General Info

File name

npp.7.5.8.Installer.exe

Full analysis
https://app.any.run/tasks/94e61209-9eef-4eda-82d5-6691eab1bd06
Verdict
Malicious activity
Analysis date
6/12/2019, 11:46:54
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5

077268086e3e4dba46b1bd1ee1ef521c

SHA1

feda36051199971832b0c822e30b6f7fda5894f9

SHA256

613f36bf5e98be7e56b7ea0c678cfb8534077c2ec1cbe839a854dd0a60278ebb

SSDEEP

98304:7v/2wyZ0bXqWXqLW3RYehe90pGjOXtovTKg5JauD:7hyZEMLW3ieU9JyXt+WgLauD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (73.0.3683.75)
  • Google Update Helper (1.3.33.23)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 65.0.2 (x86 en-US) (65.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Application was dropped or rewritten from another process
  • npp.7.7.Installer.exe (PID: 3736)
  • npp.7.7.Installer.exe (PID: 1512)
  • gup.exe (PID: 2328)
  • notepad++.exe (PID: 2168)
  • notepad++.exe (PID: 3792)
Loads dropped or rewritten executable
  • npp.7.7.Installer.exe (PID: 1512)
  • notepad++.exe (PID: 2168)
  • notepad++.exe (PID: 3792)
  • gup.exe (PID: 2328)
  • regsvr32.exe (PID: 2116)
  • npp.7.5.8.Installer.exe (PID: 2336)
Registers / Runs the DLL via REGSVR32.EXE
  • npp.7.5.8.Installer.exe (PID: 2336)
Executable content was dropped or overwritten
  • npp.7.7.Installer.exe (PID: 1512)
  • gup.exe (PID: 2328)
  • npp.7.5.8.Installer.exe (PID: 2336)
Creates files in the user directory
  • notepad++.exe (PID: 3792)
  • npp.7.5.8.Installer.exe (PID: 2336)
Creates COM task schedule object
  • regsvr32.exe (PID: 2116)
Executed via COM
  • explorer.exe (PID: 3120)
Creates files in the program directory
  • npp.7.5.8.Installer.exe (PID: 2336)
Creates a software uninstall entry
  • npp.7.5.8.Installer.exe (PID: 2336)

No info indicators.

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable MS Visual C++ (generic) (42.2%)
.exe
|   Win64 Executable (generic) (37.3%)
.dll
|   Win32 Dynamic Link Library (generic) (8.8%)
.exe
|   Win32 Executable (generic) (6%)
.exe
|   Generic Win/DOS Executable (2.7%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2016:12:11 22:50:48+01:00
PEType:
PE32
LinkerVersion:
6
CodeSize:
25088
InitializedDataSize:
141824
UninitializedDataSize:
2048
EntryPoint:
0x344a
OSVersion:
4
ImageVersion:
6
SubsystemVersion:
4
Subsystem:
Windows GUI
FileVersionNumber:
7.5.8.0
ProductVersionNumber:
7.5.8.0
FileFlagsMask:
0x0000
FileFlags:
(none)
FileOS:
Win32
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
English (U.S.)
CharacterSet:
Unicode
CompanyName:
FileDescription:
Notepad++ : a free (GNU) source code editor
FileVersion:
7.5.8.0
LegalCopyright:
Copyleft 1998-2017 by Don HO
ProductName:
Notepad++
ProductVersion:
7.58
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
11-Dec-2016 21:50:48
Detected languages
English - United States
CompanyName:
FileDescription:
Notepad++ : a free (GNU) source code editor
FileVersion:
7.5.8.0
LegalCopyright:
Copyleft 1998-2017 by Don HO
ProductName:
Notepad++
ProductVersion:
7.58
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x000000C8
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
5
Time date stamp:
11-Dec-2016 21:50:48
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x000061F1 0x00006200 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.47707
.rdata 0x00008000 0x000013A4 0x00001400 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 5.163
.data 0x0000A000 0x00020338 0x00000600 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 3.97456
.ndata 0x0002B000 0x0001A000 0x00000000 IMAGE_SCN_CNT_UNINITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.rsrc 0x00045000 0x00026120 0x00026200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 5.72234
Resources
1

2

3

4

5

102

103

104

105

106

107

110

111

202

203

204

205

206

207

211

302

303

304

305

306

307

311

402

403

404

405

406

407

411

502

503

504

505

506

507

511

602

603

604

605

606

607

611

702

703

704

705

706

707

711

802

803

804

805

806

807

811

Imports
    KERNEL32.dll

    USER32.dll

    GDI32.dll

    SHELL32.dll

    ADVAPI32.dll

    COMCTL32.dll

    ole32.dll

Exports

    No exports.

Screenshots

Processes

Total processes
47
Monitored processes
10
Malicious processes
4
Suspicious processes
2

Behavior graph

+
drop and start start drop and start drop and start npp.7.5.8.installer.exe no specs npp.7.5.8.installer.exe regsvr32.exe no specs explorer.exe no specs explorer.exe no specs notepad++.exe gup.exe notepad++.exe npp.7.7.installer.exe no specs npp.7.7.installer.exe
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
860
CMD
"C:\Users\admin\AppData\Local\Temp\npp.7.5.8.Installer.exe"
Path
C:\Users\admin\AppData\Local\Temp\npp.7.5.8.Installer.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
Don HO [email protected]
Description
Notepad++ : a free (GNU) source code editor
Version
7.5.8.0
Modules
Image
c:\users\admin\appdata\local\temp\npp.7.5.8.installer.exe
c:\systemroot\system32\ntdll.dll

PID
2336
CMD
"C:\Users\admin\AppData\Local\Temp\npp.7.5.8.Installer.exe"
Path
C:\Users\admin\AppData\Local\Temp\npp.7.5.8.Installer.exe
Indicators
Parent process
––
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Don HO [email protected]
Description
Notepad++ : a free (GNU) source code editor
Version
7.5.8.0
Modules
Image
c:\users\admin\appdata\local\temp\npp.7.5.8.installer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\version.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shdocvw.dll
c:\users\admin\appdata\local\temp\nst16ed.tmp\langdll.dll
c:\users\admin\appdata\local\temp\nst16ed.tmp\system.dll
c:\windows\system32\riched20.dll
c:\users\admin\appdata\local\temp\nst16ed.tmp\installoptions.dll
c:\windows\system32\comdlg32.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\users\admin\appdata\local\temp\nst16ed.tmp\nsdialogs.dll
c:\users\admin\appdata\local\temp\nst16ed.tmp\userinfo.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\program files\notepad++\notepad++.exe
c:\windows\system32\regsvr32.exe
c:\windows\system32\netutils.dll

PID
2116
CMD
regsvr32 /s "C:\Program Files\Notepad++\NppShell_06.dll"
Path
C:\Windows\system32\regsvr32.exe
Indicators
No indicators
Parent process
npp.7.5.8.Installer.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft(C) Register Server
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\program files\notepad++\nppshell_06.dll
c:\windows\system32\msimg32.dll

PID
3864
CMD
"C:\Windows\explorer.exe" "C:\Program Files\Notepad++\notepad++.exe"
Path
C:\Windows\explorer.exe
Indicators
No indicators
Parent process
npp.7.5.8.Installer.exe
User
admin
Integrity Level
HIGH
Exit code
1
Version:
Company
Microsoft Corporation
Description
Windows Explorer
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\slc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\actxprxy.dll

PID
3120
CMD
C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding
Path
C:\Windows\explorer.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Windows Explorer
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\slc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\actxprxy.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\apphelp.dll
c:\program files\notepad++\notepad++.exe
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\mpr.dll

PID
3792
CMD
"C:\Program Files\Notepad++\notepad++.exe"
Path
C:\Program Files\Notepad++\notepad++.exe
Indicators
Parent process
explorer.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Don HO [email protected]
Description
Notepad++ : a free (GNU) source code editor
Version
7.58
Modules
Image
c:\program files\notepad++\notepad++.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\program files\notepad++\scilexer.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\propsys.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\program files\notepad++\updater\gup.exe
c:\windows\system32\windowscodecs.dll
c:\program files\notepad++\plugins\dspellcheck\dspellcheck.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\notepad++\plugins\mimetools\mimetools.dll
c:\program files\notepad++\plugins\nppconverter\nppconverter.dll
c:\program files\notepad++\plugins\nppexport\nppexport.dll

PID
2328
CMD
"C:\Program Files\Notepad++\updater\gup.exe" -v7.58
Path
C:\Program Files\Notepad++\updater\gup.exe
Indicators
Parent process
notepad++.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Don HO [email protected]
Description
WinGup for Notepad++
Version
5.02
Modules
Image
c:\program files\notepad++\updater\gup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\notepad++\updater\libcurl.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\schannel.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\users\admin\appdata\local\temp\npp.7.7.installer.exe
c:\windows\system32\mpr.dll

PID
2168
CMD
"C:\Program Files\Notepad++\notepad++.exe" "C:\Program Files\Notepad++\change.log"
Path
C:\Program Files\Notepad++\notepad++.exe
Indicators
Parent process
npp.7.5.8.Installer.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Don HO [email protected]
Description
Notepad++ : a free (GNU) source code editor
Version
7.58
Modules
Image
c:\program files\notepad++\notepad++.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\program files\notepad++\scilexer.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll

PID
3736
CMD
"C:\Users\admin\AppData\Local\Temp\npp.7.7.Installer.exe"
Path
C:\Users\admin\AppData\Local\Temp\npp.7.7.Installer.exe
Indicators
No indicators
Parent process
gup.exe
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
Don HO [email protected]
Description
Notepad++ : a free (GNU) source code editor
Version
7.7.0.0
Modules
Image
c:\users\admin\appdata\local\temp\npp.7.7.installer.exe
c:\systemroot\system32\ntdll.dll

PID
1512
CMD
"C:\Users\admin\AppData\Local\Temp\npp.7.7.Installer.exe"
Path
C:\Users\admin\AppData\Local\Temp\npp.7.7.Installer.exe
Indicators
Parent process
gup.exe
User
admin
Integrity Level
HIGH
Exit code
2
Version:
Company
Don HO [email protected]
Description
Notepad++ : a free (GNU) source code editor
Version
7.7.0.0
Modules
Image
c:\users\admin\appdata\local\temp\npp.7.7.installer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\version.dll
c:\windows\system32\shfolder.dll
c:\users\admin\appdata\local\temp\nsr8fc7.tmp\langdll.dll

Registry activity

Total events
1039
Read events
841
Write events
194
Delete events
4

Modification events

PID
Process
Operation
Key
Name
Value
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\notepad++.exe
C:\Program Files\Notepad++\notepad++.exe
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Notepad++
C:\Program Files\Notepad++
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
DisplayName
Notepad++ (32-bit x86)
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
Publisher
Notepad++ Team
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MajorVersion
7
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MinorVersion
58
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
UninstallString
C:\Program Files\Notepad++\uninstall.exe
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
DisplayIcon
C:\Program Files\Notepad++\notepad++.exe
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
DisplayVersion
7.5.8
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
URLInfoAbout
http://notepad-plus-plus.org/
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
VersionMajor
7
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
VersionMinor
58
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
NoModify
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
NoRepair
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
EstimatedSize
9795
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSectionUsed
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_C
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_C++
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Java
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_C#
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_HTML
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_RC
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_SQL
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_PHP
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_CSS
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_VB
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Perl
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_JavaScript
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Python
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_ActionScript
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_LISP
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_VHDL
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_TeX
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_DocBook
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_NSIS
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_CMAKE
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_BATCH
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_CoffeeScript
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_BaanC
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_NppExport
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_MimeTools
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Converter
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_DSpellCheck
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_AutoUpdater
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_afrikaans
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_albanian
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_arabic
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_aragonese
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_aranese
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_azerbaijani
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_basque
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_belarusian
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_bengali
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_bosnian
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_brazilian_portuguese
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_breton
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_bulgarian
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_catalan
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_chineseTraditional
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_chineseSimplified
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_corsican
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_croatian
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_czech
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_danish
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_dutch
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_english_customizable
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_esperanto
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_estonian
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_extremaduran
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_farsi
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_finnish
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_french
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_friulian
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_galician
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_georgian
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_german
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_greek
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_gujarati
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_hebrew
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_hindi
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_hungarian
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_indonesian
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_italian
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_japanese
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_kannada
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_kazakh
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_korean
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_kyrgyz
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_latvian
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_ligurian
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_lithuanian
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_luxembourgish
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_macedonian
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_malay
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_marathi
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_mongolian
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_norwegian
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_nynorsk
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_occitan
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_polish
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_portuguese
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_punjabi
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_romanian
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_russian
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_samogitian
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_sardinian
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_serbian
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_serbianCyrillic
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_sinhala
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_slovak
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_slovenian
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_spanish
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_spanish_ar
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_swedish
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_tagalog
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_tajik
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_tamil
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_tatar
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_telugu
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_thai
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_turkish
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_ukrainian
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_urdu
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_uyghur
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_uzbek
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_uzbekCyrillic
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_vietnamese
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_welsh
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_kurdish
0
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_BlackBoard
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Choco
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_HelloKitty
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_MonoIndustrial
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Monokai
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Obsidian
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_PlasticCodeWrap
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_RubyBlue
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Twilight
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_VibrantInk
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_DeepBlack
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_vimDarkBlue
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Bespin
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Zenburn
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Solarized
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Solarized-light
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_HotFudgeSundae
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_khaki
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_MossyLawn
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Navajo
1
2336
npp.7.5.8.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_explorerContextMenu
1
2116
regsvr32.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\ANotepad++
2116
regsvr32.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}\InprocServer32
2116
regsvr32.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}\Settings
2116
regsvr32.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}
2116
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}
ANotepad++
2116
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}\InprocServer32
C:\Program Files\Notepad++\NppShell_06.dll
2116
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}\InprocServer32
ThreadingModel
Apartment
2116
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}\Settings
Title
Edit with &Notepad++
2116
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}\Settings
Path
C:\Program Files\Notepad++\notepad++.exe
2116
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}\Settings
Custom
2116
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}\Settings
ShowIcon
1
2116
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}\Settings
Dynamic
1
2116
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}\Settings
Maxtext
25
2116
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\ANotepad++
{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}
3120
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3120
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3792
notepad++.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
LanguageList
en-US
3792
notepad++.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3792
notepad++.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2328
gup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2328
gup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2168
notepad++.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
LanguageList
en-US

Files activity

Executable files
17
Suspicious files
0
Text files
131
Unknown types
1

Dropped files

PID
Process
Filename
Type
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\LangDLL.dll
executable
MD5: f1e9eed02db3a822a7ddef0c724e5f1f
SHA256: 6dff504c6759c418c6635c9b25b8c91d0d9ef7787a3a93610d7670bb563c09df
2336
npp.7.5.8.Installer.exe
C:\Program Files\Notepad++\plugins\DSpellCheck\DSpellCheck.dll
executable
MD5: bddbafe3cda8c799a644bd53358f9b04
SHA256: 93e18b19305323780b42c262ccdf81eaa76be688c8d70b4e29e1b6eab7957347
2336
npp.7.5.8.Installer.exe
C:\Program Files\Notepad++\plugins\mimeTools\mimeTools.dll
executable
MD5: 90a5a4c5016e9c73982af7ebc2da2e99
SHA256: 27b988a933b45415c955e436e94c689c243cd0decd8e23186e30a05b0281d0c3
2336
npp.7.5.8.Installer.exe
C:\Program Files\Notepad++\plugins\NppConverter\NppConverter.dll
executable
MD5: 8791c2fbb9e265ceae7baeaad31d9bb6
SHA256: 20ec1957d2880be82e61b12fa82c7da026c373d73f54dda4fb48aa71259ef6a4
2336
npp.7.5.8.Installer.exe
C:\Program Files\Notepad++\updater\GUP.exe
executable
MD5: 270727aeb725ab590039ff446173c72e
SHA256: 4de511d4d600f7598d7a2307a19b88df54e7c075ceae5ab7e8d6ab31c2115420
2336
npp.7.5.8.Installer.exe
C:\Program Files\Notepad++\NppShell_06.dll
executable
MD5: 67a38421f331e99883125d459c95c48a
SHA256: b6b8a57fca55d12a379ce6e9e334cd0683b7a550aa84cd53fb2b9776707af903
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nsDialogs.dll
executable
MD5: 42b064366f780c1f298fa3cb3aeae260
SHA256: c13104552b8b553159f50f6e2ca45114493397a6fa4bf2cbb960c4a2bbd349ab
2336
npp.7.5.8.Installer.exe
C:\Program Files\Notepad++\uninstall.exe
executable
MD5: 2eeb93810d4578bda78633b258a50466
SHA256: 633acf3308c5263ee48c5eec51cc814822d0f57f2cd8c7787b9f62c977f4cd01
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\InstallOptions.dll
executable
MD5: 720304c57dcfa17751ed455b3bb9c10a
SHA256: 6486029d3939231bd9f10457fd9a5ab2e44f30315af443197a3347df4e18c4e9
2328
gup.exe
C:\Users\admin\AppData\Local\Temp\npp.7.7.Installer.exe
executable
MD5: 151cbb695037b5b1ca023dbb66655731
SHA256: f851e5cce9a1509f4e2c476ce5f7adf151d8f385afbcf448234b7f28fba28af9
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\UserInfo.dll
executable
MD5: 1b446b36f5b4022d50ffdc0cf567b24a
SHA256: 2862c7bc7f11715cebdea003564a0d70bf42b73451e2b672110e1392ec392922
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\System.dll
executable
MD5: 17ed1c86bd67e78ade4712be48a7d2bd
SHA256: bd046e6497b304e4ea4ab102cab2b1f94ce09bde0eebba4c59942a732679e4eb
2336
npp.7.5.8.Installer.exe
C:\Program Files\Notepad++\SciLexer.dll
executable
MD5: f1a032965e7c6939c112fa4786559d88
SHA256: 48f8a710fee7f5379422532dde39501607ecde7e21f57fe151bd95d4d7d0b874
2336
npp.7.5.8.Installer.exe
C:\Program Files\Notepad++\updater\libcurl.dll
executable
MD5: bc2c2e4574aef8b2272290a88e74f250
SHA256: d994ce79cfbdac5b6b6cb47b5df7c3ddf9c4352e7cbfa5782661a82a60e39841
2336
npp.7.5.8.Installer.exe
C:\Program Files\Notepad++\notepad++.exe
executable
MD5: 7c0531dc2c5911130e5d7de39b813766
SHA256: 02f2cee4118a8f8d732d736e1758a38abdceea6470ba63ea224ae56b27e4983c
1512
npp.7.7.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsr8FC7.tmp\LangDLL.dll
executable
MD5: ab1db56369412fe8476fefffd11e4cc0
SHA256: 6f14c8f01f50a30743dac68c5ac813451463dfb427eb4e35fcdfe2410e1a913b
2336
npp.7.5.8.Installer.exe
C:\Program Files\Notepad++\plugins\NppExport\NppExport.dll
executable
MD5: 224d4d92d76a931fb627e7e5136ecbc8
SHA256: 310b0f2339dcf3ac21a639af67462a4453ac81413333f8dbd6fe1c227b5682ef
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\vietnamese.xml
xml
MD5: 4648aecae4e9d1df3ca32d9a0cba8fed
SHA256: 747d88fd1df6f7a703fdd0904b50ff32c3d6d2d26203e0ae07b44786b44a9961
1512
npp.7.7.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsr8F78.tmp
––
MD5:  ––
SHA256:  ––
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\ukrainian.xml
xml
MD5: 9102b33a6d664028a4c8c99a6cec45ca
SHA256: 8f0adf8970d4a11b560e324e93047c945f055b964943a4e95ba2f1ff93d56d64
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\urdu.xml
xml
MD5: cf965dfcf2257d8046c453ac36fcf65e
SHA256: 0b685abaea6232f3e99d563f01613161251e51aba6a62d83cb306aa5f2d396d5
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\tatar.xml
xml
MD5: 84c32874e0fbc009202c86781cf6a6b6
SHA256: 0b20a37e6512a5a3e0c92075db9eb179a156e5e20f9fe52c3260daf8c77825a3
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\uzbek.xml
xml
MD5: b4d6eb9fd0045e43cfabe6fdba4c1656
SHA256: 2df0099a05be6af1ff13b2240b2b4e120746449d0e8356fa36888e9addd9c864
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\turkish.xml
xml
MD5: 3e02249ccf909b335cf9d3dcb2d36dcf
SHA256: ba72032741d193f8aad524d347f5c1b811e87748cdf3a30fc8275292d7e49a84
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\telugu.xml
xml
MD5: a8b6a302f3bda0eeae95e5214df33ec4
SHA256: 82b4b16ee06e668e4ff30e71fcbf42623cf30dc14177c570a7ad1f47c0284e0c
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\uyghur.xml
xml
MD5: a5d2661cab9fae284200b5cd84496b41
SHA256: f5d24a6c678b1b54539adeafd2bc2697738f44cea6c184fa442980f1440e5afd
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\thai.xml
xml
MD5: 8d02b72cdcce6c5a4db56eebba394824
SHA256: 8ce450bcfd9b9617f4e0969ad4e201480b255d473cb1383c90761cc28cbd7ecc
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\tamil.xml
xml
MD5: abc0ae5ed0002512221d682263e41204
SHA256: e23759fd6d60ef9728b620a1a8316fc049ccbf93445a91a1a85d27c4e25f3f15
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\tajikCyrillic.xml
xml
MD5: c28fc035726b0fe6f56c129d87c2aabc
SHA256: 70a7f699ee317a25cb74524995037b145477b4df0c39d674381ff5c8895fb63f
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\swedish.xml
xml
MD5: cce9f63a14d4793eb9f1287240e0d716
SHA256: 2cb752051ea9ec3222f14d59956ff3721f5ca311ae7f817d6334170382654491
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\spanish.xml
xml
MD5: cac9f105e4c1d2f704b46633737532ab
SHA256: 5daf95e46a387eed620776b61cf68b9f067cab25bc07e80ed79302bdda041885
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\russian.xml
xml
MD5: e870993777ecb9189259b5d1be2a154b
SHA256: 340a637ee8468d59d5742671dc36b59d60d4229e5a761405a9f00685a24394ed
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\slovak.xml
xml
MD5: ca1e10908e6f414d8f18d8508c0a9f5c
SHA256: f19578e68f7546542331e30421ba384268979d9961ca4a39d7491b50581e491e
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\spanish_ar.xml
xml
MD5: e6e44ee7c6b6a0ff89f0fe490f3c11fc
SHA256: 2fadeca7c44132ef9a9243bd67eee23c93a25f96bc6c80b81d527d18128d284d
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\sardinian.xml
xml
MD5: 064889342004d04b1de62578aa733216
SHA256: 0169ebd43b3cec4a4f3b0143a2af6f07ec9bf73cb04882a3d4507f01931c08de
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\serbian.xml
xml
MD5: 174e7dc367ff1c213432b891f11d25bb
SHA256: 1a07c6a9c2639fa12bb000f599498ddf84827449afbb7952f4bdc4cf526c2117
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\slovenian.xml
xml
MD5: cfa148c41f87a5877bd41c932d1fa9ee
SHA256: 5264e700e193129c25f864874ae69f89439a04517b1e7a30233bb70073f5eac3
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\tagalog.xml
xml
MD5: 04e3e27d9d635c6b23c8e40dcbbdd442
SHA256: 047c63c449c5e2a9a4f97637c741eb07e6ec034bc829d85c6565bb0292c1cd72
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\sinhala.xml
xml
MD5: 9986ce0334af5335ae8c7e5a3cbc818b
SHA256: a8b55a8115a50bd3b7b07c359c49fe7da48a5acf1dacc2c0e3708f6f48636fd6
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\serbianCyrillic.xml
xml
MD5: e6c94316e6d065533305b94e7d5af2bc
SHA256: 289d7cdd9d9af5b2992e3b0ac38022f91e3d9dc0051e40733983e26e2ddcf594
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\samogitian.xml
xml
MD5: ebba131558f344afe63e1c5718d0f7ad
SHA256: 75eca9974de1fca41651975a92f374660e1a7c273a3d1dab0ef6dd573230878b
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\punjabi.xml
xml
MD5: 1b2298a7b847f23751010f2b01e7a2ab
SHA256: e3e009b986ed53654ea1c89d828ba3998039db4fae20a877f097e41a2ebb7771
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\romanian.xml
xml
MD5: 36e13b9ab8934f1e450ad10ab2586d25
SHA256: 9f5bd9fedff4532133a72cb689ce81094d5df306ed6ffdc5eefb63fdbf5ff28a
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\occitan.xml
xml
MD5: 5901057d84d593c248767b2e3313333e
SHA256: 5911f8aebcc370908ce4da08a63e6bb121c69e6731dca4d24924e4e4a0c9043f
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\portuguese.xml
xml
MD5: addf2eb5903015e8c9f3bb8bf1051920
SHA256: 50b0cb311e6dc3bef2341d785d1e54d251f138c9ec552e7d79504e5f75824fed
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\polish.xml
xml
MD5: c8e5df9393988479ccb2109b62fd1ed2
SHA256: 0d06d7a096837c419d664500ad79a132c05b3452cd4e8bb485d19846f07aaa01
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\norwegian.xml
xml
MD5: f5519b853316445aab668c1dfd480f87
SHA256: bb9a79755d37d449acff570c20e78a9e0c58482414435cf0f493e15e6216fce3
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\lithuanian.xml
xml
MD5: f5d3607678cf5229eba71c618dfca8d4
SHA256: 58132f1693eb27ea700112af1994dee954fcf31bf03f82b9a9e6ab9ee3396ef4
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\marathi.xml
xml
MD5: 40a6d310ece1419315c5e98fa1bcc966
SHA256: 907b949d2aa52365d84978a3c131bd2bad50227e6ecfd135ed112a8567628e25
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\malay.xml
text
MD5: 3158e10e8a9b3c0e84a770f5f11aaa1f
SHA256: 690416e418c9821bfe71805f76d9e18ee39fd092742d173cc9fe595268b131fa
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\nynorsk.xml
xml
MD5: 694867a6ade700da42a55da24da74200
SHA256: 319a9e846a610811fdf12b96bf352e4e07f2d7de5a6bec3000cebc1b1e21a1fe
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\mongolian.xml
xml
MD5: 7ff28b9242fe6bd774fcd71fbed5563d
SHA256: 5d35c3c2f10b6f6923c0b11bd7d82f569ba6a0a8fb854aac20988c77d35bf934
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\macedonian.xml
xml
MD5: 59f590ee75294f37ccb5ed1c7a441a11
SHA256: 59dbcc4618fa64eebd71808b16b4736b7af8855bef760aec3eb31c6f8f5f470e
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\luxembourgish.xml
xml
MD5: cc2d7d26c9d221def534845ec7453ddb
SHA256: b73cb0703537af9d58c2e1f040f2e7f741199eef954d5e109eb301fc4498ffe0
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\latvian.xml
xml
MD5: 170d9e9a92a604a309259d3d6f3b9bb6
SHA256: bbaa6bc087ab351b182d204a60eab8bc93bd5e75ca2a4a4eaf80b1d5e0fec59b
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\japanese.xml
xml
MD5: 60b4b336b0417174a31606759c94c7ae
SHA256: d8195467b44d2ed48c836944a9a8321417c3cf7707fd1b9ff83a40d69b15b3f8
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\kazakh.xml
xml
MD5: 42d3d22d81645a44258aa730177896db
SHA256: 3942e9c344acae7caa9d28a758b4df80c1211bab80ac88d81449101f9b943c66
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\korean.xml
xml
MD5: a81c00ae49aeb5c5ded60220e6e42199
SHA256: 50b2b6820683551838ea1533d21624dac75daded6ce9d4227153a4f2986cdf4d
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\indonesian.xml
xml
MD5: 94f61a217b291de80f1356e4f7eb3ca5
SHA256: feffb87431d1aaf1b0af69d60551400ec2b7880d0d0015bd3e9938af901f262b
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\kannada.xml
xml
MD5: f0baf174376d1811fd49d05ace8eb0c6
SHA256: 99f75ff79aad8084802bf1d52e7dc78eef18194d399c5248eb205db85348955d
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\italian.xml
xml
MD5: a13e9147e00feebc23921c36fa523a7f
SHA256: 83e1ef73bf1489e2bc77818279391d643b7a6adfb7411b067e38f60662b6a983
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\kurdish.xml
xml
MD5: fb02f42520e6bf27d1aac8177b9e74eb
SHA256: 945844b4982f578fb334f7fd60b177bf7d27c9daf9cf763bc62a8b960733c27f
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\kyrgyz.xml
xml
MD5: ad3a31d477ad1e09dc3f6911c1f50d1e
SHA256: 4964c0b9f36b7fec44ec0805ba153d88293311cd703680719187cdaa68fbd090
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\kabyle.xml
xml
MD5: ec924dd39f1e36164ef4e93cd5883a2d
SHA256: 56714b11409a13fcd706f2d73674919a0bb70c80c7ec18eccf865ad67ad7b48f
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\ligurian.xml
xml
MD5: 58a86031153e6bd8ae1ad5bf80fcc894
SHA256: 5fad85ea1c785dca218106e2b409c20b3cb103e8cdc87c542aae5d630599c33b
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\estonian.xml
xml
MD5: a12e2854f772938fd4ccd55345dadd4b
SHA256: f71e4b0ba4fbf616af8f1568f2160d527b78fcf711132c4a38e0bd5378902237
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\farsi.xml
xml
MD5: 9ddc0ac1e17a56703a3e0a7acb8d0e2a
SHA256: d0acda01c7bb500072f00af882297d08a14821811931e862b5225bef97ab6336
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\french.xml
xml
MD5: 3009747c987a369b3714ccae2c5a18c7
SHA256: 1432765916d4dbb9238568d3372af20bfe3e485011ff863f5741507cd861e278
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\hungarian.xml
xml
MD5: 431cf09a81d8fcef9afc5c07c7efe9f0
SHA256: 54feb64aa105042c81d9fae8acffc4ff9c2e274956d0eca2fa407445c5b46d80
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\gujarati.xml
xml
MD5: 5e8d9609900189b29b660d673a78e015
SHA256: 50c0e7a18c922bef1a758cff70d55df46913dddc22ca792e1b55b05a5b29c502
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\georgian.xml
xml
MD5: cada78594c9838103c479dbda55c9e05
SHA256: b319b96cb4eece88c0cf88b557ce56ce5abe85bdf0a6a1007b64310a708a6572
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\galician.xml
xml
MD5: 191cc6b7ed37fad274f985d7329bd048
SHA256: 89a20e547d17b1006698cd35fbad772403033420808c8299206a8e299961d83e
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\friulian.xml
xml
MD5: 6d4c069b4c4517f68657be1641bec299
SHA256: d4ffe0a2b5e35fede7e6244be9823e1e946c60db1635e6d3f753e6df938e4b3d
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\hindi.xml
xml
MD5: 9e98d9dce1ee4c6baf474ce4d12d8c85
SHA256: fc7b065059bb2d5f0a46b1128e76e54da4ce6df76e486d156d331fc612a19c2b
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\german.xml
xml
MD5: 223d1124535ab07812f1becbf3a2fd8e
SHA256: bce84469219e6da4db6d72a3a31bb2ff77d6ba1ececeb3ece5a275ced7426252
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\extremaduran.xml
xml
MD5: 896b0f1f0854f3bcc23a80c99dcebd47
SHA256: 87e0372bfd2b84316adf2c7d3130fcf2415a96ec2c8bcd5da6f1a8a3a807c8d2
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\greek.xml
xml
MD5: 109f64488a006665d76621dcd30e7ef7
SHA256: d65afc086673dc165ce82dd831b5f04c75d7d43c50957475e1c90f25766ad5da
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\hebrew.xml
xml
MD5: f4b4fe91286ea03cf8a74d429fc68682
SHA256: c7ffa68dcb4d3b15b6e0c998ca04af934fc09f75d2912b37aeb2be954c2de819
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\finnish.xml
xml
MD5: 99d18eeaa47569147a0395948cb9c7d6
SHA256: 691d523b2a8c2ea14eb5e5259eed9e9de1853b2c2fd8badc77164f2cca2dd006
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\english_customizable.xml
xml
MD5: 7907d1d7f539f1673e0401ae991ef2d1
SHA256: f43ba26f4cb3b94e050cf25899d47b0ed1686e55dac50b174fb767697c961f53
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\chinese.xml
xml
MD5: a175be84dc2ab0fadf783503665cd092
SHA256: 57573db7f00c1c45951b2e78fba43d0d581b1cbbb7baed54b7b44a7664e11efe
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\danish.xml
xml
MD5: da48f74dfed6119dc64d9d86312b6c68
SHA256: b017ecc186ac7857c8c047641ea4fb64447f1290d6f7c9d67b94ad42e4763dd3
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\catalan.xml
xml
MD5: 4cfdbb42342e0cb4f7805ef9ed3eaa96
SHA256: 19f5a0612e2e20b366717bb72f027c256623d2fe14ac2b440587ef119b9cfe54
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\esperanto.xml
xml
MD5: 4abf56d03e149ee0569619bbc11815a5
SHA256: e1486a8120d1ef7998b5335536a3a4877fdcb630f87ed9ca7b307ac075b313c6
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\corsican.xml
xml
MD5: f29edacce323826fea39355f5ca5a909
SHA256: fbe4f496403c7273b27299416d389ff93b293579404009ff6f9a8578af60a850
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\chineseSimplified.xml
xml
MD5: c293d38fb45e8619f44c92b038f509ed
SHA256: 6738543bb14f3881bed4a3be4e9dbf16121bfe7997b19831ee426af6f5c5f676
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\dutch.xml
xml
MD5: 00f9fa31ff06ce8368d8c1f6bbf6050e
SHA256: f2541183621fc961dadd7b241bbb08a0db25be7d163c6a8dd8bf0c9287ff3f85
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\english.xml
xml
MD5: f9bc106659df7679206e97c799b24236
SHA256: edde472f2bd05abfe9203eec0ed180313dce3d0427f5e729d9029b47cee29a02
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\croatian.xml
xml
MD5: 93e193e4ba3b43a8ee9f448819f9fc02
SHA256: 3a1c365a7a66dae03b9d2dc5b2368647ddea54fb1978b5d014fa71464d9ce9c9
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\czech.xml
xml
MD5: 6b2c3ce1ae242cf4cc8955601e6fbb00
SHA256: 1fb66468ade45781952a239596a805f015a358166324330b1db7ddebdaa3ec92
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\breton.xml
xml
MD5: a28d31b3147d47670455aa249df9e3a8
SHA256: 7d8569dca0eef5ccd411287ed72f70da19f92b96e05e2bfd294263098e3ed38d
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\bulgarian.xml
xml
MD5: 72d9773c8d8bd5f612d5704b97568cbe
SHA256: 292a7134364385337b1c60c4f58a449a223a04ad6bc10cdd218e23307a8e9285
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\belarusian.xml
xml
MD5: a14648bcdbe2186853046bc8e00df14f
SHA256: 669d2685f71c0dd3c0203cb205dfa725793bc93a8695688ca749090e87fec8ce
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\bosnian.xml
xml
MD5: 6b036835ed9d1ee92cd9bd4c76f41bbd
SHA256: 06ce39e85fc9acd72888da5871fae4d18aa2c5bb6a9fa0c9eca459cf0e949a63
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\brazilian_portuguese.xml
xml
MD5: c552ae4040c081abb56f8d01d5e3865e
SHA256: 4888bc8c1a756932055a83528715eec1cb6f3ede9074c325796a9f81f8a9349d
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\basque.xml
xml
MD5: 7ef1dd1b3280122bac0a69063249fd46
SHA256: 1047a56b9ea18bafbb7fd03daa190cb980883694dfd7fc1556136ab81834d489
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\aranese.xml
xml
MD5: 333a18acb93ba083e86679c065b69d15
SHA256: de5da809aa6e44c4e6a01c3b5fb7da5a66d9683cb905416f3fcff2ed413ea7c6
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\azerbaijani.xml
xml
MD5: 8cd5c70b03ef9c48585c06fa149f9fcd
SHA256: d2e185e9c8b1e7d994dcb3b44748f1b499f18ca22a573f452a9b0d791344c448
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\bengali.xml
xml
MD5: d081b39bf7a87b8ccd3caa5e9d15087c
SHA256: 5ecd5febabcb4b4616035fab1b567bf2a0ff8b2ded72d74e6ea5511671814484
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\aragonese.xml
xml
MD5: ff161db746ade330439882ba0640d2ea
SHA256: 1db8eeb9c6cae8705cacfc3043a7556678e9ed52162fb8ec536c5befc19343a9
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\arabic.xml
xml
MD5: 560a2986ce1a7528b2b22cc22c6babe8
SHA256: ed00a2cc8c9e513eeda79a30452a9090c76d005328034539f4fb0474cee2f5ae
3792
notepad++.exe
C:\Users\admin\AppData\Roaming\Notepad++\plugins\Config\converter.ini
text
MD5: f70f579156c93b097e656caba577a5c9
SHA256: b926498a19ca95dc28964b7336e5847107dd3c0f52c85195c135d9dd6ca402d4
2336
npp.7.5.8.Installer.exe
C:\Program Files\Notepad++\localization\english.xml
xml
MD5: f9bc106659df7679206e97c799b24236
SHA256: edde472f2bd05abfe9203eec0ed180313dce3d0427f5e729d9029b47cee29a02
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\albanian.xml
xml
MD5: 5803d49d9a1320f50394a0ab36c427b6
SHA256: 508ddd0bd359666186a34b1249b55de31062f2eb4323bce01409e602e7fc0b64
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\ioSpecial.ini
––
MD5:  ––
SHA256:  ––
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\afrikaans.xml
xml
MD5: c2f475cc2b49d3aee490c9059529744a
SHA256: 5d285d98f8891bcf73a770fde00c3215062842224b81c4e70537569712f84570
2336
npp.7.5.8.Installer.exe
C:\Program Files\Notepad++\langs.model.xml
xml
MD5: 529f7c3cd358f72165272916cd750289
SHA256: c837409af3caa67bbac8b8260e6dc901a4d71f836b2ae19d055c712a19d0ee09
2336
npp.7.5.8.Installer.exe
C:\Program Files\Notepad++\readme.txt
text
MD5: 5c52adcd2bcc000a8b4bd5eb36b84cde
SHA256: f09758a2c953bdd2b817441e9a00255d3685c99369468c2695f0ca39aaaa5e6b
2336
npp.7.5.8.Installer.exe
C:\Program Files\Notepad++\contextMenu.xml
xml
MD5: a7998766b85ee71ff1d82a1198988529
SHA256: aa48a7c2ec3ed377c42c293f732807572f2ea305c9771b6ea210e7b92ef2c199
2336
npp.7.5.8.Installer.exe
C:\Program Files\Notepad++\change.log
text
MD5: bc0383eb643ffbd8f5cfad626689075d
SHA256: 09386e5700f02cff50661d95e20cd2ad57b1a75be2780fa7b654a4df7d9d2856
2336
npp.7.5.8.Installer.exe
C:\Program Files\Notepad++\stylers.model.xml
xml
MD5: 1f82bc911135cf39eb254a90be6c449c
SHA256: 5572e6249ccefe33b40c444dd5c9282aaf6416683b21bfc2d5df79b621d3ad03
2336
npp.7.5.8.Installer.exe
C:\Program Files\Notepad++\functionList.xml
xml
MD5: bd8d804a62a5b9392885a6904033f0bf
SHA256: ea1e92c06735a137cd03c36a252027c013e9224dd3013fbe3ddd5c5c0098b2b9
2336
npp.7.5.8.Installer.exe
C:\Program Files\Notepad++\updater\README.md
text
MD5: 9f56b12cbffcfad543fb1f91e3955f1b
SHA256: aef40520cf12a0842097e8cfbeb9d9128f52573e5f90ca12d4a0a9045978547e
2336
npp.7.5.8.Installer.exe
C:\Program Files\Notepad++\LICENSE
text
MD5: 397ad6fd5743ecc1826add6ea0fb0af4
SHA256: b2a74140769dc8bd34cb72bd2d177e58522e69427f39651b738011f244f835bd
3792
notepad++.exe
C:\Users\admin\AppData\Roaming\Notepad++\shortcuts.xml
text
MD5: ad21a64014891793dd9b21d835278f36
SHA256: c24699c9d00abdd510140fe1b2ace97bfc70d8b21bf3462ded85afc4f73fe52f
2336
npp.7.5.8.Installer.exe
C:\Program Files\Notepad++\updater\gup.xml
xml
MD5: b023cc4d768b34a5401f317479740a53
SHA256: d3e6404c7286961cbab82d4c49f82bcb166db9b5a13eacaa0eeb59a0709a0c14
2336
npp.7.5.8.Installer.exe
C:\Program Files\Notepad++\updater\LICENSE
text
MD5: 8e3494bf8cf1967afd3b1016fbbe5bb0
SHA256: 319917f5ccd09878db6f67c9a77dee846055644ca49eb535628b9e020a87261e
3792
notepad++.exe
C:\Users\admin\AppData\Roaming\Notepad++\stylers.xml
xml
MD5: 1f82bc911135cf39eb254a90be6c449c
SHA256: 5572e6249ccefe33b40c444dd5c9282aaf6416683b21bfc2d5df79b621d3ad03
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Roaming\Notepad++\plugins\Config\DSpellCheck.ini
text
MD5: 110639e14988e997205bbaac203be8ed
SHA256: 5c449851138a2b0586bce3c7377b890180ce56d8d05cea0978edbfdf40871637
2336
npp.7.5.8.Installer.exe
C:\Program Files\Notepad++\plugins\Config\Hunspell\en_US.dic
text
MD5: 2f6e098411997f3d1217865bb468947f
SHA256: b88263b1637b124d516dd3518a83a19e91dc73db6bf30d05e3aceb30e6ff4604
3792
notepad++.exe
C:\Users\admin\AppData\Roaming\Notepad++\langs.xml
xml
MD5: 529f7c3cd358f72165272916cd750289
SHA256: c837409af3caa67bbac8b8260e6dc901a4d71f836b2ae19d055c712a19d0ee09
2336
npp.7.5.8.Installer.exe
C:\Program Files\Notepad++\plugins\Config\Hunspell\en_US.aff
text
MD5: ff0059b0644df7008c9f635f77da7601
SHA256: 1d1a827ce91d9eb061d5954ba325f8a538b386bd70704af431fbaac1c8e9623a
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\ioSpecial.ini
text
MD5: adaa38865242e48e08a78b50c368cfbb
SHA256: 75ed0e85c3c16df843e9dce51d6e9273b58f163988329870b94cf2eaa729129e
3792
notepad++.exe
C:\Users\admin\AppData\Roaming\Notepad++\session.xml
text
MD5: ba80c732becf667973ceb1565b782cf7
SHA256: 817f4b0a1f9e63ffc08d5ef009ead55b6b279e09f1b95fd0b2a103a0ab28d2ca
2336
npp.7.5.8.Installer.exe
C:\Program Files\Notepad++\plugins\APIs\BaanC.xml
xml
MD5: 2537a01a4619a19962fb1b85cbee9a13
SHA256: 9780d21f36eca4cb7f85c67fe9113c3c223822662812f6ab533c011cd2f56e7e
2336
npp.7.5.8.Installer.exe
C:\Program Files\Notepad++\plugins\APIs\coffee.xml
xml
MD5: 633f1e56a9f5b7e1c7c75e6dff944b25
SHA256: 46d379e7ad5565fc197a32b62d04ceb1be4452af2ae45663415809bc7badb0bd
3792
notepad++.exe
C:\Users\admin\AppData\Roaming\Notepad++\config.xml
xml
MD5: d32c8d0c87cf4b366270a68bc5f967df
SHA256: d6bd231be92761a51e45fe64b5dbc935a98aac55f4c7543e278be8d1dab3ff10
2336
npp.7.5.8.Installer.exe
C:\Program Files\Notepad++\plugins\APIs\batch.xml
xml
MD5: 713831a4916810500b39efbdb41435a2
SHA256: d43ce011aa2d5a946c36b4c3a6a0a98fd9570253bc461a267d3b44aaec3cb6b0
2336
npp.7.5.8.Installer.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++.lnk
lnk
MD5: 4b8a47442f76ea601fac18bfb9ce1181
SHA256: 0b1ee44bff6f405cf14af878906d497c0a5bf6dc0479132dd6c35ddbfd7148bd
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\ioSpecial.ini
text
MD5: 82da278d54f4026c8750eb7dc3b4acb0
SHA256: 35cbdc56de081643ac5b776ef34f24efeb561900c7a2d687672d1858b5a2fa94
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\ioSpecial.ini
text
MD5: 105054a5e575b90f6c324a1a41e00517
SHA256: 399da7f620df73aad91d2b9410c8359dcf715bda12e3b824c6626525771e65e9
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\modern-wizard.bmp
image
MD5: c2cf6928a3ab574a5548b4dc1c38b6c0
SHA256: 2125550c12fa512782f2016e802d70bc51f4a06017cfbd4176b4a994eb2542f0
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\modern-header.bmp
image
MD5: 56da15fdb8d96f8f5c649dcb5e79d775
SHA256: bb90d4338d2474138473e6b16e94b0237ee847bea45019ed0dd4439c71bd233e
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\uzbekCyrillic.xml
xml
MD5: 71b7ce4804f337f3d5c4fea4a0733691
SHA256: 380e17fd360658921ea937043e540b2af642a7307be691f5c58b825623b61a99
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nst16ED.tmp\nppLocalization\welsh.xml
xml
MD5: 538acafd2ef4e67581a908f970838626
SHA256: 11fd56a75e14493a7305d6cd2aa79dd6990465eb0dec8bdf6354dd6e5db35634
2336
npp.7.5.8.Installer.exe
C:\Users\admin\AppData\Local\Temp\nso16CD.tmp
––
MD5:  ––
SHA256:  ––

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
1
Threats
0

HTTP requests

No HTTP requests.

Connections

PID Process IP ASN CN Reputation
2328 gup.exe 37.59.28.236:443 OVH SAS FR whitelisted

DNS requests

Domain IP Reputation
notepad-plus-plus.org 37.59.28.236
whitelisted

Threats

No threats detected.

Debug output strings

Process Message
notepad++.exe 42C4C5846BB675C74E2B2C90C69AB44366401093
notepad++.exe 42C4C5846BB675C74E2B2C90C69AB44366401093
notepad++.exe 42C4C5846BB675C74E2B2C90C69AB44366401093
notepad++.exe 42C4C5846BB675C74E2B2C90C69AB44366401093
notepad++.exe 42C4C5846BB675C74E2B2C90C69AB44366401093
notepad++.exe 42C4C5846BB675C74E2B2C90C69AB44366401093