General Info

File name

googletoolbarinstaller_updater_signed.exe

Full analysis
https://app.any.run/tasks/cfea4280-3965-450b-9982-4f7e43510995
Verdict
Malicious activity
Analysis date
7/11/2019, 18:52:20
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

e07728f85c48f56645c2d2a4be8aacf5

SHA1

a8345e02bce2075d53b091fb8c95bb052d8e5e7a

SHA256

60b49fbfc3d98134fd35d9bfe45db96985947fdfd0be5221f9fb774a577fc07c

SSDEEP

12288:m5xMvWsU705oDm38AezWs/U1EWtA6UJTiLAxT/7MAjNbk:ixMvMzDq8AeP/U1EWO1T3Twok

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (75.0.3770.100)
  • Google Update Helper (1.3.34.7)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.7.2 (4.7.03062)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (14.21.27702.2)
  • Microsoft Visual C++ 2019 X86 Additional Runtime - 14.21.27702 (14.21.27702)
  • Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.21.27702 (14.21.27702)
  • Mozilla Firefox 67.0.4 (x86 en-US) (67.0.4)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • Update for Microsoft .NET Framework 4.7.2 (KB4087364) (1)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB4019990
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Application was dropped or rewritten from another process
  • GoogleToolbarManager_8B0481A9A34D47CD.exe (PID: 3904)
  • GoogleToolbarManager_8B0481A9A34D47CD.exe (PID: 2632)
  • GoogleUpdateSetup_5CC4B0F53D73AD88.exe (PID: 944)
  • GoogleUpdate.exe (PID: 3104)
  • GoogleUpdaterService.exe (PID: 3660)
  • GoogleToolbarNotifier.exe (PID: 2184)
  • TFRE062.tmp (PID: 3720)
  • GoogleToolbarNotifier.exe (PID: 1100)
  • GoogleToolbarUser_32.exe (PID: 2476)
  • GoogleToolbarNotifier.exe (PID: 864)
  • GoogleToolbarNotifier.exe (PID: 2528)
  • GoogleToolbarUser_32.exe (PID: 3108)
  • GoogleToolbarManager_8B0481A9A34D47CD.exe (PID: 3880)
  • GoogleUpdaterService_B33FC4DD36A473C6.exe (PID: 3312)
  • GoogleUpdaterService.exe (PID: 2176)
  • SearchWithGoogleUpdate_CA8A7236098B8F9A.exe (PID: 2932)
  • GoogleUpdaterService.exe (PID: 3848)
  • GoogleToolbarNotifier.exe (PID: 3644)
  • GoogleToolbarManager_8B0481A9A34D47CD.exe (PID: 2944)
  • GoogleToolbarManager_8B0481A9A34D47CD.exe (PID: 2168)
  • GoogleToolbarManager_8B0481A9A34D47CD.exe (PID: 3568)
Loads dropped or rewritten executable
  • GoogleUpdate.exe (PID: 3104)
  • GoogleToolbarManager_8B0481A9A34D47CD.exe (PID: 3904)
  • GoogleToolbarNotifier.exe (PID: 1100)
  • TFRE062.tmp (PID: 3720)
  • GoogleToolbarManager_8B0481A9A34D47CD.exe (PID: 3568)
  • iexplore.exe (PID: 3168)
  • GoogleToolbarNotifier.exe (PID: 864)
  • GoogleToolbarNotifier.exe (PID: 3644)
  • svchost.exe (PID: 848)
  • iexplore.exe (PID: 2720)
  • GoogleToolbarUser_32.exe (PID: 2476)
  • GoogleToolbarNotifier.exe (PID: 2528)
  • googletoolbarinstaller_updater_signed.exe (PID: 3772)
Changes settings of System certificates
  • GoogleToolbarManager_8B0481A9A34D47CD.exe (PID: 3904)
  • googletoolbarinstaller_updater_signed.exe (PID: 3772)
Loads the Task Scheduler DLL interface
  • GoogleUpdaterService_B33FC4DD36A473C6.exe (PID: 3312)
  • GoogleUpdaterService.exe (PID: 3848)
Executed via COM
  • GoogleUpdateOnDemand.exe (PID: 2700)
  • GoogleUpdateOnDemand.exe (PID: 2988)
  • GoogleUpdateOnDemand.exe (PID: 2876)
  • GoogleUpdateOnDemand.exe (PID: 768)
  • GoogleToolbarNotifier.exe (PID: 2184)
  • GoogleToolbarNotifier.exe (PID: 1100)
  • GoogleToolbarNotifier.exe (PID: 864)
  • GoogleToolbarNotifier.exe (PID: 2528)
Creates files in the program directory
  • GoogleToolbarManager_8B0481A9A34D47CD.exe (PID: 3904)
  • GoogleToolbarUser_32.exe (PID: 2476)
  • GoogleUpdateSetup_5CC4B0F53D73AD88.exe (PID: 944)
  • GoogleToolbarManager_8B0481A9A34D47CD.exe (PID: 2944)
  • GoogleUpdaterService_B33FC4DD36A473C6.exe (PID: 3312)
  • SearchWithGoogleUpdate_CA8A7236098B8F9A.exe (PID: 2932)
  • GoogleToolbarManager_8B0481A9A34D47CD.exe (PID: 3568)
  • googletoolbarinstaller_updater_signed.exe (PID: 3772)
Executable content was dropped or overwritten
  • GoogleToolbarNotifier.exe (PID: 1100)
  • iexplore.exe (PID: 2720)
  • GoogleUpdateSetup_5CC4B0F53D73AD88.exe (PID: 944)
  • GoogleToolbarManager_8B0481A9A34D47CD.exe (PID: 3904)
  • msiexec.exe (PID: 3080)
  • SearchWithGoogleUpdate_CA8A7236098B8F9A.exe (PID: 2932)
  • GoogleUpdaterService_B33FC4DD36A473C6.exe (PID: 3312)
  • GoogleToolbarManager_8B0481A9A34D47CD.exe (PID: 3568)
  • googletoolbarinstaller_updater_signed.exe (PID: 3772)
Starts application with an unusual extension
  • GoogleUpdaterService.exe (PID: 3660)
Removes files from Windows directory
  • TFRE062.tmp (PID: 3720)
Executed as Windows Service
  • GoogleUpdaterService.exe (PID: 3660)
  • GoogleToolbarManager_8B0481A9A34D47CD.exe (PID: 3880)
Creates files in the Windows directory
  • TFRE062.tmp (PID: 3720)
  • GoogleToolbarManager_8B0481A9A34D47CD.exe (PID: 3880)
Creates COM task schedule object
  • GoogleToolbarManager_8B0481A9A34D47CD.exe (PID: 3904)
  • GoogleToolbarNotifier.exe (PID: 3644)
  • GoogleToolbarManager_8B0481A9A34D47CD.exe (PID: 3568)
Adds / modifies Windows certificates
  • GoogleToolbarManager_8B0481A9A34D47CD.exe (PID: 3904)
  • googletoolbarinstaller_updater_signed.exe (PID: 3772)
Starts Internet Explorer
  • GoogleToolbarManager_8B0481A9A34D47CD.exe (PID: 3880)
Creates a software uninstall entry
  • GoogleToolbarManager_8B0481A9A34D47CD.exe (PID: 3568)
Reads Internet Cache Settings
  • googletoolbarinstaller_updater_signed.exe (PID: 3772)
Application launched itself
  • googletoolbarinstaller_updater_signed.exe (PID: 3292)
Reads internet explorer settings
  • iexplore.exe (PID: 2720)
Reads settings of System Certificates
  • iexplore.exe (PID: 2720)
Creates files in the user directory
  • iexplore.exe (PID: 2720)
Reads Internet Cache Settings
  • iexplore.exe (PID: 2720)
Application launched itself
  • iexplore.exe (PID: 3168)
Changes internet zones settings
  • iexplore.exe (PID: 3168)
Creates a software uninstall entry
  • msiexec.exe (PID: 3080)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable MS Visual C++ (generic) (42.2%)
.exe
|   Win64 Executable (generic) (37.3%)
.dll
|   Win32 Dynamic Link Library (generic) (8.8%)
.exe
|   Win32 Executable (generic) (6%)
.exe
|   Generic Win/DOS Executable (2.7%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2016:10:31 23:55:14+01:00
PEType:
PE32
LinkerVersion:
8
CodeSize:
293376
InitializedDataSize:
230400
UninitializedDataSize:
null
EntryPoint:
0x27539
OSVersion:
4
ImageVersion:
null
SubsystemVersion:
4
Subsystem:
Windows GUI
FileVersionNumber:
7.5.8231.2252
ProductVersionNumber:
7.5.8231.2252
FileFlagsMask:
0x003f
FileFlags:
(none)
FileOS:
Windows NT 32-bit
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
English (U.S.)
CharacterSet:
Unicode
CompanyName:
Google Inc.
LegalCopyright:
Copyright © 2000-2014
FileDescription:
Google Toolbar Installer
ProductName:
Google Toolbar for Internet Explorer
ProductVersion:
7, 5, 8231, 2252
FileVersion:
7, 5, 8231, 2252
OriginalFileName:
GoogleToolbarInstaller.exe
InternalName:
GoogleToolbarInstaller
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
31-Oct-2016 22:55:14
Detected languages
Bulgarian - Bulgaria
Catalan - Spain
Chinese - PRC
Chinese - Taiwan
Croatian - Croatia
Czech - Czech Republic
Danish - Denmark
Dutch - Netherlands
English - United Kingdom
English - United States
Estonian - Estonia
Finnish - Finland
French - France
German - Germany
Greek - Greece
Hindi - India
Hungarian - Hungary
Icelandic - Iceland
Indonesian - Indonesia (Bahasa)
Italian - Italy
Japanese - Japan
Korean - Korea
Latvian - Latvia
Lithuanian - Lithuania
Norwegian - Norway (Bokmal)
Polish - Poland
Portuguese - Brazil
Portuguese - Portugal
Romanian - Romania
Russian - Russia
Serbian - Serbia (Cyrillic)
Slovak - Slovakia
Slovenian - Slovenia
Spanish - Spain (International sort)
Swedish - Sweden
Thai - Thailand
Turkish - Turkey
Ukrainian - Ukraine
Vietnamese - Viet Nam
Debug artifacts
componentinstaller.pdb
CompanyName:
Google Inc.
LegalCopyright:
Copyright © 2000-2014
FileDescription:
Google Toolbar Installer
ProductName:
Google Toolbar for Internet Explorer
ProductVersion:
7, 5, 8231, 2252
FileVersion:
7, 5, 8231, 2252
OriginalFilename:
GoogleToolbarInstaller.exe
InternalName:
GoogleToolbarInstaller
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x000000F0
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
5
Time date stamp:
31-Oct-2016 22:55:14
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x00047826 0x00047A00 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.63139
.rdata 0x00049000 0x00010F94 0x00011000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 5.40925
.data 0x0005A000 0x0000BD48 0x00002200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 4.12538
.rsrc 0x00066000 0x000200E0 0x00020200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 5.50255
.reloc 0x00087000 0x00004EE8 0x00005000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_DISCARDABLE,IMAGE_SCN_MEM_READ 4.94542
Resources
1

2

3

4

5

6

10

16

1701

1702

14576

GOOGLETOOLBAR.MANIFEST.XML

Imports
    VERSION.dll

    KERNEL32.dll

    USER32.dll

    ADVAPI32.dll

    ole32.dll

    SHELL32.dll

    OLEAUT32.dll

    SHLWAPI.dll

    GDI32.dll

    urlmon.dll

    USERENV.dll

    PSAPI.DLL

    WTSAPI32.dll

    WINTRUST.dll

    WININET.dll

    CRYPT32.dll

Exports

    No exports.

Screenshots

Processes

Total processes
73
Monitored processes
36
Malicious processes
14
Suspicious processes
9

Behavior graph

+
start drop and start drop and start drop and start drop and start drop and start drop and start drop and start googletoolbarinstaller_updater_signed.exe no specs googletoolbarinstaller_updater_signed.exe googletoolbarmanager_8b0481a9a34d47cd.exe msiexec.exe googleupdaterservice_b33fc4dd36a473c6.exe googleupdaterservice.exe no specs searchwithgoogleupdate_ca8a7236098b8f9a.exe googletoolbarnotifier.exe no specs googleupdaterservice.exe no specs googletoolbarnotifier.exe no specs googletoolbarmanager_8b0481a9a34d47cd.exe no specs googletoolbarmanager_8b0481a9a34d47cd.exe no specs googletoolbarmanager_8b0481a9a34d47cd.exe no specs iexplore.exe iexplore.exe svchost.exe googletoolbaruser_32.exe no specs googletoolbaruser_32.exe googletoolbarnotifier.exe no specs googletoolbarnotifier.exe googleupdaterservice.exe no specs tfre062.tmp no specs googletoolbarnotifier.exe no specs googleupdateondemand.exe no specs googleupdate.exe no specs googleupdateondemand.exe no specs googleupdate.exe no specs googletoolbarmanager_8b0481a9a34d47cd.exe no specs googleupdateondemand.exe no specs googleupdate.exe no specs googleupdateondemand.exe no specs googleupdate.exe no specs googletoolbarmanager_8b0481a9a34d47cd.exe googleupdatesetup_5cc4b0f53d73ad88.exe googleupdate.exe googleupdate.exe
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
848
CMD
C:\Windows\system32\svchost.exe -k netsvcs
Path
C:\Windows\System32\svchost.exe
Indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Host Process for Windows Services
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\gpsvc.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\nsi.dll
c:\windows\system32\sysntfy.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\themeservice.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\profsvc.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\atl.dll
c:\windows\system32\winsta.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\slc.dll
c:\windows\system32\sens.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\shsvcs.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\schedsvc.dll
c:\windows\system32\pcwum.dll
c:\windows\system32\shell32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\authz.dll
c:\windows\system32\ubpm.dll
c:\windows\system32\ktmw32.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\credssp.dll
c:\windows\system32\fveapi.dll
c:\windows\system32\tbs.dll
c:\windows\system32\fvecerts.dll
c:\windows\system32\logoncli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\wiarpc.dll
c:\windows\system32\taskcomp.dll
c:\windows\system32\version.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\netjoin.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\ikeext.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\wbem\wmisvc.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\iphlpsvc.dll
c:\windows\system32\firewallapi.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\wdscore.dll
c:\windows\system32\srvsvc.dll
c:\windows\system32\browser.dll
c:\windows\system32\vssapi.dll
c:\windows\system32\vsstrace.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\samcli.dll
c:\windows\system32\sscore.dll
c:\windows\system32\nci.dll
c:\windows\system32\clusapi.dll
c:\windows\system32\cryptdll.dll
c:\windows\system32\resutils.dll
c:\windows\system32\spinf.dll
c:\windows\system32\netprofm.dll
c:\windows\system32\propsys.dll
c:\windows\system32\wbem\wbemcore.dll
c:\windows\system32\wbem\esscli.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\wmiutils.dll
c:\windows\system32\wbem\repdrvfs.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\npmproxy.dll
c:\windows\system32\sxs.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\tschannel.dll
c:\windows\system32\wbem\wmiprvsd.dll
c:\windows\system32\ncobjapi.dll
c:\windows\system32\wbem\wbemess.dll
c:\windows\system32\wbem\ncprov.dll
c:\windows\system32\qmgr.dll
c:\windows\system32\bitsperf.dll
c:\windows\system32\bitsigd.dll
c:\windows\system32\upnp.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\ssdpapi.dll
c:\windows\system32\wuaueng.dll
c:\windows\system32\esent.dll
c:\windows\system32\winspool.drv
c:\windows\system32\cabinet.dll
c:\windows\system32\mspatcha.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wmsgapi.dll
c:\windows\system32\wer.dll
c:\windows\system32\appinfo.dll
c:\windows\system32\aelupsvc.dll
c:\windows\system32\netcfgx.dll
c:\windows\system32\hnetcfg.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\ndiscapcfg.dll
c:\windows\system32\rascfg.dll
c:\windows\system32\mprapi.dll
c:\windows\system32\tcpipcfg.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\es.dll
c:\windows\system32\windanr.exe
c:\users\admin\appdata\local\temp\googletoolbarinstaller_updater_signed.exe
c:\program files\google\google toolbar\component\googletoolbarmanager_8b0481a9a34d47cd.exe
c:\program files\google\google toolbar\component\googleupdaterservice_b33fc4dd36a473c6.exe
c:\program files\google\common\google updater\googleupdaterservice.exe
c:\program files\google\google toolbar\component\searchwithgoogleupdate_ca8a7236098b8f9a.exe
c:\program files\google\googletoolbarnotifier\googletoolbarnotifier.exe
c:\program files\google\google toolbar\googletoolbar_32.dll
c:\program files\google\google toolbar\googletoolbaruser_32.exe
c:\users\admin\appdata\local\temp\tfre062.tmp
c:\program files\google\update\1.3.34.11\googleupdateondemand.exe
c:\program files\google\google toolbar\component\googleupdatesetup_5cc4b0f53d73ad88.exe
c:\program files\gum107a.tmp\googleupdate.exe

PID
3292
CMD
"C:\Users\admin\AppData\Local\Temp\googletoolbarinstaller_updater_signed.exe"
Path
C:\Users\admin\AppData\Local\Temp\googletoolbarinstaller_updater_signed.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google Inc.
Description
Google Toolbar Installer
Version
7, 5, 8231, 2252
Modules
Image
c:\users\admin\appdata\local\temp\googletoolbarinstaller_updater_signed.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\mpr.dll

PID
3772
CMD
"C:\Users\admin\AppData\Local\Temp\googletoolbarinstaller_updater_signed.exe" /sid:S-1-5-21-1302019708-1500728564-335382590-1000 /dont_elevate
Path
C:\Users\admin\AppData\Local\Temp\googletoolbarinstaller_updater_signed.exe
Indicators
Parent process
googletoolbarinstaller_updater_signed.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Google Inc.
Description
Google Toolbar Installer
Version
7, 5, 8231, 2252
Modules
Image
c:\users\admin\appdata\local\temp\googletoolbarinstaller_updater_signed.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll
c:\windows\system32\sxs.dll
c:\program files\google\google toolbar\component\cmp710f.tmp
c:\program files\google\google toolbar\component\cmp75c4.tmp
c:\program files\google\google toolbar\component\cmp7827.tmp
c:\program files\google\google toolbar\component\cmp7a8b.tmp
c:\program files\google\google toolbar\component\cmp7b87.tmp
c:\program files\google\google toolbar\component\cmp7d1f.tmp
c:\program files\google\google toolbar\component\cmp7f44.tmp
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\apphelp.dll
c:\program files\google\google toolbar\component\googletoolbarmanager_8b0481a9a34d47cd.exe

PID
3568
CMD
"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_8B0481A9A34D47CD.exe" /install /sid:S-1-5-21-1302019708-1500728564-335382590-1000 /sid:S-1-5-21-1302019708-1500728564-335382590-1000 /dont_elevate /installwindow:524650
Path
C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_8B0481A9A34D47CD.exe
Indicators
Parent process
googletoolbarinstaller_updater_signed.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Google Inc.
Description
Google Toolbar Manager
Version
7, 5, 8231, 2252
Modules
Image
c:\program files\google\google toolbar\component\googletoolbarmanager_8b0481a9a34d47cd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\msi.dll
c:\windows\system32\shell32.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\version.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\msimsg.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\apphelp.dll
c:\program files\google\google toolbar\component\googleupdaterservice_b33fc4dd36a473c6.exe
c:\program files\google\google toolbar\component\searchwithgoogleupdate_ca8a7236098b8f9a.exe
c:\program files\google\googletoolbarnotifier\5.12.11510.1228\swg.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\p2pcollab.dll
c:\windows\system32\qagentrt.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\fveui.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\sxs.dll

PID
3080
CMD
C:\Windows\system32\msiexec.exe /V
Path
C:\Windows\system32\msiexec.exe
Indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\ole32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\msimsg.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msisip.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\winsta.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\microsoft.net\framework\v4.0.30319\fusion.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\devrtl.dll

PID
3312
CMD
"C:\Program Files\Google\Google Toolbar\Component\GoogleUpdaterService_B33FC4DD36A473C6.exe" /install /appid=tbie
Path
C:\Program Files\Google\Google Toolbar\Component\GoogleUpdaterService_B33FC4DD36A473C6.exe
Indicators
Parent process
GoogleToolbarManager_8B0481A9A34D47CD.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Google
Description
gusvc
Version
2.4.2617.4952.beta
Modules
Image
c:\program files\google\google toolbar\component\googleupdaterservice_b33fc4dd36a473c6.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\shell32.dll
c:\windows\system32\version.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\apphelp.dll
c:\program files\google\common\google updater\googleupdaterservice.exe
c:\windows\system32\mstask.dll

PID
2176
CMD
"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe" /Service
Path
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
Indicators
No indicators
Parent process
GoogleUpdaterService_B33FC4DD36A473C6.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Google
Description
gusvc
Version
2.4.2617.4952.beta
Modules
Image
c:\program files\google\common\google updater\googleupdaterservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\shell32.dll
c:\windows\system32\version.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll

PID
2932
CMD
"C:\Program Files\Google\Google Toolbar\Component\SearchWithGoogleUpdate_CA8A7236098B8F9A.exe" ietb GUEA
Path
C:\Program Files\Google\Google Toolbar\Component\SearchWithGoogleUpdate_CA8A7236098B8F9A.exe
Indicators
Parent process
GoogleToolbarManager_8B0481A9A34D47CD.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Google Inc.
Description
GoogleToolbarNotifier
Version
5, 12, 11510, 1228
Modules
Image
c:\program files\google\google toolbar\component\searchwithgoogleupdate_ca8a7236098b8f9a.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\apphelp.dll
c:\program files\google\googletoolbarnotifier\googletoolbarnotifier.exe
c:\windows\system32\clbcatq.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\iertutil.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\program files\google\common\google updater\googleupdaterservice.exe

PID
3644
CMD
"C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" /RegServer "/dll=C:\Program Files\Google\GoogleToolbarNotifier\5.12.11510.1228\gtn.dll"
Path
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
Indicators
No indicators
Parent process
SearchWithGoogleUpdate_CA8A7236098B8F9A.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Google Inc.
Description
GoogleToolbarNotifier
Version
4, 1, 509, 1944
Modules
Image
c:\program files\google\googletoolbarnotifier\googletoolbarnotifier.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\program files\google\googletoolbarnotifier\5.12.11510.1228\gtn.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\wininet.dll
c:\windows\system32\ole32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\program files\google\googletoolbarnotifier\5.12.11510.1228\swg.dll
c:\windows\system32\version.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\shell32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll

PID
3848
CMD
"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe" /install /appid=swg
Path
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
Indicators
No indicators
Parent process
SearchWithGoogleUpdate_CA8A7236098B8F9A.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Google
Description
gusvc
Version
2.4.2617.4952.beta
Modules
Image
c:\program files\google\common\google updater\googleupdaterservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\shell32.dll
c:\windows\system32\version.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\mstask.dll

PID
2528
CMD
"C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" -Embedding
Path
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google Inc.
Description
GoogleToolbarNotifier
Version
4, 1, 509, 1944
Modules
Image
c:\program files\google\googletoolbarnotifier\googletoolbarnotifier.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\program files\google\googletoolbarnotifier\5.12.11510.1228\gtn.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\profapi.dll
c:\program files\google\googletoolbarnotifier\5.12.11510.1228\swg.dll
c:\windows\system32\version.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\shell32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sxs.dll
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll

PID
2168
CMD
"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_8B0481A9A34D47CD.exe" /postinstall /sid:S-1-5-21-1302019708-1500728564-335382590-1000 /sid:S-1-5-21-1302019708-1500728564-335382590-1000 /dont_elevate /installwindow:524650
Path
C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_8B0481A9A34D47CD.exe
Indicators
No indicators
Parent process
googletoolbarinstaller_updater_signed.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Google Inc.
Description
Google Toolbar Manager
Version
7, 5, 8231, 2252
Modules
Image
c:\program files\google\google toolbar\component\googletoolbarmanager_8b0481a9a34d47cd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\msi.dll
c:\windows\system32\shell32.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\version.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\cryptbase.dll

PID
2944
CMD
"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_8B0481A9A34D47CD.exe" /custombuttonsinstall
Path
C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_8B0481A9A34D47CD.exe
Indicators
No indicators
Parent process
googletoolbarinstaller_updater_signed.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Google Inc.
Description
Google Toolbar Manager
Version
7, 5, 8231, 2252
Modules
Image
c:\program files\google\google toolbar\component\googletoolbarmanager_8b0481a9a34d47cd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\msi.dll
c:\windows\system32\shell32.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\version.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\cryptbase.dll

PID
3880
CMD
"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_8B0481A9A34D47CD.exe" /service
Path
C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_8B0481A9A34D47CD.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Exit code
0
Version:
Company
Google Inc.
Description
Google Toolbar Manager
Version
7, 5, 8231, 2252
Modules
Image
c:\program files\google\google toolbar\component\googletoolbarmanager_8b0481a9a34d47cd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\msi.dll
c:\windows\system32\shell32.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\version.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\wls0wndh.dll
c:\windows\system32\winsta.dll
c:\windows\system32\sspicli.dll
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\apphelp.dll

PID
3168
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" http://toolbar.google.com/tbredir?r=di&l=en&v=7.5&tbbrand=
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
GoogleToolbarManager_8B0481A9A34D47CD.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\cryptbase.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\version.dll
c:\program files\google\google toolbar\googletoolbar_32.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\ieui.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\url.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\propsys.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\msfeeds.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mlang.dll
c:\windows\system32\normaliz.dll

PID
2720
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3168 CREDAT:71937
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
iexplore.exe
User
admin
Integrity Level
LOW
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\comdlg32.dll
c:\program files\internet explorer\ieshims.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rsaenh.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\version.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mlang.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\uxtheme.dll
c:\program files\java\jre1.8.0_92\bin\ssv.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\program files\google\google toolbar\googletoolbar_32.dll
c:\windows\system32\userenv.dll
c:\progra~1\micros~1\office14\urlredir.dll
c:\program files\google\google toolbar\component\googletoolbardynamic_32_4dc8e820b2954571.dll
c:\windows\system32\msi.dll
c:\windows\system32\msimg32.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\query.dll
c:\windows\system32\secur32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\progra~1\micros~1\office14\msohev.dll
c:\program files\java\jre1.8.0_92\bin\jp2ssv.dll
c:\program files\java\jre1.8.0_92\bin\msvcr100.dll
c:\program files\java\jre1.8.0_92\bin\deploy.dll
c:\windows\system32\imagehlp.dll
c:\program files\google\google toolbar\googletoolbaruser_32.exe
c:\windows\system32\sxs.dll
c:\windows\system32\dwmapi.dll
c:\program files\google\google toolbar\component\googletoolbardynamic_mui_en_4d8162b8670aa63c.dll
c:\windows\system32\dbghelp.dll
c:\program files\google\googletoolbarnotifier\5.12.11510.1228\swg.dll
c:\windows\system32\p2pcollab.dll
c:\windows\system32\qagentrt.dll
c:\windows\system32\fveui.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\jscript.dll
c:\windows\system32\feclient.dll
c:\windows\system32\dxtrans.dll
c:\windows\system32\atl.dll
c:\windows\system32\ddrawex.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\windows\system32\dxtmsft.dll
c:\windows\system32\imgutil.dll
c:\windows\system32\pngfilt.dll
c:\windows\system32\schannel.dll
c:\windows\system32\credssp.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll
c:\programdata\google\google toolbar\component\googlecld_019168f3fd68d3c7.dll
c:\windows\system32\cryptnet.dll
c:\programdata\google\google toolbar\component\googleupdatesetup_5cc4b0f53d73ad88.exe
c:\windows\system32\cabinet.dll
c:\windows\system32\devrtl.dll

PID
3108
CMD
"C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe"
Path
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
Indicators
No indicators
Parent process
iexplore.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google Inc.
Description
Google Toolbar Broker
Version
7, 5, 7619, 1252
Modules
Image
c:\program files\google\google toolbar\googletoolbaruser_32.exe
c:\systemroot\system32\ntdll.dll

PID
2476
CMD
"C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe"
Path
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
Indicators
Parent process
iexplore.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Google Inc.
Description
Google Toolbar Broker
Version
7, 5, 7619, 1252
Modules
Image
c:\program files\google\google toolbar\googletoolbaruser_32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\lpk.dll
c:\windows\system32\ole32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shell32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\version.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\program files\google\google toolbar\component\googletoolbardynamic_32_4dc8e820b2954571.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\msimg32.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\query.dll
c:\windows\system32\normaliz.dll
c:\program files\google\google toolbar\component\googletoolbardynamic_mui_en_4d8162b8670aa63c.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll
c:\windows\system32\slc.dll
c:\windows\system32\networkexplorer.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mpr.dll
c:\windows\system32\drprov.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\winmm.dll
c:\windows\system32\portabledeviceapi.dll
c:\windows\system32\audiodev.dll
c:\windows\system32\wmvcore.dll
c:\windows\system32\wmasf.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\ehstorapi.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\sxs.dll
c:\program files\google\update\1.3.34.11\psmachine.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll

PID
864
CMD
"C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" -Embedding
Path
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google Inc.
Description
GoogleToolbarNotifier
Version
4, 1, 509, 1944
Modules
Image
c:\program files\google\googletoolbarnotifier\googletoolbarnotifier.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\program files\google\googletoolbarnotifier\5.12.11510.1228\gtn.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\profapi.dll
c:\program files\google\googletoolbarnotifier\5.12.11510.1228\swg.dll
c:\windows\system32\version.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\shell32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sxs.dll
c:\program files\internet explorer\iexplore.exe

PID
1100
CMD
"C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" -Embedding
Path
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google Inc.
Description
GoogleToolbarNotifier
Version
4, 1, 509, 1944
Modules
Image
c:\program files\google\googletoolbarnotifier\googletoolbarnotifier.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\program files\google\googletoolbarnotifier\5.12.11510.1228\gtn.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\profapi.dll
c:\program files\google\googletoolbarnotifier\5.12.11510.1228\swg.dll
c:\windows\system32\version.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\shell32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sxs.dll
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll

PID
3660
CMD
"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"
Path
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Google
Description
gusvc
Version
2.4.2617.4952.beta
Modules
Image
c:\program files\google\common\google updater\googleupdaterservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\shell32.dll
c:\windows\system32\version.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sxs.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\tfre062.tmp

PID
3720
CMD
"C:\Users\admin\AppData\Local\Temp\TFRE062.tmp" -set_machine_ds
Path
C:\Users\admin\AppData\Local\Temp\TFRE062.tmp
Indicators
No indicators
Parent process
GoogleUpdaterService.exe
User
SYSTEM
Integrity Level
SYSTEM
Exit code
1
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\tfre062.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\program files\google\googletoolbarnotifier\5.12.11510.1228\swg.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\version.dll
c:\windows\system32\wininet.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll

PID
2184
CMD
"C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" -Embedding
Path
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google Inc.
Description
GoogleToolbarNotifier
Version
4, 1, 509, 1944
Modules
Image
c:\program files\google\googletoolbarnotifier\googletoolbarnotifier.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\program files\google\googletoolbarnotifier\5.12.11510.1228\gtn.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\profapi.dll
c:\program files\google\googletoolbarnotifier\5.12.11510.1228\swg.dll
c:\windows\system32\version.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\shell32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sxs.dll
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll

PID
768
CMD
"C:\Program Files\Google\Update\1.3.34.11\GoogleUpdateOnDemand.exe" -Embedding
Path
C:\Program Files\Google\Update\1.3.34.11\GoogleUpdateOnDemand.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google LLC
Description
Google Update
Version
1.3.34.11
Modules
Image
c:\program files\google\update\1.3.34.11\googleupdateondemand.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\apphelp.dll
c:\program files\google\update\googleupdate.exe

PID
1696
CMD
"C:\Program Files\Google\Update\GoogleUpdate.exe" /ondemand
Path
C:\Program Files\Google\Update\GoogleUpdate.exe
Indicators
No indicators
Parent process
GoogleUpdateOnDemand.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google Inc.
Description
Google Installer
Version
1.3.33.23
Modules
Image
c:\program files\google\update\googleupdate.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\ole32.dll
c:\program files\google\update\1.3.34.11\goopdate.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\msi.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\psapi.dll
c:\windows\system32\version.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\program files\google\update\1.3.34.11\goopdateres_en.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\google\update\1.3.34.11\psmachine.dll
c:\windows\system32\comsvcs.dll
c:\windows\system32\atl.dll

PID
2876
CMD
"C:\Program Files\Google\Update\1.3.34.11\GoogleUpdateOnDemand.exe" -Embedding
Path
C:\Program Files\Google\Update\1.3.34.11\GoogleUpdateOnDemand.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Google LLC
Description
Google Update
Version
1.3.34.11
Modules
Image
c:\program files\google\update\1.3.34.11\googleupdateondemand.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\apphelp.dll
c:\program files\google\update\googleupdate.exe

PID
3832
CMD
"C:\Program Files\Google\Update\GoogleUpdate.exe" /ondemand
Path
C:\Program Files\Google\Update\GoogleUpdate.exe
Indicators
No indicators
Parent process
GoogleUpdateOnDemand.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Google Inc.
Description
Google Installer
Version
1.3.33.23
Modules
Image
c:\program files\google\update\googleupdate.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\ole32.dll
c:\program files\google\update\1.3.34.11\goopdate.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\msi.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\psapi.dll
c:\windows\system32\version.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\cryptbase.dll
c:\program files\google\update\1.3.34.11\goopdateres_en.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\google\update\1.3.34.11\psmachine.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\apphelp.dll

PID
2632
CMD
"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_8B0481A9A34D47CD.exe" /execute:0
Path
C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_8B0481A9A34D47CD.exe
Indicators
No indicators
Parent process
GoogleUpdate.exe
User
admin
Integrity Level
HIGH
Exit code
1
Version:
Company
Google Inc.
Description
Google Toolbar Manager
Version
7, 5, 8231, 2252
Modules
Image
c:\program files\google\google toolbar\component\googletoolbarmanager_8b0481a9a34d47cd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\msi.dll
c:\windows\system32\shell32.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\version.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\cryptbase.dll

PID
2700
CMD
"C:\Program Files\Google\Update\1.3.34.11\GoogleUpdateOnDemand.exe" -Embedding
Path
C:\Program Files\Google\Update\1.3.34.11\GoogleUpdateOnDemand.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google LLC
Description
Google Update
Version
1.3.34.11
Modules
Image
c:\program files\google\update\1.3.34.11\googleupdateondemand.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\apphelp.dll
c:\program files\google\update\googleupdate.exe

PID
2296
CMD
"C:\Program Files\Google\Update\GoogleUpdate.exe" /ondemand
Path
C:\Program Files\Google\Update\GoogleUpdate.exe
Indicators
No indicators
Parent process
GoogleUpdateOnDemand.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google Inc.
Description
Google Installer
Version
1.3.33.23
Modules
Image
c:\program files\google\update\googleupdate.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\ole32.dll
c:\program files\google\update\1.3.34.11\goopdate.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\msi.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\psapi.dll
c:\windows\system32\version.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\program files\google\update\1.3.34.11\goopdateres_en.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\google\update\1.3.34.11\psmachine.dll
c:\windows\system32\comsvcs.dll
c:\windows\system32\atl.dll

PID
2988
CMD
"C:\Program Files\Google\Update\1.3.34.11\GoogleUpdateOnDemand.exe" -Embedding
Path
C:\Program Files\Google\Update\1.3.34.11\GoogleUpdateOnDemand.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Google LLC
Description
Google Update
Version
1.3.34.11
Modules
Image
c:\program files\google\update\1.3.34.11\googleupdateondemand.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\apphelp.dll
c:\program files\google\update\googleupdate.exe

PID
3384
CMD
"C:\Program Files\Google\Update\GoogleUpdate.exe" /ondemand
Path
C:\Program Files\Google\Update\GoogleUpdate.exe
Indicators
No indicators
Parent process
GoogleUpdateOnDemand.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Google Inc.
Description
Google Installer
Version
1.3.33.23
Modules
Image
c:\program files\google\update\googleupdate.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\ole32.dll
c:\program files\google\update\1.3.34.11\goopdate.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\msi.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\psapi.dll
c:\windows\system32\version.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\cryptbase.dll
c:\program files\google\update\1.3.34.11\goopdateres_en.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\google\update\1.3.34.11\psmachine.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\apphelp.dll

PID
3904
CMD
"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_8B0481A9A34D47CD.exe" /execute:1
Path
C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_8B0481A9A34D47CD.exe
Indicators
Parent process
GoogleUpdate.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Google Inc.
Description
Google Toolbar Manager
Version
7, 5, 8231, 2252
Modules
Image
c:\program files\google\google toolbar\component\googletoolbarmanager_8b0481a9a34d47cd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\msi.dll
c:\windows\system32\shell32.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\version.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\cryptbase.dll
c:\program files\google\google toolbar\component\cmpf52.tmp
c:\program files\google\google toolbar\component\cmpfc0.tmp
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\apphelp.dll
c:\program files\google\google toolbar\component\googleupdatesetup_5cc4b0f53d73ad88.exe
c:\program files\google\google toolbar\googletoolbar_32.dll
c:\program files\google\google toolbar\googletoolbaruser_32.exe

PID
944
CMD
"C:\Program Files\Google\Google Toolbar\Component\GoogleUpdateSetup_5CC4B0F53D73AD88.exe" /install "runtime=true&needsadmin=True&brand=GGOT" /installsource toolbar /silent
Path
C:\Program Files\Google\Google Toolbar\Component\GoogleUpdateSetup_5CC4B0F53D73AD88.exe
Indicators
Parent process
GoogleToolbarManager_8B0481A9A34D47CD.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Google Inc.
Description
Google Update Setup
Version
1.3.21.107
Modules
Image
c:\program files\google\google toolbar\component\googleupdatesetup_5cc4b0f53d73ad88.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\apphelp.dll
c:\program files\gum107a.tmp\googleupdate.exe

PID
3104
CMD
"C:\Program Files\GUM107A.tmp\GoogleUpdate.exe" /install "runtime=true&needsadmin=True&brand=GGOT" /installsource toolbar /silent
Path
C:\Program Files\GUM107A.tmp\GoogleUpdate.exe
Indicators
Parent process
GoogleUpdateSetup_5CC4B0F53D73AD88.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Google Inc.
Description
Google Installer
Version
1.3.21.103
Modules
Image
c:\program files\gum107a.tmp\googleupdate.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\program files\gum107a.tmp\goopdate.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\msi.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\version.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\program files\gum107a.tmp\goopdateres_en.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\propsys.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\program files\google\update\googleupdate.exe
c:\windows\system32\psapi.dll

PID
2964
CMD
"C:\Program Files\Google\Update\GoogleUpdate.exe" /ping PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiPz48cmVxdWVzdCBwcm90b2NvbD0iMy4wIiB2ZXJzaW9uPSIxLjMuMjEuMTA3IiBzaGVsbF92ZXJzaW9uPSIxLjMuMjEuMTAzIiBpc21hY2hpbmU9IjEiIHNlc3Npb25pZD0ie0Q1N0JGNEM3LTVBNUYtNEI4Mi1BNEY2LUNFM0FEQjUyMzQ1MH0iIGluc3RhbGxzb3VyY2U9InRvb2xiYXIiIHJlcXVlc3RpZD0iezQxNTQ3MTRELTkwNkEtNERGNy04MjVBLUYxOUU5QTQ2NDYzOH0iPjxvcyBwbGF0Zm9ybT0id2luIiB2ZXJzaW9uPSI2LjEiIHNwPSJTZXJ2aWNlIFBhY2sgMSIgYXJjaD0ieDg2Ii8-PGFwcCBhcHBpZD0iezQzMEZENEQwLUI3MjktNEY2MS1BQTM0LTkxNTI2NDgxNzk5RH0iIHZlcnNpb249IjEuMy4zNC4xMSIgbmV4dHZlcnNpb249IjEuMy4yMS4xMDciIGxhbmc9IiIgYnJhbmQ9IkdHT1QiIGNsaWVudD0iIj48ZXZlbnQgZXZlbnR0eXBlPSIyIiBldmVudHJlc3VsdD0iMSIgZXJyb3Jjb2RlPSIwIiBleHRyYWNvZGUxPSIwIi8-PC9hcHA-PC9yZXF1ZXN0Pg
Path
C:\Program Files\Google\Update\GoogleUpdate.exe
Indicators
Parent process
GoogleUpdate.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Google Inc.
Description
Google Installer
Version
1.3.33.23
Modules
Image
c:\program files\google\update\googleupdate.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\ole32.dll
c:\program files\google\update\1.3.34.11\goopdate.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\msi.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\psapi.dll
c:\windows\system32\version.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\schannel.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\msxml3.dll

Registry activity

Total events
2614
Read events
1620
Write events
984
Delete events
10

Modification events

PID
Process
Operation
Key
Name
Value
848
svchost.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1302019708-1500728564-335382590-1000
RefCount
3
848
svchost.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1302019708-1500728564-335382590-1000
RefCount
2
848
svchost.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\LanmanServer\Parameters
300000000D42A
2AD4000000000300
848
svchost.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1302019708-1500728564-335382590-1000
RefCount
4
3292
googletoolbarinstaller_updater_signed.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3292
googletoolbarinstaller_updater_signed.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3772
googletoolbarinstaller_updater_signed.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar\Branding
sin
0
3772
googletoolbarinstaller_updater_signed.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar\Branding
ein
1
3772
googletoolbarinstaller_updater_signed.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar
test
23710
3772
googletoolbarinstaller_updater_signed.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\googletoolbarinstaller_updater_signed_RASAPI32
EnableFileTracing
0
3772
googletoolbarinstaller_updater_signed.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\googletoolbarinstaller_updater_signed_RASAPI32
EnableConsoleTracing
0
3772
googletoolbarinstaller_updater_signed.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\googletoolbarinstaller_updater_signed_RASAPI32
FileTracingMask
4294901760
3772
googletoolbarinstaller_updater_signed.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\googletoolbarinstaller_updater_signed_RASAPI32
ConsoleTracingMask
4294901760
3772
googletoolbarinstaller_updater_signed.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\googletoolbarinstaller_updater_signed_RASAPI32
MaxFileSize
1048576
3772
googletoolbarinstaller_updater_signed.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\googletoolbarinstaller_updater_signed_RASAPI32
FileDirectory
%windir%\tracing
3772
googletoolbarinstaller_updater_signed.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\googletoolbarinstaller_updater_signed_RASMANCS
EnableFileTracing
0
3772
googletoolbarinstaller_updater_signed.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\googletoolbarinstaller_updater_signed_RASMANCS
EnableConsoleTracing
0
3772
googletoolbarinstaller_updater_signed.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\googletoolbarinstaller_updater_signed_RASMANCS
FileTracingMask
4294901760
3772
googletoolbarinstaller_updater_signed.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\googletoolbarinstaller_updater_signed_RASMANCS
ConsoleTracingMask
4294901760
3772
googletoolbarinstaller_updater_signed.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\googletoolbarinstaller_updater_signed_RASMANCS
MaxFileSize
1048576
3772
googletoolbarinstaller_updater_signed.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\googletoolbarinstaller_updater_signed_RASMANCS
FileDirectory
%windir%\tracing
3772
googletoolbarinstaller_updater_signed.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3772
googletoolbarinstaller_updater_signed.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000077000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3772
googletoolbarinstaller_updater_signed.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3772
googletoolbarinstaller_updater_signed.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3772
googletoolbarinstaller_updater_signed.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar\Component
NextVersion
7.5.8231.2252
3772
googletoolbarinstaller_updater_signed.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
LanguageList
en-US
3772
googletoolbarinstaller_updater_signed.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46
Blob
0F0000000100000014000000F45A0858C9CD920E647BAD539AB9F1CFC77F24CB090000000100000016000000301406082B0601050507030306082B06010505070308140000000100000014000000DAED6474149C143CABDD99A9BD5B284D8B3CC9D80B000000010000001400000055005300450052005400720075007300740000001D0000000100000010000000F919B9CCCE1E59C2E785F7DC2CCF6708030000000100000014000000E12DFB4B41D7D9C32B30514BAC1D81D8385E2D4620000000010000006A040000308204663082034EA003020102021044BE0C8B500024B411D3362DE0B35F1B300D06092A864886F70D0101050500308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A656374301E170D3939303730393138333132305A170D3139303730393138343033365A308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A65637430820122300D06092A864886F70D01010105000382010F003082010A0282010100CEAA813FA3A36178AA31005595119E270F1F1CDF3A9B826830C04A611DF12F0EFABE79F7A523EF55519684CDDBE3B96E3E31D80A2067C7F4D9BF94EB47043E02CE2AA25D870409F6309D188A97B2AA1CFC41D2A136CBFB3D91BAE7D97035FAE4E790C39BA39BD33CF5129977B1B709E068E61CB8F39463886A6AFE0B76C9BEF422E467B9AB1A5E77C18507DD0D6CBFEE06C7776A419EA70FD7FBEE9417B7FC85BEA4ABC41C31DDD7B6D1E4F0EFDF168FB25293D7A1D489A1072EBFE10112421E1AE1D89534DB647928FFBA2E11C2E5E85B9248FB470BC26CDAAD328341F3A5E54170FD65906DFAFA51C4F9BD962B19042CD36DA7DCF07F6F8365E26AAB8786750203010001A381AF3081AC300B0603551D0F0404030201C6300F0603551D130101FF040530030101FF301D0603551D0E04160414DAED6474149C143CABDD99A9BD5B284D8B3CC9D830420603551D1F043B30393037A035A0338631687474703A2F2F63726C2E7573657274727573742E636F6D2F55544E2D5553455246697273742D4F626A6563742E63726C30290603551D250422302006082B0601050507030306082B06010505070308060A2B0601040182370A0304300D06092A864886F70D01010505000382010100081F52B1374478DBFDCEB9DA959698AA556480B55A40DD21A5C5C1F35F2C4CC8475A69EAE8F03535F4D025F3C8A6A4874ABD1BB17308BDD4C3CAB635BB59867731CDA78014AE13EFFCB148F96B25252D51B62C6D45C198C88A565D3EEE434E3E6B278ED03A4B850B5FD3ED6AA775CBD15A872F3975135A72B002819FBEF00F845420626C69D4E14DC60D9943010D12968C789DBF50A2B144AA6ACF177ACF6F0FD4F824555FF0341649663E5046C96371383162B862B9F353AD6CB52BA212AA194F09DA5EE793C68E1408FEF0308018A086854DC87DD78B03FE6ED5F79D16AC922CA023E59C91521F94DF179473C3B3C1C17105200078BD13521DA83ECD001FC8
3772
googletoolbarinstaller_updater_signed.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46
Blob
190000000100000010000000E843AC3B52EC8C297FA948C9B1FB2819030000000100000014000000E12DFB4B41D7D9C32B30514BAC1D81D8385E2D461D0000000100000010000000F919B9CCCE1E59C2E785F7DC2CCF67080B00000001000000140000005500530045005200540072007500730074000000140000000100000014000000DAED6474149C143CABDD99A9BD5B284D8B3CC9D8090000000100000016000000301406082B0601050507030306082B060105050703080F0000000100000014000000F45A0858C9CD920E647BAD539AB9F1CFC77F24CB20000000010000006A040000308204663082034EA003020102021044BE0C8B500024B411D3362DE0B35F1B300D06092A864886F70D0101050500308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A656374301E170D3939303730393138333132305A170D3139303730393138343033365A308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A65637430820122300D06092A864886F70D01010105000382010F003082010A0282010100CEAA813FA3A36178AA31005595119E270F1F1CDF3A9B826830C04A611DF12F0EFABE79F7A523EF55519684CDDBE3B96E3E31D80A2067C7F4D9BF94EB47043E02CE2AA25D870409F6309D188A97B2AA1CFC41D2A136CBFB3D91BAE7D97035FAE4E790C39BA39BD33CF5129977B1B709E068E61CB8F39463886A6AFE0B76C9BEF422E467B9AB1A5E77C18507DD0D6CBFEE06C7776A419EA70FD7FBEE9417B7FC85BEA4ABC41C31DDD7B6D1E4F0EFDF168FB25293D7A1D489A1072EBFE10112421E1AE1D89534DB647928FFBA2E11C2E5E85B9248FB470BC26CDAAD328341F3A5E54170FD65906DFAFA51C4F9BD962B19042CD36DA7DCF07F6F8365E26AAB8786750203010001A381AF3081AC300B0603551D0F0404030201C6300F0603551D130101FF040530030101FF301D0603551D0E04160414DAED6474149C143CABDD99A9BD5B284D8B3CC9D830420603551D1F043B30393037A035A0338631687474703A2F2F63726C2E7573657274727573742E636F6D2F55544E2D5553455246697273742D4F626A6563742E63726C30290603551D250422302006082B0601050507030306082B06010505070308060A2B0601040182370A0304300D06092A864886F70D01010505000382010100081F52B1374478DBFDCEB9DA959698AA556480B55A40DD21A5C5C1F35F2C4CC8475A69EAE8F03535F4D025F3C8A6A4874ABD1BB17308BDD4C3CAB635BB59867731CDA78014AE13EFFCB148F96B25252D51B62C6D45C198C88A565D3EEE434E3E6B278ED03A4B850B5FD3ED6AA775CBD15A872F3975135A72B002819FBEF00F845420626C69D4E14DC60D9943010D12968C789DBF50A2B144AA6ACF177ACF6F0FD4F824555FF0341649663E5046C96371383162B862B9F353AD6CB52BA212AA194F09DA5EE793C68E1408FEF0308018A086854DC87DD78B03FE6ED5F79D16AC922CA023E59C91521F94DF179473C3B3C1C17105200078BD13521DA83ECD001FC8
3772
googletoolbarinstaller_updater_signed.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46
Blob
040000000100000010000000A7F2E41606411150306B9CE3B49CB0C90F0000000100000014000000F45A0858C9CD920E647BAD539AB9F1CFC77F24CB090000000100000016000000301406082B0601050507030306082B06010505070308140000000100000014000000DAED6474149C143CABDD99A9BD5B284D8B3CC9D80B000000010000001400000055005300450052005400720075007300740000001D0000000100000010000000F919B9CCCE1E59C2E785F7DC2CCF6708030000000100000014000000E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46190000000100000010000000E843AC3B52EC8C297FA948C9B1FB281920000000010000006A040000308204663082034EA003020102021044BE0C8B500024B411D3362DE0B35F1B300D06092A864886F70D0101050500308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A656374301E170D3939303730393138333132305A170D3139303730393138343033365A308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A65637430820122300D06092A864886F70D01010105000382010F003082010A0282010100CEAA813FA3A36178AA31005595119E270F1F1CDF3A9B826830C04A611DF12F0EFABE79F7A523EF55519684CDDBE3B96E3E31D80A2067C7F4D9BF94EB47043E02CE2AA25D870409F6309D188A97B2AA1CFC41D2A136CBFB3D91BAE7D97035FAE4E790C39BA39BD33CF5129977B1B709E068E61CB8F39463886A6AFE0B76C9BEF422E467B9AB1A5E77C18507DD0D6CBFEE06C7776A419EA70FD7FBEE9417B7FC85BEA4ABC41C31DDD7B6D1E4F0EFDF168FB25293D7A1D489A1072EBFE10112421E1AE1D89534DB647928FFBA2E11C2E5E85B9248FB470BC26CDAAD328341F3A5E54170FD65906DFAFA51C4F9BD962B19042CD36DA7DCF07F6F8365E26AAB8786750203010001A381AF3081AC300B0603551D0F0404030201C6300F0603551D130101FF040530030101FF301D0603551D0E04160414DAED6474149C143CABDD99A9BD5B284D8B3CC9D830420603551D1F043B30393037A035A0338631687474703A2F2F63726C2E7573657274727573742E636F6D2F55544E2D5553455246697273742D4F626A6563742E63726C30290603551D250422302006082B0601050507030306082B06010505070308060A2B0601040182370A0304300D06092A864886F70D01010505000382010100081F52B1374478DBFDCEB9DA959698AA556480B55A40DD21A5C5C1F35F2C4CC8475A69EAE8F03535F4D025F3C8A6A4874ABD1BB17308BDD4C3CAB635BB59867731CDA78014AE13EFFCB148F96B25252D51B62C6D45C198C88A565D3EEE434E3E6B278ED03A4B850B5FD3ED6AA775CBD15A872F3975135A72B002819FBEF00F845420626C69D4E14DC60D9943010D12968C789DBF50A2B144AA6ACF177ACF6F0FD4F824555FF0341649663E5046C96371383162B862B9F353AD6CB52BA212AA194F09DA5EE793C68E1408FEF0308018A086854DC87DD78B03FE6ED5F79D16AC922CA023E59C91521F94DF179473C3B3C1C17105200078BD13521DA83ECD001FC8
3772
googletoolbarinstaller_updater_signed.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar\Component
CurrentVersion
7.5.8231.2252
3772
googletoolbarinstaller_updater_signed.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar\Branding
sin
1
3772
googletoolbarinstaller_updater_signed.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar\Branding
ein
0
3772
googletoolbarinstaller_updater_signed.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar\4.0\Setup
FirstInstallTime
1562863964
3772
googletoolbarinstaller_updater_signed.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar\4.0\Setup
FailedInstallPing
http://clients1.google.com/tools/pso/ping?as=tbin&gu=pi&mode=3&sin=1&ein=0&version=7.5.8231.2252&brand=GUEA&hl=en&tbiv=7.5.8231.2252&time=1562863964&fitime=1562863964&browser=8.0.7601.17514&osver=6.1&ossp=1.0&osarch=32&ext=EXE&id=16810CA6615935ABAF4A2BA5B184EBE01EB3AFgTEXA
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2318C2B1-4965-11d4-9B18-009027A5CD4F}
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
delete key
HKEY_CLASSES_ROOT\Local Settings\MuiCache\70\52C64B7E
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
delete key
HKEY_CLASSES_ROOT\Local Settings\MuiCache\70
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar
test
41
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar\Component\Used
GoogleToolbarManager.exe
1
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\Clients\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}
cmd_7.5.8231.2252_0
"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_8B0481A9A34D47CD.exe" /execute:0
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\Clients\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}
cmd_7.5.8231.2252_1
"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_8B0481A9A34D47CD.exe" /execute:1
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\Clients\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}
cmd_7.5.8231.2252_2
"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_8B0481A9A34D47CD.exe" /execute:2
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\Clients\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}
cmd_7.5.8231.2252_3
"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_8B0481A9A34D47CD.exe" /execute:3
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\Clients\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}
cmd_7.5.8231.2252_4
"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_8B0481A9A34D47CD.exe" /execute:4
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\Clients\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}
cmd_7.5.8231.2252_5
"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_8B0481A9A34D47CD.exe" /execute:5
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\Clients\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}
cmd_7.5.8231.2252_6
"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_8B0481A9A34D47CD.exe" /execute:6
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\Clients\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}
cmd_7.5.8231.2252_7
"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_8B0481A9A34D47CD.exe" /execute:7
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\Clients\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}
cmd_7.5.8231.2252_8
"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_8B0481A9A34D47CD.exe" /execute:8
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\Clients\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}
cmd_7.5.8231.2252_9
"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_8B0481A9A34D47CD.exe" /execute:9
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\Clients\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}
name
Google Toolbar
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}
brand
GUEA
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientState\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}
InstallTime
1562863961
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar\GoogleUpdate
InstallResult
pi
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar\GoogleUpdate
InstallTimestamp
1562863961
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar\Branding
brand
GUEA
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar\Branding
id
16810CA6615935ABAF4A2BA5B184EBE01EB3AFgTEXA
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar\Branding
installtime
1562863962
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar\Branding
InstallType
3
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar\4.0\Setup
DisableBrowseByName
0
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options
BrowseByName
0
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar\4.0\Setup
ToastOfferTime
0
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar\4.0\Setup
EulaAccepted
0
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar\4.0\Setup
EnableUsageStats
1
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options
ToastSetPageRank
2
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options
ToastSetHomePage
2
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar\4.0\Setup
SystemPatchLevel
1
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options
UsageStatsEnabled
1
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2318C2B1-4965-11d4-9B18-009027A5CD4F}
DisplayName
Google Toolbar for Internet Explorer
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2318C2B1-4965-11d4-9B18-009027A5CD4F}
UninstallString
"C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_8B0481A9A34D47CD.exe" /uninstall
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2318C2B1-4965-11d4-9B18-009027A5CD4F}
NoModify
1
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2318C2B1-4965-11d4-9B18-009027A5CD4F}
NoRepair
1
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2318C2B1-4965-11d4-9B18-009027A5CD4F}
Publisher
Google Inc.
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2318C2B1-4965-11d4-9B18-009027A5CD4F}
DisplayIcon
C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarManager_8B0481A9A34D47CD.exe
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2318C2B1-4965-11d4-9B18-009027A5CD4F}
InstallLocation
C:\Program Files\Google\Google Toolbar\
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2318C2B1-4965-11d4-9B18-009027A5CD4F}
MajorVersion
7
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2318C2B1-4965-11d4-9B18-009027A5CD4F}
MinorVersion
5
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2318C2B1-4965-11d4-9B18-009027A5CD4F}
DisplayVersion
7.5.8231.2252
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1A972DAF-A7EC-4ce3-B6C9-7B523CD6685F}
AppName
GoogleToolbarUser_32.exe
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1A972DAF-A7EC-4ce3-B6C9-7B523CD6685F}
AppPath
C:\Program Files\Google\Google Toolbar
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1A972DAF-A7EC-4ce3-B6C9-7B523CD6685F}
Policy
3
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EE0B94B9-335F-4d2c-8B43-DACCD1EA6FF1}
AppName
GoogleToolbarUser_64.exe
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EE0B94B9-335F-4d2c-8B43-DACCD1EA6FF1}
AppPath
C:\Program Files\Google\Google Toolbar
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EE0B94B9-335F-4d2c-8B43-DACCD1EA6FF1}
Policy
3
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{2318C2B1-4965-11d4-9B18-009027A5CD4F}
Compatibility Flags
1024
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11d4-9B18-009027A5CD4F}
Google Toolbar
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11d4-9B18-009027A5CD4F}\InprocServer32
C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11d4-9B18-009027A5CD4F}\InprocServer32
ThreadingModel
Apartment
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar
{2318C2B1-4965-11d4-9B18-009027A5CD4F}
00
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA58ED58-01DD-4d91-8333-CF10577473F7}
Google Toolbar Helper
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA58ED58-01DD-4d91-8333-CF10577473F7}\InprocServer32
C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AA58ED58-01DD-4d91-8333-CF10577473F7}\InprocServer32
ThreadingModel
Apartment
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform
GTB7.5
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\18555481990E8AB4CBB63FB4F26006C0
AuthorizedLUAApp
1
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar\Component\Used
GoogleUpdaterService.exe
1
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar\Component\Used
SearchWithGoogleUpdate.exe
1
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\71\52C64B7E
LanguageList
en-US
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\71\52C64B7E
@%SystemRoot%\system32\p2pcollab.dll,-8042
Peer to Peer Trust
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\71\52C64B7E
@%SystemRoot%\system32\qagentrt.dll,-10
System Health Authentication
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\71\52C64B7E
@%SystemRoot%\system32\dnsapi.dll,-103
Domain Name System (DNS) Server Trust
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\71\52C64B7E
@%SystemRoot%\System32\fveui.dll,-843
BitLocker Drive Encryption
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\71\52C64B7E
@%SystemRoot%\System32\fveui.dll,-844
BitLocker Data Recovery Agent
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options
ToastSetDefaultSearch
3
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Enable Browser Extensions
yes
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options
RbbsBreak
1
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options
ButtonPageRank
0
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options
{14C626CA-ACAB-46e5-8A99-53C9E11CCCA0}_enabled
0
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar\4.0\Setup
WelcomePage
http://toolbar.google.com/tbredir?r=di&l=en&v=7.5&tbbrand=
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar\Installations
1562863963
v=7.5.8231.2252&tbbrand=GUEA&i=0
3568
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar\Component
PrimaryInstallDone
1
3080
msiexec.exe
delete key
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\70\52C64B7E
3080
msiexec.exe
delete key
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\70
3080
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
3080
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback
3080
msiexec.exe
delete key
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
3080
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress
3080
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000_CLASSES\Local Settings\MuiCache\70\52C64B7E
LanguageList
en-US
3080
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Owner
080C000066440C0E0938D501
3080
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
SessionHash
F634EB2994B1D883B36EC270E67676AECB1196A64F5D68E6ECB93B897AE07E9F
3080
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Sequence
1
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress
C:\Windows\Installer\16816b.ipi
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\16816c.rbs
30750737
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\16816c.rbsLow
1882502848
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5BFB0305F3F68B04BAB8C647D818B9C1
18555481990E8AB4CBB63FB4F26006C0
02:\SOFTWARE\Google\Installers\MsiStubRun
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Installers
MsiStubRun
0
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\18555481990E8AB4CBB63FB4F26006C0\InstallProperties
LocalPackage
C:\Windows\Installer\16816d.msi
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\18555481990E8AB4CBB63FB4F26006C0\InstallProperties
AuthorizedCDFPrefix
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\18555481990E8AB4CBB63FB4F26006C0\InstallProperties
Comments
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\18555481990E8AB4CBB63FB4F26006C0\InstallProperties
Contact
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\18555481990E8AB4CBB63FB4F26006C0\InstallProperties
DisplayVersion
1.0.0
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\18555481990E8AB4CBB63FB4F26006C0\InstallProperties
HelpLink
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\18555481990E8AB4CBB63FB4F26006C0\InstallProperties
HelpTelephone
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\18555481990E8AB4CBB63FB4F26006C0\InstallProperties
InstallDate
20190711
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\18555481990E8AB4CBB63FB4F26006C0\InstallProperties
InstallLocation
C:\Program Files\Google\Installers\
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\18555481990E8AB4CBB63FB4F26006C0\InstallProperties
InstallSource
C:\Program Files\Google\Google Toolbar\
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\18555481990E8AB4CBB63FB4F26006C0\InstallProperties
ModifyPath
MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\18555481990E8AB4CBB63FB4F26006C0\InstallProperties
Publisher
Google Inc.
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\18555481990E8AB4CBB63FB4F26006C0\InstallProperties
Readme
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\18555481990E8AB4CBB63FB4F26006C0\InstallProperties
Size
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\18555481990E8AB4CBB63FB4F26006C0\InstallProperties
EstimatedSize
45
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\18555481990E8AB4CBB63FB4F26006C0\InstallProperties
SystemComponent
1
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\18555481990E8AB4CBB63FB4F26006C0\InstallProperties
UninstallString
MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\18555481990E8AB4CBB63FB4F26006C0\InstallProperties
URLInfoAbout
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\18555481990E8AB4CBB63FB4F26006C0\InstallProperties
URLUpdateInfo
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\18555481990E8AB4CBB63FB4F26006C0\InstallProperties
VersionMajor
1
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\18555481990E8AB4CBB63FB4F26006C0\InstallProperties
VersionMinor
0
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\18555481990E8AB4CBB63FB4F26006C0\InstallProperties
WindowsInstaller
1
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\18555481990E8AB4CBB63FB4F26006C0\InstallProperties
Version
16777216
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\18555481990E8AB4CBB63FB4F26006C0\InstallProperties
Language
1033
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{18455581-E099-4BA8-BC6B-F34B2F06600C}
AuthorizedCDFPrefix
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{18455581-E099-4BA8-BC6B-F34B2F06600C}
Comments
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{18455581-E099-4BA8-BC6B-F34B2F06600C}
Contact
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{18455581-E099-4BA8-BC6B-F34B2F06600C}
DisplayVersion
1.0.0
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{18455581-E099-4BA8-BC6B-F34B2F06600C}
HelpLink
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{18455581-E099-4BA8-BC6B-F34B2F06600C}
HelpTelephone
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{18455581-E099-4BA8-BC6B-F34B2F06600C}
InstallDate
20190711
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{18455581-E099-4BA8-BC6B-F34B2F06600C}
InstallLocation
C:\Program Files\Google\Installers\
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{18455581-E099-4BA8-BC6B-F34B2F06600C}
InstallSource
C:\Program Files\Google\Google Toolbar\
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{18455581-E099-4BA8-BC6B-F34B2F06600C}
ModifyPath
MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{18455581-E099-4BA8-BC6B-F34B2F06600C}
Publisher
Google Inc.
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{18455581-E099-4BA8-BC6B-F34B2F06600C}
Readme
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{18455581-E099-4BA8-BC6B-F34B2F06600C}
Size
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{18455581-E099-4BA8-BC6B-F34B2F06600C}
EstimatedSize
45
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{18455581-E099-4BA8-BC6B-F34B2F06600C}
SystemComponent
1
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{18455581-E099-4BA8-BC6B-F34B2F06600C}
UninstallString
MsiExec.exe /I{18455581-E099-4BA8-BC6B-F34B2F06600C}
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{18455581-E099-4BA8-BC6B-F34B2F06600C}
URLInfoAbout
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{18455581-E099-4BA8-BC6B-F34B2F06600C}
URLUpdateInfo
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{18455581-E099-4BA8-BC6B-F34B2F06600C}
VersionMajor
1
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{18455581-E099-4BA8-BC6B-F34B2F06600C}
VersionMinor
0
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{18455581-E099-4BA8-BC6B-F34B2F06600C}
WindowsInstaller
1
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{18455581-E099-4BA8-BC6B-F34B2F06600C}
Version
16777216
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{18455581-E099-4BA8-BC6B-F34B2F06600C}
Language
1033
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\A9C08D73A738D4645A912F4E39ABB657
18555481990E8AB4CBB63FB4F26006C0
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\18555481990E8AB4CBB63FB4F26006C0\InstallProperties
DisplayName
Google Toolbar for Internet Explorer
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{18455581-E099-4BA8-BC6B-F34B2F06600C}
DisplayName
Google Toolbar for Internet Explorer
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\18555481990E8AB4CBB63FB4F26006C0
Complete
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\18555481990E8AB4CBB63FB4F26006C0\Features
Complete
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\18555481990E8AB4CBB63FB4F26006C0\Patches
AllPatches
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\18555481990E8AB4CBB63FB4F26006C0
ProductName
Google Toolbar for Internet Explorer
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\18555481990E8AB4CBB63FB4F26006C0
PackageCode
48497EB4EC7F8F440917FDF4C216A09F
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\18555481990E8AB4CBB63FB4F26006C0
Language
1033
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\18555481990E8AB4CBB63FB4F26006C0
Version
16777216
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\18555481990E8AB4CBB63FB4F26006C0
Assignment
1
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\18555481990E8AB4CBB63FB4F26006C0
AdvertiseFlags
388
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\18555481990E8AB4CBB63FB4F26006C0
InstanceType
0
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\18555481990E8AB4CBB63FB4F26006C0
AuthorizedLUAApp
1
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\18555481990E8AB4CBB63FB4F26006C0
DeploymentFlags
3
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\A9C08D73A738D4645A912F4E39ABB657
18555481990E8AB4CBB63FB4F26006C0
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\18555481990E8AB4CBB63FB4F26006C0\SourceList
PackageName
GoogleToolbarHelper_signed.msi
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\18555481990E8AB4CBB63FB4F26006C0\SourceList\Net
1
C:\Program Files\Google\Google Toolbar\
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\18555481990E8AB4CBB63FB4F26006C0\SourceList\Media
1
;
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\18555481990E8AB4CBB63FB4F26006C0
Clients
:
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\18555481990E8AB4CBB63FB4F26006C0\SourceList
LastUsedSource
n;1;C:\Program Files\Google\Google Toolbar\
3080
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings
StringCacheGeneration
113
3312
GoogleUpdaterService_B33FC4DD36A473C6.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Common\Google Updater
path
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
3312
GoogleUpdaterService_B33FC4DD36A473C6.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Common\Google Updater
version
2.4.2617.4952
3312
GoogleUpdaterService_B33FC4DD36A473C6.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Common\Google Updater\apps\tbie
auto
0
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{61E28BF8-C02B-499F-8E7A-34C1E4A1C649}
gusvc
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\GoogleUpdaterService.exe
AppID
{61E28BF8-C02B-499F-8E7A-34C1E4A1C649}
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{61E28BF8-C02B-499F-8E7A-34C1E4A1C649}
LocalService
gusvc
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GUSchedulerCtl.UpdaterScheduler.1
Google Updater Scheduler class
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GUSchedulerCtl.UpdaterScheduler.1\CLSID
{B53B7061-6584-46AA-A033-D610EB10BD9B}
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GUSchedulerCtl.UpdaterScheduler
Google Updater Scheduler class
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GUSchedulerCtl.UpdaterScheduler\CLSID
{B53B7061-6584-46AA-A033-D610EB10BD9B}
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GUSchedulerCtl.UpdaterScheduler\CurVer
GUSchedulerCtl.UpdaterScheduler.1
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B53B7061-6584-46AA-A033-D610EB10BD9B}
Google Updater Scheduler class
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B53B7061-6584-46AA-A033-D610EB10BD9B}\ProgID
GUSchedulerCtl.UpdaterScheduler.1
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B53B7061-6584-46AA-A033-D610EB10BD9B}\VersionIndependentProgID
GUSchedulerCtl.UpdaterScheduler
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B53B7061-6584-46AA-A033-D610EB10BD9B}\LocalServer32
"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B53B7061-6584-46AA-A033-D610EB10BD9B}
AppID
{61E28BF8-C02B-499F-8E7A-34C1E4A1C649}
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B53B7061-6584-46AA-A033-D610EB10BD9B}\TypeLib
{5924C60B-6D7F-4AD6-8084-24A59431C967}
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GUServiceCtl.SilentUpdater.1
Google Silent Updater class
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GUServiceCtl.SilentUpdater.1\CLSID
{89DAE4CD-9F17-4980-902A-99BA84A8F5C8}
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GUServiceCtl.SilentUpdater
Google Silent Updater class
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GUServiceCtl.SilentUpdater\CLSID
{89DAE4CD-9F17-4980-902A-99BA84A8F5C8}
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\GUServiceCtl.SilentUpdater\CurVer
GUServiceCtl.SilentUpdater.1
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{89DAE4CD-9F17-4980-902A-99BA84A8F5C8}
Google Silent Updater class
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{89DAE4CD-9F17-4980-902A-99BA84A8F5C8}\ProgID
GUServiceCtl.SilentUpdater.1
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{89DAE4CD-9F17-4980-902A-99BA84A8F5C8}\VersionIndependentProgID
GUServiceCtl.SilentUpdater
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{89DAE4CD-9F17-4980-902A-99BA84A8F5C8}\LocalServer32
"C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{89DAE4CD-9F17-4980-902A-99BA84A8F5C8}
AppID
{61E28BF8-C02B-499F-8E7A-34C1E4A1C649}
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{89DAE4CD-9F17-4980-902A-99BA84A8F5C8}\TypeLib
{5924C60B-6D7F-4AD6-8084-24A59431C967}
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{5924C60B-6D7F-4AD6-8084-24A59431C967}\1.0
Google Updater Service 1.0 Type Library
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{5924C60B-6D7F-4AD6-8084-24A59431C967}\1.0\FLAGS
0
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{5924C60B-6D7F-4AD6-8084-24A59431C967}\1.0\0\win32
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{5924C60B-6D7F-4AD6-8084-24A59431C967}\1.0\HELPDIR
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C07A89E4-82A3-4A29-9908-DFC9DEBF8267}
ISilentUpdater
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C07A89E4-82A3-4A29-9908-DFC9DEBF8267}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C07A89E4-82A3-4A29-9908-DFC9DEBF8267}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C07A89E4-82A3-4A29-9908-DFC9DEBF8267}\TypeLib
{5924C60B-6D7F-4AD6-8084-24A59431C967}
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C07A89E4-82A3-4A29-9908-DFC9DEBF8267}\TypeLib
Version
1.0
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5C8CE0B5-6DA0-49A1-B675-78FD03EA3224}
IUpdaterScheduler
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5C8CE0B5-6DA0-49A1-B675-78FD03EA3224}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5C8CE0B5-6DA0-49A1-B675-78FD03EA3224}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5C8CE0B5-6DA0-49A1-B675-78FD03EA3224}\TypeLib
{5924C60B-6D7F-4AD6-8084-24A59431C967}
2176
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5C8CE0B5-6DA0-49A1-B675-78FD03EA3224}\TypeLib
Version
1.0
2932
SearchWithGoogleUpdate_CA8A7236098B8F9A.exe
write
HKEY_CURRENT_USER\Software\Google\GoogleToolbarNotifier\Temp
ust
100
2932
SearchWithGoogleUpdate_CA8A7236098B8F9A.exe
write
HKEY_CURRENT_USER\Software\Google\GoogleToolbarNotifier\Temp
ust
103
2932
SearchWithGoogleUpdate_CA8A7236098B8F9A.exe
write
HKEY_CURRENT_USER\Software\Google\GoogleToolbarNotifier\Temp
ust
104
2932
SearchWithGoogleUpdate_CA8A7236098B8F9A.exe
write
HKEY_CURRENT_USER\Software\Google\GoogleToolbarNotifier\Temp
ust
105
2932
SearchWithGoogleUpdate_CA8A7236098B8F9A.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\GoogleToolbarNotifier
Version
5.12.11510.1228
2932
SearchWithGoogleUpdate_CA8A7236098B8F9A.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\GoogleToolbarNotifier\Clients
ietb
0
2932
SearchWithGoogleUpdate_CA8A7236098B8F9A.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\GoogleToolbarNotifier
brand
GUEA
2932
SearchWithGoogleUpdate_CA8A7236098B8F9A.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager
PendingFileRenameOperations
\??\C:\Program Files\Google\GoogleToolbarNotifier\5.12.11510.1228
2932
SearchWithGoogleUpdate_CA8A7236098B8F9A.exe
write
HKEY_CURRENT_USER\Software\Google\GoogleToolbarNotifier\Temp
ust
106
2932
SearchWithGoogleUpdate_CA8A7236098B8F9A.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\GoogleToolbarNotifier
id
6fd9472243564dac94ea7bb113e7651e
2932
SearchWithGoogleUpdate_CA8A7236098B8F9A.exe
write
HKEY_CURRENT_USER\Software\Google\GoogleToolbarNotifier\Temp
ust
108
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{A97CA128-6998-4F8E-807E-8ED05FADAFB0}
ProtectorExe
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\ProtectorExe.EXE
AppID
{A97CA128-6998-4F8E-807E-8ED05FADAFB0}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{96FBC13C-8214-4100-88E0-FF74D7A1CB4D}
protector_dll
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\protector_dll.DLL
AppID
{96FBC13C-8214-4100-88E0-FF74D7A1CB4D}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{A97CA128-6998-4F8E-807E-8ED05FADAFB0}
RunAs
Interactive User
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\protector_dll.Protector.1
Protector Class
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\protector_dll.Protector.1\CLSID
{6134CEA9-DD6E-495C-A0D1-4F232027D7D7}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\protector_dll.Protector
Protector Class
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\protector_dll.Protector\CLSID
{6134CEA9-DD6E-495C-A0D1-4F232027D7D7}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\protector_dll.Protector\CurVer
protector_dll.Protector.1
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6134CEA9-DD6E-495C-A0D1-4F232027D7D7}
Protector Class
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6134CEA9-DD6E-495C-A0D1-4F232027D7D7}\ProgID
protector_dll.Protector.1
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6134CEA9-DD6E-495C-A0D1-4F232027D7D7}\VersionIndependentProgID
protector_dll.Protector
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6134CEA9-DD6E-495C-A0D1-4F232027D7D7}\InprocServer32
C:\Program Files\Google\GoogleToolbarNotifier\5.12.11510.1228\swg.dll
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6134CEA9-DD6E-495C-A0D1-4F232027D7D7}\InprocServer32
ThreadingModel
Apartment
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6134CEA9-DD6E-495C-A0D1-4F232027D7D7}
AppID
{96FBC13C-8214-4100-88E0-FF74D7A1CB4D}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6134CEA9-DD6E-495C-A0D1-4F232027D7D7}\TypeLib
{C7CB459A-7261-4AE6-A87A-17041EE98A40}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ProtectorExe.ProtectorHost.1
ProtectorHost Class
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ProtectorExe.ProtectorHost.1\CLSID
{FBA44040-BD27-4A09-ACC8-C08B7C723DCD}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ProtectorExe.ProtectorHost
ProtectorHost Class
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ProtectorExe.ProtectorHost\CLSID
{FBA44040-BD27-4A09-ACC8-C08B7C723DCD}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\ProtectorExe.ProtectorHost\CurVer
ProtectorExe.ProtectorHost.1
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FBA44040-BD27-4A09-ACC8-C08B7C723DCD}
ProtectorHost Class
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FBA44040-BD27-4A09-ACC8-C08B7C723DCD}\ProgID
ProtectorExe.ProtectorHost.1
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FBA44040-BD27-4A09-ACC8-C08B7C723DCD}\VersionIndependentProgID
ProtectorExe.ProtectorHost
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FBA44040-BD27-4A09-ACC8-C08B7C723DCD}\LocalServer32
"C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FBA44040-BD27-4A09-ACC8-C08B7C723DCD}
AppID
{A97CA128-6998-4F8E-807E-8ED05FADAFB0}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FBA44040-BD27-4A09-ACC8-C08B7C723DCD}\TypeLib
{C7CB459A-7261-4AE6-A87A-17041EE98A40}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FBA44040-BD27-4A09-ACC8-C08B7C723DCD}
Depend
C:\Program Files\Google\GoogleToolbarNotifier\5.12.11510.1228\gtn.dll
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\protector_dll.ProtectorLib.1
ProtectorLib Class
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\protector_dll.ProtectorLib.1\CLSID
{84798B8E-69F8-4846-9516-373C2996E2F7}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\protector_dll.ProtectorLib
ProtectorLib Class
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\protector_dll.ProtectorLib\CLSID
{84798B8E-69F8-4846-9516-373C2996E2F7}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\protector_dll.ProtectorLib\CurVer
protector_dll.ProtectorLib.1
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{84798B8E-69F8-4846-9516-373C2996E2F7}
ProtectorLib Class
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{84798B8E-69F8-4846-9516-373C2996E2F7}\ProgID
protector_dll.ProtectorLib.1
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{84798B8E-69F8-4846-9516-373C2996E2F7}\VersionIndependentProgID
protector_dll.ProtectorLib
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{84798B8E-69F8-4846-9516-373C2996E2F7}\InprocServer32
C:\Program Files\Google\GoogleToolbarNotifier\5.12.11510.1228\swg.dll
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{84798B8E-69F8-4846-9516-373C2996E2F7}\InprocServer32
ThreadingModel
Apartment
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{84798B8E-69F8-4846-9516-373C2996E2F7}
AppID
{96FBC13C-8214-4100-88E0-FF74D7A1CB4D}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{84798B8E-69F8-4846-9516-373C2996E2F7}\TypeLib
{C7CB459A-7261-4AE6-A87A-17041EE98A40}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C7CB459A-7261-4AE6-A87A-17041EE98A40}\1a.0
protector_dllLib
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C7CB459A-7261-4AE6-A87A-17041EE98A40}\1a.0\FLAGS
0
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C7CB459A-7261-4AE6-A87A-17041EE98A40}\1a.0\0\win32
C:\Program Files\Google\GoogleToolbarNotifier\5.12.11510.1228\swg.dll
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{C7CB459A-7261-4AE6-A87A-17041EE98A40}\1a.0\HELPDIR
C:\Program Files\Google\GoogleToolbarNotifier\5.12.11510.1228
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F1A383D4-0364-4092-82E0-C39DAE5D801D}
IProtector12
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F1A383D4-0364-4092-82E0-C39DAE5D801D}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F1A383D4-0364-4092-82E0-C39DAE5D801D}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F1A383D4-0364-4092-82E0-C39DAE5D801D}\TypeLib
{C7CB459A-7261-4AE6-A87A-17041EE98A40}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{F1A383D4-0364-4092-82E0-C39DAE5D801D}\TypeLib
Version
1a.0
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{315A0BBF-D55B-4FCE-833E-8BAA5B6344F6}
IProtector11
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{315A0BBF-D55B-4FCE-833E-8BAA5B6344F6}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{315A0BBF-D55B-4FCE-833E-8BAA5B6344F6}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{315A0BBF-D55B-4FCE-833E-8BAA5B6344F6}\TypeLib
{C7CB459A-7261-4AE6-A87A-17041EE98A40}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{315A0BBF-D55B-4FCE-833E-8BAA5B6344F6}\TypeLib
Version
1a.0
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6C110376-C248-47F6-9DB2-CFCDEADB6A3E}
IProtector10
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6C110376-C248-47F6-9DB2-CFCDEADB6A3E}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6C110376-C248-47F6-9DB2-CFCDEADB6A3E}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6C110376-C248-47F6-9DB2-CFCDEADB6A3E}\TypeLib
{C7CB459A-7261-4AE6-A87A-17041EE98A40}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6C110376-C248-47F6-9DB2-CFCDEADB6A3E}\TypeLib
Version
1a.0
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{277FD1E8-9884-4E0A-9392-7CFF83F067B2}
IProtector9
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{277FD1E8-9884-4E0A-9392-7CFF83F067B2}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{277FD1E8-9884-4E0A-9392-7CFF83F067B2}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{277FD1E8-9884-4E0A-9392-7CFF83F067B2}\TypeLib
{C7CB459A-7261-4AE6-A87A-17041EE98A40}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{277FD1E8-9884-4E0A-9392-7CFF83F067B2}\TypeLib
Version
1a.0
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A45CDEEB-65F5-49AE-AA3E-9376F4806075}
IProtector8
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A45CDEEB-65F5-49AE-AA3E-9376F4806075}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A45CDEEB-65F5-49AE-AA3E-9376F4806075}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A45CDEEB-65F5-49AE-AA3E-9376F4806075}\TypeLib
{C7CB459A-7261-4AE6-A87A-17041EE98A40}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A45CDEEB-65F5-49AE-AA3E-9376F4806075}\TypeLib
Version
1a.0
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5D358B5C-3415-42BB-A606-E1089B674F41}
IProtector7
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5D358B5C-3415-42BB-A606-E1089B674F41}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5D358B5C-3415-42BB-A606-E1089B674F41}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5D358B5C-3415-42BB-A606-E1089B674F41}\TypeLib
{C7CB459A-7261-4AE6-A87A-17041EE98A40}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5D358B5C-3415-42BB-A606-E1089B674F41}\TypeLib
Version
1a.0
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6EACF525-5F81-4381-9E46-DC316C39E0D2}
IProtector6
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6EACF525-5F81-4381-9E46-DC316C39E0D2}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6EACF525-5F81-4381-9E46-DC316C39E0D2}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6EACF525-5F81-4381-9E46-DC316C39E0D2}\TypeLib
{C7CB459A-7261-4AE6-A87A-17041EE98A40}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6EACF525-5F81-4381-9E46-DC316C39E0D2}\TypeLib
Version
1a.0
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1F7328B7-E25A-4527-B24B-D9173401BB89}
IProtector5
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1F7328B7-E25A-4527-B24B-D9173401BB89}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1F7328B7-E25A-4527-B24B-D9173401BB89}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1F7328B7-E25A-4527-B24B-D9173401BB89}\TypeLib
{C7CB459A-7261-4AE6-A87A-17041EE98A40}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{1F7328B7-E25A-4527-B24B-D9173401BB89}\TypeLib
Version
1a.0
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9891812B-5820-4A77-827E-772B200239E1}
IProtector4
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9891812B-5820-4A77-827E-772B200239E1}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9891812B-5820-4A77-827E-772B200239E1}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9891812B-5820-4A77-827E-772B200239E1}\TypeLib
{C7CB459A-7261-4AE6-A87A-17041EE98A40}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9891812B-5820-4A77-827E-772B200239E1}\TypeLib
Version
1a.0
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{91F39C2A-95E7-497A-A539-0AC715DC66D2}
IProtector3
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{91F39C2A-95E7-497A-A539-0AC715DC66D2}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{91F39C2A-95E7-497A-A539-0AC715DC66D2}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{91F39C2A-95E7-497A-A539-0AC715DC66D2}\TypeLib
{C7CB459A-7261-4AE6-A87A-17041EE98A40}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{91F39C2A-95E7-497A-A539-0AC715DC66D2}\TypeLib
Version
1a.0
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2212951C-1623-4095-906B-AC50B8F91016}
IProtector2
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2212951C-1623-4095-906B-AC50B8F91016}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2212951C-1623-4095-906B-AC50B8F91016}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2212951C-1623-4095-906B-AC50B8F91016}\TypeLib
{C7CB459A-7261-4AE6-A87A-17041EE98A40}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2212951C-1623-4095-906B-AC50B8F91016}\TypeLib
Version
1a.0
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2351B346-00E8-4EAC-9B75-B138B465D659}
IProtector
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2351B346-00E8-4EAC-9B75-B138B465D659}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2351B346-00E8-4EAC-9B75-B138B465D659}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2351B346-00E8-4EAC-9B75-B138B465D659}\TypeLib
{C7CB459A-7261-4AE6-A87A-17041EE98A40}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{2351B346-00E8-4EAC-9B75-B138B465D659}\TypeLib
Version
1a.0
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{91959FBB-853A-4AC7-A082-2DDF787F4CA9}
IProtectorHost2
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{91959FBB-853A-4AC7-A082-2DDF787F4CA9}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{91959FBB-853A-4AC7-A082-2DDF787F4CA9}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{91959FBB-853A-4AC7-A082-2DDF787F4CA9}\TypeLib
{C7CB459A-7261-4AE6-A87A-17041EE98A40}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{91959FBB-853A-4AC7-A082-2DDF787F4CA9}\TypeLib
Version
1a.0
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DA69D3CC-7676-4A65-889F-C052977F1AA9}
IProtectorHost
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DA69D3CC-7676-4A65-889F-C052977F1AA9}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DA69D3CC-7676-4A65-889F-C052977F1AA9}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DA69D3CC-7676-4A65-889F-C052977F1AA9}\TypeLib
{C7CB459A-7261-4AE6-A87A-17041EE98A40}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DA69D3CC-7676-4A65-889F-C052977F1AA9}\TypeLib
Version
1a.0
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BACAB2F3-7213-4865-96E9-B6B06BF49192}
IProtectorLib8
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BACAB2F3-7213-4865-96E9-B6B06BF49192}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BACAB2F3-7213-4865-96E9-B6B06BF49192}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BACAB2F3-7213-4865-96E9-B6B06BF49192}\TypeLib
{C7CB459A-7261-4AE6-A87A-17041EE98A40}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BACAB2F3-7213-4865-96E9-B6B06BF49192}\TypeLib
Version
1a.0
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{17484B9D-89FA-484F-912E-017D06C41FE0}
IProtectorLib7
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{17484B9D-89FA-484F-912E-017D06C41FE0}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{17484B9D-89FA-484F-912E-017D06C41FE0}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{17484B9D-89FA-484F-912E-017D06C41FE0}\TypeLib
{C7CB459A-7261-4AE6-A87A-17041EE98A40}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{17484B9D-89FA-484F-912E-017D06C41FE0}\TypeLib
Version
1a.0
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{480AD54B-C652-44B9-BCF6-746745055CD3}
IProtectorLib6
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{480AD54B-C652-44B9-BCF6-746745055CD3}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{480AD54B-C652-44B9-BCF6-746745055CD3}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{480AD54B-C652-44B9-BCF6-746745055CD3}\TypeLib
{C7CB459A-7261-4AE6-A87A-17041EE98A40}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{480AD54B-C652-44B9-BCF6-746745055CD3}\TypeLib
Version
1a.0
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{235317AD-6EF4-4209-9354-F88869E1A3BB}
IProtectorLib5
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{235317AD-6EF4-4209-9354-F88869E1A3BB}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{235317AD-6EF4-4209-9354-F88869E1A3BB}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{235317AD-6EF4-4209-9354-F88869E1A3BB}\TypeLib
{C7CB459A-7261-4AE6-A87A-17041EE98A40}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{235317AD-6EF4-4209-9354-F88869E1A3BB}\TypeLib
Version
1a.0
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DD65ABB2-2628-425B-86F5-825E4A3D3AD9}
IProtectorLib4
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DD65ABB2-2628-425B-86F5-825E4A3D3AD9}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DD65ABB2-2628-425B-86F5-825E4A3D3AD9}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DD65ABB2-2628-425B-86F5-825E4A3D3AD9}\TypeLib
{C7CB459A-7261-4AE6-A87A-17041EE98A40}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DD65ABB2-2628-425B-86F5-825E4A3D3AD9}\TypeLib
Version
1a.0
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9D932020-700E-4F0D-8446-2872ABD8B4FA}
IProtectorLib3
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9D932020-700E-4F0D-8446-2872ABD8B4FA}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9D932020-700E-4F0D-8446-2872ABD8B4FA}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9D932020-700E-4F0D-8446-2872ABD8B4FA}\TypeLib
{C7CB459A-7261-4AE6-A87A-17041EE98A40}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{9D932020-700E-4F0D-8446-2872ABD8B4FA}\TypeLib
Version
1a.0
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A0CF48B9-DB91-49A5-BEE7-2FB45BA2F610}
IProtectorLib2
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A0CF48B9-DB91-49A5-BEE7-2FB45BA2F610}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A0CF48B9-DB91-49A5-BEE7-2FB45BA2F610}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A0CF48B9-DB91-49A5-BEE7-2FB45BA2F610}\TypeLib
{C7CB459A-7261-4AE6-A87A-17041EE98A40}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A0CF48B9-DB91-49A5-BEE7-2FB45BA2F610}\TypeLib
Version
1a.0
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AF606610-3627-4DF2-A6D5-32C6A355ACD1}
IProtectorLib
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AF606610-3627-4DF2-A6D5-32C6A355ACD1}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AF606610-3627-4DF2-A6D5-32C6A355ACD1}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AF606610-3627-4DF2-A6D5-32C6A355ACD1}\TypeLib
{C7CB459A-7261-4AE6-A87A-17041EE98A40}
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{AF606610-3627-4DF2-A6D5-32C6A355ACD1}\TypeLib
Version
1a.0
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{80B84A0A-EDA4-47fd-8BE1-6B49F4197EE5}
AppName
GoogleToolbarNotifier.exe
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{80B84A0A-EDA4-47fd-8BE1-6B49F4197EE5}
AppPath
C:\Program Files\Google\GoogleToolbarNotifier
3644
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{80B84A0A-EDA4-47fd-8BE1-6B49F4197EE5}
Policy
3
3848
GoogleUpdaterService.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Common\Google Updater\apps\swg
auto
0
2528
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GoogleToolbarNotifier_RASAPI32
EnableFileTracing
0
2528
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GoogleToolbarNotifier_RASAPI32
EnableConsoleTracing
0
2528
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GoogleToolbarNotifier_RASAPI32
FileTracingMask
4294901760
2528
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GoogleToolbarNotifier_RASAPI32
ConsoleTracingMask
4294901760
2528
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GoogleToolbarNotifier_RASAPI32
MaxFileSize
1048576
2528
GoogleToolbarNotifier.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\GoogleToolbarNotifier_RASAPI32
FileDirectory
%windir%\tracing
2528
GoogleToolbarNotifier.exe
write
HKEY_CURRENT_USER\Software\Google\GoogleToolbarNotifier
DefaultLanguage
en
2528
GoogleToolbarNotifier.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\71\52C64B7E
LanguageList
en-US
2528
GoogleToolbarNotifier.exe
write
HKEY_CURRENT_USER\Software\Google\GoogleToolbarNotifier
ts
1562863963
2528
GoogleToolbarNotifier.exe
write
HKEY_CURRENT_USER\Software\Google\GoogleToolbarNotifier\Stats
DetectChange_DS
0
2528
GoogleToolbarNotifier.exe
write
HKEY_CURRENT_USER\Software\Google\GoogleToolbarNotifier\Stats
UserAllowChange_DS
0
2528
GoogleToolbarNotifier.exe
write
HKEY_CURRENT_USER\Software\Google\GoogleToolbarNotifier\Stats
ShowUI_Popup
0
2528
GoogleToolbarNotifier.exe
write
HKEY_CURRENT_USER\Software\Google\GoogleToolbarNotifier\Stats
ShowUI_TrayIcon
0
2528
GoogleToolbarNotifier.exe
write
HKEY_CURRENT_USER\Software\Google\GoogleToolbarNotifier\Stats
HideUI_Throttled
0
2528
GoogleToolbarNotifier.exe
write
HKEY_CURRENT_USER\Software\Google\GoogleToolbarNotifier\Stats
ModifyUI_UserIntent
0
2528
GoogleToolbarNotifier.exe
write
HKEY_CURRENT_USER\Software\Google\GoogleToolbarNotifier\Stats
Bubble_Click
0
2528
GoogleToolbarNotifier.exe
write
HKEY_CURRENT_USER\Software\Google\GoogleToolbarNotifier\Stats
Icon_Click
0
2528
GoogleToolbarNotifier.exe
write
HKEY_CURRENT_USER\Software\Google\GoogleToolbarNotifier\Stats
LastReportTime
0
2528
GoogleToolbarNotifier.exe
write
HKEY_CURRENT_USER\Software\Google\GoogleToolbarNotifier\Stats
LastReportTime
1562863963
2528
GoogleToolbarNotifier.exe
write
HKEY_CURRENT_USER\Software\Google\GoogleToolbarNotifier
FirstRun
0
2528
GoogleToolbarNotifier.exe
write
HKEY_CURRENT_USER\Software\Google\GoogleToolbarNotifier
lds
http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
2528
GoogleToolbarNotifier.exe
write
HKEY_CURRENT_USER\Software\Google\GoogleToolbarNotifier
UpdateURL
http://clients1.google.com/tools/swg2/update
2528
GoogleToolbarNotifier.exe
write
HKEY_CURRENT_USER\Software\Google\GoogleToolbarNotifier
AppPath
C:\Program Files\Google\GoogleToolbarNotifier
2528
GoogleToolbarNotifier.exe
write
HKEY_CURRENT_USER\Software\Google\GoogleToolbarNotifier
InstalledVersion
5.12.11510.1228
2528
GoogleToolbarNotifier.exe
write
HKEY_CURRENT_USER\Software\Google\GoogleToolbarNotifier
UsageStat
1
2168
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\Clients\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}
pv
7.5.8231.2252
2168
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar\Component\Used
GoogleToolbarManager.exe
1
2944
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar\Component\NonManifest
C:\ProgramData\Google\Custom Buttons\toolbar.google.com_O8Y91YHB24Z6SR0SGYSK.XML
1
2944
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar\Component\Used
GoogleToolbarDynamic_mui_en.dll
1
3880
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\Clients\{F69EABDD-A4BB-4555-BE7E-1EA5F59BBA24}
pv
7.5.8231.2252
3880
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar\Component\Used
GoogleToolbarManager.exe
1
3880
GoogleToolbarManager_8B0481A9A34D47CD.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar\4.0\Setup
BringIeToForeground
1
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AA58ED58-01DD-4D91-8333-CF10577473F7}
VerCache
581D050E0938D50128D6B50B0938D5010000000070F2020005000700E404C31D05000700E404C31D09040000
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2318C2B1-4965-11D4-9B18-009027A5CD4F}
VerCache
581D050E0938D50128D6B50B0938D5010000000070F2020005000700E404C31D05000700E404C31D09040000
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
CompatibilityFlags
0
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
SecuritySafe
1
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000078000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
{4D495B53-A3FC-11E9-B2FD-5254004A04AF}
0
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Type
4
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Count
1
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Time
E307070004000B00100034002C004503
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Type
4
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Count
1
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Time
E307070004000B00100034002C004503
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
FullScreen
no
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Window_Placement
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF20000000200000004003000078020000
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\Links
Order
08000000020000000C01000001000000020000007E0000000000000070003200EC000000464B245120005355474745537E312E55524C0000540008000400EFBE454B974D464B24512A000000F94300000000020000000000000000000000000000005300750067006700650073007400650064002000530069007400650073002E00750072006C0000001C00000000000000820000000100000074003200E2000000464B24512000574542534C497E312E55524C0000580008000400EFBE454B864A464B24512A000000743E0000000003000000000000000000000000000000570065006200200053006C006900630065002000470061006C006C006500720079002E00750072006C0000001C00000000000000
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Type
3
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Count
1
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Time
E307070004000B00100034002D005700
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
LoadTime
12
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AA58ED58-01DD-4D91-8333-CF10577473F7}\iexplore
Type
3
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AA58ED58-01DD-4D91-8333-CF10577473F7}\iexplore
Flags
0
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AA58ED58-01DD-4D91-8333-CF10577473F7}\iexplore
Count
1
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AA58ED58-01DD-4D91-8333-CF10577473F7}\iexplore
Time
E307070004000B00100034002D007600
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AA58ED58-01DD-4D91-8333-CF10577473F7}\iexplore
LoadTime
23
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Type
3
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Count
1
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Time
E307070004000B00100034002D009600
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
LoadTime
159
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Type
3
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Count
1
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Time
E307070004000B00100034002D002201
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
LoadTime
93
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\iexplore
Type
2
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\iexplore
Flags
0
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\iexplore
Count
1
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\iexplore
Time
E307070004000B00100034002D008A02
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\iexplore
Count
2
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\iexplore
Time
E307070004000B00100034002D009902
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\iexplore
LoadTime
7
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\iexplore
Count
3
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\iexplore
Time
E307070004000B00100034002E003800
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\iexplore
Count
4
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\iexplore
Time
E307070004000B00100034002E007600
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
Path
C:\Users\admin\Favorites\Links\Suggested Sites.url
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
Handler
{B0FA7D7C-7195-4F03-B03E-9DC1C9EBC394}
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
FeedUrl
https://ieonline.microsoft.com/#ieslice
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
DisplayName
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
ErrorState
0
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
DisplayMask
0
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
Path
C:\Users\admin\Favorites\Links\Web Slice Gallery.url
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
Handler
{B0FA7D7C-7195-4F03-B03E-9DC1C9EBC394}
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
FeedUrl
http://go.microsoft.com/fwlink/?LinkId=121315
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
DisplayName
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
ErrorState
0
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
DisplayMask
0
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\User Preferences
6256FFB019F8FDFBD36745B06F4540E9AEAF222A25
01000000D08C9DDF0115D1118C7A00C04FC297EB01000000BD615485961203458C6C4C94D3B0609E0000000002000000000010660000000100002000000043B518B9CDD2FDF5E28D2411CFE944B22A10BCC0C62D36F72279D1F0E47D30C6000000000E800000000200002000000004A75FFF40208DDC5F83CC66609C00513F54C91F9C56E53C590F61E2DCCA472D10000000D4800C721DD2451E6E3F18F3EE78962940000000C3E3DF6327FB66FC91EE34B5F17F57D7FBDAFC4B08F16A818F4FF578F744AC2349022855BBA8C4DB30C167FB62013E8B6C8289AAD52CF05DAAE56D95A742FB46
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\User Preferences
88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977
01000000D08C9DDF0115D1118C7A00C04FC297EB01000000BD615485961203458C6C4C94D3B0609E00000000020000000000106600000001000020000000B1760D137D6DF05D7D71927BE343FEC6387E850633FDB171AAFF749F29C497AE000000000E80000000020000200000004DD1C5935113BA53B381026F710314B5286C95BAF2FFAE759CB6A5C872603F6050000000AB85711B61CD69BA70847FE34E5C8AA524F97B625464C41D7E0E00835B3162D842874FF49318147D6405E685D191A02F0F709DD85A39A2A20A363197D6706B1DB0CFEB631E8C077A0B1DB2AD556602C44000000057696B079FB191EC703B620F65317850A9442590622E2E4CDF762D09E369E13B0B655D921363485022666F6DC8ACA33767468E00CC94721836F849338469DCAD
3168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes
DefaultScope
{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Setup
LastElevationRefresh
0A0514100938D501
2720
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Google Toolbar\Component\Used
GoogleToolbarDynamic_mui_en.dll
1
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options
UserPatchLevel
1
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options
LastPatchVersion
7.5.8231.2252
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\UsageStats\Weekly\Counts
DynamicInSafeComponentDir
1
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options
DefaultsCopied
1
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\UsageStats\Weekly\Counts
IENewTabOrWindowOpened.ext
1
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\UsageStats\Weekly\Counts
UnhideToolbar.ext
1
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
{2318C2B1-4965-11D4-9B18-009027A5CD4F}
B1C218236549D4119B18009027A5CD4F
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
ITBar7Layout
13000000000000000000000030000000100001001F00000001000000000700005E010000060000000101000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000B1C218236549D4119B18009027A5CD4F0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0
instances
131550;
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\UsageStats\Weekly\Integers
SearchTypesCount.ext
1
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\S_toolbar.google.com_O8Y91YHB24Z6SR0SGYSK.XML
ontoolbar_start_time
1562863965
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.news
ontoolbar_start_time
1562863965
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.lucky
order
0
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.lucky
in_search_list
1
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.lucky
ontoolbar
0
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.lucky
title
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.lucky
option1
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.lucky
gadget_options
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.site
order
1
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.site
in_search_list
1
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.site
ontoolbar
0
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.site
title
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.site
option1
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.site
gadget_options
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.country
order
2
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.country
in_search_list
1
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.country
ontoolbar
0
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.country
title
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.country
option1
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.country
gadget_options
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.images
order
3
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.images
in_search_list
1
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.images
ontoolbar
0
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.images
title
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.images
option1
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.images
gadget_options
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.video
order
4
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.video
in_search_list
1
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.video
ontoolbar
0
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.video
title
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.video
option1
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.video
gadget_options
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.news
order
5
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.news
in_search_list
1
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.news
ontoolbar
1
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.news
title
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.news
option1
2720
iexplore.exe
write
HKEY_CURRENT_USER\Software\Google\Google Toolbar\4.0\Options\Custom Buttons\google.news
gadget_options