFlashPaper.MacromediaFlashPaper
Macromedia Flash Paper
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MacromediaFlashPaper.MacromediaFlashPaper\CLSID
{D27CDB6E-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FlashFactory.FlashFactory.1
Macromedia Flash Factory Object
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FlashFactory.FlashFactory.1\CLSID
{D27CDB70-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.1
Shockwave Flash Object
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.1\CLSID
{D27CDB6E-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FlashFactory.FlashFactory
Macromedia Flash Factory Object
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FlashFactory.FlashFactory\CLSID
{D27CDB70-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FlashFactory.FlashFactory\CurVer
FlashFactory.FlashFactory.1
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.3
Shockwave Flash Object
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.3\CLSID
{D27CDB6E-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.4
Shockwave Flash Object
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.4\CLSID
{D27CDB6E-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.5
Shockwave Flash Object
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.5\CLSID
{D27CDB6E-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.6
Shockwave Flash Object
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.6\CLSID
{D27CDB6E-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.7
Shockwave Flash Object
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.7\CLSID
{D27CDB6E-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.8
Shockwave Flash Object
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.8\CLSID
{D27CDB6E-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.9
Shockwave Flash Object
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.9\CLSID
{D27CDB6E-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.10
Shockwave Flash Object
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.10\CLSID
{D27CDB6E-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.11
Shockwave Flash Object
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.11\CLSID
{D27CDB6E-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.12
Shockwave Flash Object
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.12\CLSID
{D27CDB6E-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.13
Shockwave Flash Object
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.13\CLSID
{D27CDB6E-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.14
Shockwave Flash Object
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.14\CLSID
{D27CDB6E-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.15
Shockwave Flash Object
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.15\CLSID
{D27CDB6E-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.16
Shockwave Flash Object
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.16\CLSID
{D27CDB6E-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.17
Shockwave Flash Object
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.17\CLSID
{D27CDB6E-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.18
Shockwave Flash Object
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.18\CLSID
{D27CDB6E-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.19
Shockwave Flash Object
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.19\CLSID
{D27CDB6E-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.20
Shockwave Flash Object
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.20\CLSID
{D27CDB6E-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.21
Shockwave Flash Object
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.21\CLSID
{D27CDB6E-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.22
Shockwave Flash Object
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.22\CLSID
{D27CDB6E-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.23
Shockwave Flash Object
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.23\CLSID
{D27CDB6E-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.24
Shockwave Flash Object
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.24\CLSID
{D27CDB6E-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.25
Shockwave Flash Object
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.25\CLSID
{D27CDB6E-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.26
Shockwave Flash Object
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.26\CLSID
{D27CDB6E-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.27
Shockwave Flash Object
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.27\CLSID
{D27CDB6E-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.28
Shockwave Flash Object
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.28\CLSID
{D27CDB6E-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.29
Shockwave Flash Object
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.29\CLSID
{D27CDB6E-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.30
Shockwave Flash Object
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.30\CLSID
{D27CDB6E-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.31
Shockwave Flash Object
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.31\CLSID
{D27CDB6E-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.32
Shockwave Flash Object
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash.32\CLSID
{D27CDB6E-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash
Shockwave Flash Object
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash\CLSID
{D27CDB6E-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ShockwaveFlash.ShockwaveFlash\CurVer
ShockwaveFlash.ShockwaveFlash.32
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}
Shockwave Flash Object
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID
ShockwaveFlash.ShockwaveFlash.32
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID
ShockwaveFlash.ShockwaveFlash
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32
C:\Windows\system32\Macromed\Flash\Flash32_32_0_0_192.ocx
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32
ThreadingModel
Apartment
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32
C:\Windows\system32\Macromed\Flash\Flash32_32_0_0_192.ocx, 1
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus
0
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus\1
131473
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib
{D27CDB6B-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version
1.0
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}
Macromedia Flash Factory Object
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID
FlashFactory.FlashFactory.1
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID
FlashFactory.FlashFactory
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32
C:\Windows\system32\Macromed\Flash\Flash32_32_0_0_192.ocx
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32
ThreadingModel
Apartment
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32
C:\Windows\system32\Macromed\Flash\Flash32_32_0_0_192.ocx, 1
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib
{D27CDB6B-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version
1.0
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.spl
ShockwaveFlash.ShockwaveFlash
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.spl
Content Type
application/futuresplash
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.swf
ShockwaveFlash.ShockwaveFlash
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.swf
Content Type
application/x-shockwave-flash
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.mfp
MacromediaFlashPaper.MacromediaFlashPaper
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.mfp
Content Type
application/x-shockwave-flash
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.sol
Content Type
text/plain
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.sor
Content Type
text/plain
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/futuresplash
Extension
.spl
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/futuresplash
CLSID
{D27CDB6E-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-shockwave-flash
Extension
.swf
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-shockwave-flash
CLSID
{D27CDB6E-AE6D-11cf-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{D27CDB70-AE6D-11cf-96B8-444553540000}
Compatibility Flags
65536
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\NavigatorPluginsList\Shockwave Flash
application/futuresplash
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\NavigatorPluginsList\Shockwave Flash
application/x-shockwave-flash
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0
Shockwave Flash
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0\FLAGS
0
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0\0\win32
C:\Windows\system32\Macromed\Flash\Flash32_32_0_0_192.ocx
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0\HELPDIR
C:\Windows\system32\Macromed\Flash
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D27CDB6C-AE6D-11CF-96B8-444553540000}
IShockwaveFlash
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D27CDB6C-AE6D-11CF-96B8-444553540000}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D27CDB6C-AE6D-11CF-96B8-444553540000}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D27CDB6C-AE6D-11CF-96B8-444553540000}\TypeLib
{D27CDB6B-AE6D-11CF-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D27CDB6C-AE6D-11CF-96B8-444553540000}\TypeLib
Version
1.0
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D27CDB6D-AE6D-11CF-96B8-444553540000}
_IShockwaveFlashEvents
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D27CDB6D-AE6D-11CF-96B8-444553540000}\ProxyStubClsid
{00020420-0000-0000-C000-000000000046}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D27CDB6D-AE6D-11CF-96B8-444553540000}\ProxyStubClsid32
{00020420-0000-0000-C000-000000000046}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D27CDB6D-AE6D-11CF-96B8-444553540000}\TypeLib
{D27CDB6B-AE6D-11CF-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D27CDB6D-AE6D-11CF-96B8-444553540000}\TypeLib
Version
1.0
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{86230738-D762-4C50-A2DE-A753E5B1686F}
IFlashObject
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{86230738-D762-4C50-A2DE-A753E5B1686F}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{86230738-D762-4C50-A2DE-A753E5B1686F}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{86230738-D762-4C50-A2DE-A753E5B1686F}\TypeLib
{D27CDB6B-AE6D-11CF-96B8-444553540000}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{86230738-D762-4C50-A2DE-A753E5B1686F}\TypeLib
Version
1.0
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{57A0E746-3863-4D20-A811-950C84F1DB9B}\1.1
FlashAccessibility
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{57A0E746-3863-4D20-A811-950C84F1DB9B}\1.1\FLAGS
0
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{57A0E746-3863-4D20-A811-950C84F1DB9B}\1.1\0\win32
C:\Windows\system32\Macromed\Flash\Flash32_32_0_0_192.ocx\2
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{57A0E746-3863-4D20-A811-950C84F1DB9B}\1.1\HELPDIR
C:\Windows\system32\Macromed\Flash
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{57A0E747-3863-4D20-A811-950C84F1DB9B}
IFlashAccessibility
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{57A0E747-3863-4D20-A811-950C84F1DB9B}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{57A0E747-3863-4D20-A811-950C84F1DB9B}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{57A0E747-3863-4D20-A811-950C84F1DB9B}\TypeLib
{57A0E746-3863-4D20-A811-950C84F1DB9B}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{57A0E747-3863-4D20-A811-950C84F1DB9B}\TypeLib
Version
1.1
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{307F64C0-621D-4D56-BBC6-91EFC13CE40D}
ISimpleTextSelection
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{307F64C0-621D-4D56-BBC6-91EFC13CE40D}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{307F64C0-621D-4D56-BBC6-91EFC13CE40D}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{307F64C0-621D-4D56-BBC6-91EFC13CE40D}\TypeLib
{57A0E746-3863-4D20-A811-950C84F1DB9B}
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{307F64C0-621D-4D56-BBC6-91EFC13CE40D}\TypeLib
Version
1.1
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MacromediaFlashPaper.MacromediaFlashPaper\shell\open\command
"C:\Program Files\Internet Explorer\iexplore.exe" -nohome "%1"
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MacromediaFlashPaper.MacromediaFlashPaper\DefaultIcon
"%1"
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\FlashPlayer
CurrentVersion
32,0,0,192
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX
DisplayName
Adobe Flash Player 32 ActiveX
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX
Publisher
Adobe
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX
DisplayVersion
32.0.0.192
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX
HelpLink
http://www.adobe.com/go/flashplayer_support/
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX
NoModify
1
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX
NoRepair
1
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX
RequiresIESysFile
4.70.0.1155
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX
URLInfoAbout
http://www.adobe.com
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX
URLUpdateInfo
http://www.adobe.com/go/getflashplayer/
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX
VersionMajor
32
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX
VersionMinor
0
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX
UninstallString
C:\Windows\system32\Macromed\Flash\FlashUtil32_32_0_0_192_ActiveX.exe -maintain activex
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX
DisplayIcon
C:\Windows\system32\Macromed\Flash\FlashUtil32_32_0_0_192_ActiveX.exe
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Adobe Flash Player ActiveX
EstimatedSize
20300
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\FlashPlayerActiveX
Version
32.0.0.192
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\FlashPlayerActiveX
PlayerPath
C:\Windows\system32\Macromed\Flash\Flash32_32_0_0_192.ocx
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\FlashPlayerActiveX
UninstallerPath
C:\Windows\system32\Macromed\Flash\FlashUtil32_32_0_0_192_ActiveX.exe
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\FlashPlayerActiveX
isScriptDebugger
0
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\FlashPlayerActiveX
isESR
0
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\FlashPlayerActiveX
isMSI
0
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Macromedia\FlashPlayerActiveXReleaseType
Release
1
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\4D8D4B61-8366-40E4-AD80-4F50E7E2AC27_RASAPI32
EnableFileTracing
0
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\4D8D4B61-8366-40E4-AD80-4F50E7E2AC27_RASAPI32
EnableConsoleTracing
0
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\4D8D4B61-8366-40E4-AD80-4F50E7E2AC27_RASAPI32
FileTracingMask
4294901760
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\4D8D4B61-8366-40E4-AD80-4F50E7E2AC27_RASAPI32
ConsoleTracingMask
4294901760
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\4D8D4B61-8366-40E4-AD80-4F50E7E2AC27_RASAPI32
MaxFileSize
1048576
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\4D8D4B61-8366-40E4-AD80-4F50E7E2AC27_RASAPI32
FileDirectory
%windir%\tracing
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\4D8D4B61-8366-40E4-AD80-4F50E7E2AC27_RASMANCS
EnableFileTracing
0
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\4D8D4B61-8366-40E4-AD80-4F50E7E2AC27_RASMANCS
EnableConsoleTracing
0
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\4D8D4B61-8366-40E4-AD80-4F50E7E2AC27_RASMANCS
FileTracingMask
4294901760
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\4D8D4B61-8366-40E4-AD80-4F50E7E2AC27_RASMANCS
ConsoleTracingMask
4294901760
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\4D8D4B61-8366-40E4-AD80-4F50E7E2AC27_RASMANCS
MaxFileSize
1048576
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\4D8D4B61-8366-40E4-AD80-4F50E7E2AC27_RASMANCS
FileDirectory
%windir%\tracing
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000074000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashUtil32_32_0_0_192_ActiveX.exe
DisableExceptionChainValidation
0
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashPlayerApp.exe
DisableExceptionChainValidation
0
2576
4D8D4B61-8366-40E4-AD80-4F50E7E2AC27
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashPlayerUpdateService.exe
DisableExceptionChainValidation
0
1088
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012019051520190516
CachePath
%USERPROFILE%\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012019051520190516
1088
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012019051520190516
CachePrefix
:2019051520190516:
1088
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012019051520190516
CacheLimit
8192
1088
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012019051520190516
CacheOptions
11
1088
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012019051520190516
CacheRepair
0
1088
iexplore.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012018082820180829
1088
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\Total
24
1088
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\adobe.com
24
1088
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\Total
0
1088
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\adobe.com
0
2820
flashplayer32ax_ra_install[1].exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2820
flashplayer32ax_ra_install[1].exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2820
flashplayer32ax_ra_install[1].exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
LanguageList
en-US
2820
flashplayer32ax_ra_install[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\flashplayer32ax_ra_install[1]_RASAPI32
EnableFileTracing
0
2820
flashplayer32ax_ra_install[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\flashplayer32ax_ra_install[1]_RASAPI32
EnableConsoleTracing
0
2820
flashplayer32ax_ra_install[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\flashplayer32ax_ra_install[1]_RASAPI32
FileTracingMask
4294901760
2820
flashplayer32ax_ra_install[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\flashplayer32ax_ra_install[1]_RASAPI32
ConsoleTracingMask
4294901760
2820
flashplayer32ax_ra_install[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\flashplayer32ax_ra_install[1]_RASAPI32
MaxFileSize
1048576
2820
flashplayer32ax_ra_install[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\flashplayer32ax_ra_install[1]_RASAPI32
FileDirectory
%windir%\tracing
2820
flashplayer32ax_ra_install[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\flashplayer32ax_ra_install[1]_RASMANCS
EnableFileTracing
0
2820
flashplayer32ax_ra_install[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\flashplayer32ax_ra_install[1]_RASMANCS
EnableConsoleTracing
0
2820
flashplayer32ax_ra_install[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\flashplayer32ax_ra_install[1]_RASMANCS
FileTracingMask
4294901760
2820
flashplayer32ax_ra_install[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\flashplayer32ax_ra_install[1]_RASMANCS
ConsoleTracingMask
4294901760
2820
flashplayer32ax_ra_install[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\flashplayer32ax_ra_install[1]_RASMANCS
MaxFileSize
1048576
2820
flashplayer32ax_ra_install[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\flashplayer32ax_ra_install[1]_RASMANCS
FileDirectory
%windir%\tracing
2820
flashplayer32ax_ra_install[1].exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2820
flashplayer32ax_ra_install[1].exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000073000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3456
flashplayer32ax_ra_install[1].exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
LanguageList
en-US
3456
flashplayer32ax_ra_install[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81
Blob
0F000000010000001400000085FEF11B4F47FE3952F98301C9F98976FEFEE0CE09000000010000002A000000302806082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030353000000010000002500000030233021060B6086480186F8450107300130123010060A2B0601040182373C0101030200C01400000001000000140000007B5B45CFAFCECB7AFD31921A6AB6F346EB5748501D00000001000000100000005B3B67000EEB80022E42605B6B3B72400B000000010000000E000000740068006100770074006500000003000000010000001400000091C6D6EE3E8AC86384E548C299295C756C817B812000000001000000240400003082042030820308A0030201020210344ED55720D5EDEC49F42FCE37DB2B6D300D06092A864886F70D01010505003081A9310B300906035504061302555331153013060355040A130C7468617774652C20496E632E31283026060355040B131F43657274696669636174696F6E205365727669636573204469766973696F6E31383036060355040B132F2863292032303036207468617774652C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79311F301D06035504031316746861777465205072696D61727920526F6F74204341301E170D3036313131373030303030305A170D3336303731363233353935395A3081A9310B300906035504061302555331153013060355040A130C7468617774652C20496E632E31283026060355040B131F43657274696669636174696F6E205365727669636573204469766973696F6E31383036060355040B132F2863292032303036207468617774652C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79311F301D06035504031316746861777465205072696D61727920526F6F7420434130820122300D06092A864886F70D01010105000382010F003082010A0282010100ACA0F0FB8059D49CC7A4CF9DA159730910450C0D2C6E68F16C5B4868495937FC0B3319C2777FCC102D95341CE6EB4D09A71CD2B8C9973602B789D4245F06C0CC4494948D02626FEB5ADD118D289A5C8490107A0DBD74662F6A38A0E2D55444EB1D079F07BA6FEEE9FD4E0B29F53E84A001F19CABF81C7E89A4E8A1D871650DA3517BEEBCD222600DB95B9DDFBAFC515B0BAF98B2E92EE904E86287DE2BC8D74EC14C641EDDCF8758BA4A4FCA68071D1C9D4AC6D52F91CC7C71721CC5C067EB32FDC9925C94DA85C09BBF537D2B09F48C9D911F976A52CBDE0936A477D87B875044D53E6E2969FB3949261E09A5807B402DEBE82785C9FE61FD7EE67C971DD59D0203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E041604147B5B45CFAFCECB7AFD31921A6AB6F346EB574850300D06092A864886F70D010105050003820101007911C04BB391B6FCF0E967D40D6E45BE55E893D2CE033FEDDA25B01D57CB1E3A76A04CEC5076E864720CA4A9F1B88BD6D68784BB32E54111C077D9B3609DEB1BD5D16E4444A9A601EC55621D77B85C8E48497C9C3B5711ACAD73378E2F785C906847D96060E6FC073D222017C4F716E9C4D872F9C8737CDF162F15A93EFD6A27B6A1EB5ABA981FD5E34D640A9D13C861BAF5391C87BAB8BD7B227FF6FEAC4079E5AC106F3D8F1B79768BC437B3211884E53600EB632099B9E9FE3304BB41C8C102F94463209E81CE42D3D63F2C76D3639C59DD8FA6E10EA02E41F72E9547CFBCFD33F3F60B617E7E912B8147C22730EEA7105D378F5C392BE404F07B8D568C68
3456
flashplayer32ax_ra_install[1].exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81
Blob
190000000100000010000000DC73F9B71E16D51D26527D32B11A6A3D03000000010000001400000091C6D6EE3E8AC86384E548C299295C756C817B810B000000010000000E00000074006800610077007400650000001D00000001000000100000005B3B67000EEB80022E42605B6B3B72401400000001000000140000007B5B45CFAFCECB7AFD31921A6AB6F346EB57485053000000010000002500000030233021060B6086480186F8450107300130123010060A2B0601040182373C0101030200C009000000010000002A000000302806082B0601050507030106082B0601050507030206082B0601050507030406082B060105050703030F000000010000001400000085FEF11B4F47FE3952F98301C9F98976FEFEE0CE2000000001000000240400003082042030820308A0030201020210344ED55720D5EDEC49F42FCE37DB2B6D300D06092A864886F70D01010505003081A9310B300906035504061302555331153013060355040A130C7468617774652C20496E632E31283026060355040B131F43657274696669636174696F6E205365727669636573204469766973696F6E31383036060355040B132F2863292032303036207468617774652C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79311F301D06035504031316746861777465205072696D61727920526F6F74204341301E170D3036313131373030303030305A170D3336303731363233353935395A3081A9310B300906035504061302555331153013060355040A130C7468617774652C20496E632E31283026060355040B131F43657274696669636174696F6E205365727669636573204469766973696F6E31383036060355040B132F2863292032303036207468617774652C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79311F301D06035504031316746861777465205072696D61727920526F6F7420434130820122300D06092A864886F70D01010105000382010F003082010A0282010100ACA0F0FB8059D49CC7A4CF9DA159730910450C0D2C6E68F16C5B4868495937FC0B3319C2777FCC102D95341CE6EB4D09A71CD2B8C9973602B789D4245F06C0CC4494948D02626FEB5ADD118D289A5C8490107A0DBD74662F6A38A0E2D55444EB1D079F07BA6FEEE9FD4E0B29F53E84A001F19CABF81C7E89A4E8A1D871650DA3517BEEBCD222600DB95B9DDFBAFC515B0BAF98B2E92EE904E86287DE2BC8D74EC14C641EDDCF8758BA4A4FCA68071D1C9D4AC6D52F91CC7C71721CC5C067EB32FDC9925C94DA85C09BBF537D2B09F48C9D911F976A52CBDE0936A477D87B875044D53E6E2969FB3949261E09A5807B402DEBE82785C9FE61FD7EE67C971DD59D0203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E041604147B5B45CFAFCECB7AFD31921A6AB6F346EB574850300D06092A864886F70D010105050003820101007911C04BB391B6FCF0E967D40D6E45BE55E893D2CE033FEDDA25B01D57CB1E3A76A04CEC5076E864720CA4A9F1B88BD6D68784BB32E54111C077D9B3609DEB1BD5D16E4444A9A601EC55621D77B85C8E48497C9C3B5711ACAD73378E2F785C906847D96060E6FC073D222017C4F716E9C4D872F9C8737CDF162F15A93EFD6A27B6A1EB5ABA981FD5E34D640A9D13C861BAF5391C87BAB8BD7B227FF6FEAC4079E5AC106F3D8F1B79768BC437B3211884E53600EB632099B9E9FE3304BB41C8C102F94463209E81CE42D3D63F2C76D3639C59DD8FA6E10EA02E41F72E9547CFBCFD33F3F60B617E7E912B8147C22730EEA7105D378F5C392BE404F07B8D568C68
1860
gtcheck.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar
test
test
1860
gtcheck.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
CompatibilityFlags
0
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
SecuritySafe
1
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000071000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
{06871909-76F1-11E9-A09E-5254004A04AF}
0
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Type
4
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Count
1
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Time
E307050003000F00090008002700BC01
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Type
4
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Count
1
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Time
E307050003000F00090008002700CB01
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
FullScreen
no
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Window_Placement
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF20000000200000004003000078020000
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\Links
Order
08000000020000000C01000001000000020000007E0000000000000070003200EC000000464B245120005355474745537E312E55524C0000540008000400EFBE454B974D464B24512A000000F94300000000020000000000000000000000000000005300750067006700650073007400650064002000530069007400650073002E00750072006C0000001C00000000000000820000000100000074003200E2000000464B24512000574542534C497E312E55524C0000580008000400EFBE454B864A464B24512A000000743E0000000003000000000000000000000000000000570065006200200053006C006900630065002000470061006C006C006500720079002E00750072006C0000001C00000000000000
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\WindowsSearch
UpgradeTime
BFE1ECC9FD0AD501
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
Path
C:\Users\admin\Favorites\Links\Suggested Sites.url
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
Handler
{B0FA7D7C-7195-4F03-B03E-9DC1C9EBC394}
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
FeedUrl
https://ieonline.microsoft.com/#ieslice
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
DisplayName
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
ErrorState
0
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
DisplayMask
0
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
Path
C:\Users\admin\Favorites\Links\Web Slice Gallery.url
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
Handler
{B0FA7D7C-7195-4F03-B03E-9DC1C9EBC394}
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
FeedUrl
http://go.microsoft.com/fwlink/?LinkId=121315
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
DisplayName
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
ErrorState
0
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
DisplayMask
0
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CFBFAE00-17A6-11D0-99CB-00C04FD64497}\iexplore
Type
0
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CFBFAE00-17A6-11D0-99CB-00C04FD64497}\iexplore
Count
1
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CFBFAE00-17A6-11D0-99CB-00C04FD64497}\iexplore
Time
E307050003000F00090009000200BA00
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Type
3
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Count
2
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Time
E307050003000F000900090002004102
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
LoadTime
24
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Type
3
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Count
2
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Time
E307050003000F000900090002007F02
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
LoadTime
373
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Type
3
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Count
2
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Time
E307050003000F00090009000200AE02
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
LoadTime
52
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TypedURLs
url1
http://www.bing.com/search?q=adobe+flsdhplayer&src=IE-SearchBox&FORM=IE8SRC
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TypedURLs
url2
gamespot.com
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TypedURLs
url3
chron.com
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TypedURLs
url4
office
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TypedURLs
url5
newtabtv.com
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TypedURLs
url6
youtube
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TypedURLs
url7
almasryalyoum.com
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TypedURLs
url8
btolat.com
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TypedURLs
url9
reference.com
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TypedURLs
url10
extra.to
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TypedURLs
url11
chip.de
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TypedURLs
url12
pantip.com
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TypedURLs
url13
xda
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TypedURLs
url14
.com
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TypedURLs
url15
as.com
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TypedURLs
url16
autodesk.com
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D27CDB6E-AE6D-11CF-96B8-444553540000}\iexplore
Type
1
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D27CDB6E-AE6D-11CF-96B8-444553540000}\iexplore
Count
1
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D27CDB6E-AE6D-11CF-96B8-444553540000}\iexplore
Time
E307050003000F000900090009002C01
3336
iexplore.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
LanguageList
en-US
3336
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81
Blob
0F000000010000001400000085FEF11B4F47FE3952F98301C9F98976FEFEE0CE09000000010000002A000000302806082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030353000000010000002500000030233021060B6086480186F8450107300130123010060A2B0601040182373C0101030200C01400000001000000140000007B5B45CFAFCECB7AFD31921A6AB6F346EB5748501D00000001000000100000005B3B67000EEB80022E42605B6B3B72400B000000010000000E000000740068006100770074006500000003000000010000001400000091C6D6EE3E8AC86384E548C299295C756C817B812000000001000000240400003082042030820308A0030201020210344ED55720D5EDEC49F42FCE37DB2B6D300D06092A864886F70D01010505003081A9310B300906035504061302555331153013060355040A130C7468617774652C20496E632E31283026060355040B131F43657274696669636174696F6E205365727669636573204469766973696F6E31383036060355040B132F2863292032303036207468617774652C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79311F301D06035504031316746861777465205072696D61727920526F6F74204341301E170D3036313131373030303030305A170D3336303731363233353935395A3081A9310B300906035504061302555331153013060355040A130C7468617774652C20496E632E31283026060355040B131F43657274696669636174696F6E205365727669636573204469766973696F6E31383036060355040B132F2863292032303036207468617774652C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79311F301D06035504031316746861777465205072696D61727920526F6F7420434130820122300D06092A864886F70D01010105000382010F003082010A0282010100ACA0F0FB8059D49CC7A4CF9DA159730910450C0D2C6E68F16C5B4868495937FC0B3319C2777FCC102D95341CE6EB4D09A71CD2B8C9973602B789D4245F06C0CC4494948D02626FEB5ADD118D289A5C8490107A0DBD74662F6A38A0E2D55444EB1D079F07BA6FEEE9FD4E0B29F53E84A001F19CABF81C7E89A4E8A1D871650DA3517BEEBCD222600DB95B9DDFBAFC515B0BAF98B2E92EE904E86287DE2BC8D74EC14C641EDDCF8758BA4A4FCA68071D1C9D4AC6D52F91CC7C71721CC5C067EB32FDC9925C94DA85C09BBF537D2B09F48C9D911F976A52CBDE0936A477D87B875044D53E6E2969FB3949261E09A5807B402DEBE82785C9FE61FD7EE67C971DD59D0203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E041604147B5B45CFAFCECB7AFD31921A6AB6F346EB574850300D06092A864886F70D010105050003820101007911C04BB391B6FCF0E967D40D6E45BE55E893D2CE033FEDDA25B01D57CB1E3A76A04CEC5076E864720CA4A9F1B88BD6D68784BB32E54111C077D9B3609DEB1BD5D16E4444A9A601EC55621D77B85C8E48497C9C3B5711ACAD73378E2F785C906847D96060E6FC073D222017C4F716E9C4D872F9C8737CDF162F15A93EFD6A27B6A1EB5ABA981FD5E34D640A9D13C861BAF5391C87BAB8BD7B227FF6FEAC4079E5AC106F3D8F1B79768BC437B3211884E53600EB632099B9E9FE3304BB41C8C102F94463209E81CE42D3D63F2C76D3639C59DD8FA6E10EA02E41F72E9547CFBCFD33F3F60B617E7E912B8147C22730EEA7105D378F5C392BE404F07B8D568C68
3336
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81
3336
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\91C6D6EE3E8AC86384E548C299295C756C817B81
Blob
190000000100000010000000DC73F9B71E16D51D26527D32B11A6A3D09000000010000002A000000302806082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030353000000010000002500000030233021060B6086480186F8450107300130123010060A2B0601040182373C0101030200C01400000001000000140000007B5B45CFAFCECB7AFD31921A6AB6F346EB5748501D00000001000000100000005B3B67000EEB80022E42605B6B3B72400B000000010000000E000000740068006100770074006500000003000000010000001400000091C6D6EE3E8AC86384E548C299295C756C817B812000000001000000240400003082042030820308A0030201020210344ED55720D5EDEC49F42FCE37DB2B6D300D06092A864886F70D01010505003081A9310B300906035504061302555331153013060355040A130C7468617774652C20496E632E31283026060355040B131F43657274696669636174696F6E205365727669636573204469766973696F6E31383036060355040B132F2863292032303036207468617774652C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79311F301D06035504031316746861777465205072696D61727920526F6F74204341301E170D3036313131373030303030305A170D3336303731363233353935395A3081A9310B300906035504061302555331153013060355040A130C7468617774652C20496E632E31283026060355040B131F43657274696669636174696F6E205365727669636573204469766973696F6E31383036060355040B132F2863292032303036207468617774652C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79311F301D06035504031316746861777465205072696D61727920526F6F7420434130820122300D06092A864886F70D01010105000382010F003082010A0282010100ACA0F0FB8059D49CC7A4CF9DA159730910450C0D2C6E68F16C5B4868495937FC0B3319C2777FCC102D95341CE6EB4D09A71CD2B8C9973602B789D4245F06C0CC4494948D02626FEB5ADD118D289A5C8490107A0DBD74662F6A38A0E2D55444EB1D079F07BA6FEEE9FD4E0B29F53E84A001F19CABF81C7E89A4E8A1D871650DA3517BEEBCD222600DB95B9DDFBAFC515B0BAF98B2E92EE904E86287DE2BC8D74EC14C641EDDCF8758BA4A4FCA68071D1C9D4AC6D52F91CC7C71721CC5C067EB32FDC9925C94DA85C09BBF537D2B09F48C9D911F976A52CBDE0936A477D87B875044D53E6E2969FB3949261E09A5807B402DEBE82785C9FE61FD7EE67C971DD59D0203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E041604147B5B45CFAFCECB7AFD31921A6AB6F346EB574850300D06092A864886F70D010105050003820101007911C04BB391B6FCF0E967D40D6E45BE55E893D2CE033FEDDA25B01D57CB1E3A76A04CEC5076E864720CA4A9F1B88BD6D68784BB32E54111C077D9B3609DEB1BD5D16E4444A9A601EC55621D77B85C8E48497C9C3B5711ACAD73378E2F785C906847D96060E6FC073D222017C4F716E9C4D872F9C8737CDF162F15A93EFD6A27B6A1EB5ABA981FD5E34D640A9D13C861BAF5391C87BAB8BD7B227FF6FEAC4079E5AC106F3D8F1B79768BC437B3211884E53600EB632099B9E9FE3304BB41C8C102F94463209E81CE42D3D63F2C76D3639C59DD8FA6E10EA02E41F72E9547CFBCFD33F3F60B617E7E912B8147C22730EEA7105D378F5C392BE404F07B8D568C68
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Window_Placement
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFD20100001F000000F204000077020000
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Window_Placement
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF00000000000000002003000058020000
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Count
3
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Time
E307050003000F000900090015009F00
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
LoadTime
18
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Count
3
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Time
E307050003000F00090009001500AE00
3336
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
LoadTime
281