General Info Watch the FULL Interactive Analysis at ANY.RUN!

File name

FileOpenInstaller.exe

Verdict
Malicious activity
Analysis date
1/11/2019, 14:52:22
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

2f11564d98b6fa9800fbca140cefa32e

SHA1

710acb3e260acdb2f5694aab9ad231821f9e0753

SHA256

65938403b4547f047093b52fb8705a17bb29994e613004664e14e0e12ec40f46

SSDEEP

49152:1nM59EYit7P82ySoCOvDRiCMB8/dZR3+w9NLtcM24VcxAsjiTnLOklz+DaelRj9B:C9wo2y/CIwCKadHxLnyxqTJz+Dael5cc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Application was dropped or rewritten from another process
  • FileOpenBroker32.exe (PID: 2516)
  • FileOpenManager32.exe (PID: 3896)
Changes the autorun value in the registry
  • FileOpenInstaller.tmp (PID: 3016)
Creates files in the user directory
  • FileOpenBroker32.exe (PID: 2516)
Creates or modifies windows services
  • FileOpenManager32.exe (PID: 3896)
Executable content was dropped or overwritten
  • FileOpenInstaller.tmp (PID: 3016)
  • FileOpenInstaller.exe (PID: 2440)
  • FileOpenInstaller.exe (PID: 3168)
Reads Windows owner or organization settings
  • FileOpenInstaller.tmp (PID: 3016)
Reads the Windows organization settings
  • FileOpenInstaller.tmp (PID: 3016)
Starts SC.EXE for service management
  • FileOpenInstaller.tmp (PID: 3016)
Application launched itself
  • AcroRd32.exe (PID: 3384)
  • RdrCEF.exe (PID: 3460)
Creates files in the user directory
  • AcroRd32.exe (PID: 3384)
Creates files in the program directory
  • FileOpenInstaller.tmp (PID: 3016)
Creates a software uninstall entry
  • FileOpenInstaller.tmp (PID: 3016)
Application was dropped or rewritten from another process
  • FileOpenInstaller.tmp (PID: 4088)
  • FileOpenInstaller.tmp (PID: 3016)
Loads dropped or rewritten executable
  • FileOpenInstaller.tmp (PID: 3016)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable Delphi generic (45.2%)
.dll
|   Win32 Dynamic Link Library (generic) (20.9%)
.exe
|   Win32 Executable (generic) (14.3%)
.exe
|   Win16/32 Executable Delphi generic (6.6%)
.exe
|   Generic Win/DOS Executable (6.3%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2016:04:06 16:39:04+02:00
PEType:
PE32
LinkerVersion:
2.25
CodeSize:
66560
InitializedDataSize:
63488
UninitializedDataSize:
null
EntryPoint:
0x117dc
OSVersion:
5
ImageVersion:
6
SubsystemVersion:
5
Subsystem:
Windows GUI
FileVersionNumber:
1.0.84.979
ProductVersionNumber:
1.0.84.979
FileFlagsMask:
0x003f
FileFlags:
(none)
FileOS:
Win32
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
Neutral
CharacterSet:
Unicode
Comments:
This installation was built with Inno Setup.
CompanyName:
FileOpen Systems, Inc.
FileDescription:
{cm:FileOpenClient} B979
FileVersion:
1.0.84.979
LegalCopyright:
© 2012-2017 FileOpen Systems, Inc.
ProductName:
{cm:FileOpenClient} B979
ProductVersion:
B979
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
06-Apr-2016 14:39:04
Detected languages
English - United States
Comments:
This installation was built with Inno Setup.
CompanyName:
FileOpen Systems, Inc.
FileDescription:
{cm:FileOpenClient} B979
FileVersion:
1.0.84.979
LegalCopyright:
© 2012-2017 FileOpen Systems, Inc.
ProductName:
{cm:FileOpenClient} B979
ProductVersion:
B979
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0050
Pages in file:
0x0002
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x000F
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x001A
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x00000100
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
8
Time date stamp:
06-Apr-2016 14:39:04
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x0000F244 0x0000F400 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.37521
.itext 0x00011000 0x00000F64 0x00001000 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 5.7322
.data 0x00012000 0x00000C88 0x00000E00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 2.29672
.bss 0x00013000 0x000056BC 0x00000000 IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.idata 0x00019000 0x00000E04 0x00001000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 4.59781
.tls 0x0001A000 0x00000008 0x00000000 IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.rdata 0x0001B000 0x00000018 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 0.204488
.rsrc 0x0001C000 0x0000D788 0x0000D800 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 4.11125
Resources
1

4091

4092

4093

4094

4095

4096

11111

CHARTABLE

DVCLAL

PACKAGEINFO

MAINICON

Imports
    oleaut32.dll

    advapi32.dll

    user32.dll

    kernel32.dll

    comctl32.dll

Exports

    No exports.

Screenshots

Processes

Total processes
49
Monitored processes
14
Malicious processes
2
Suspicious processes
3

Behavior graph

+
drop and start start drop and start fileopeninstaller.exe fileopeninstaller.tmp no specs fileopeninstaller.exe fileopeninstaller.tmp sc.exe no specs sc.exe no specs sc.exe no specs fileopenmanager32.exe no specs fileopenbroker32.exe acrord32.exe no specs acrord32.exe no specs rdrcef.exe no specs rdrcef.exe no specs rdrcef.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3168
CMD
"C:\Users\admin\AppData\Local\Temp\FileOpenInstaller.exe"
Path
C:\Users\admin\AppData\Local\Temp\FileOpenInstaller.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
FileOpen Systems, Inc.
Description
{cm:FileOpenClient} B979
Version
1.0.84.979
Modules
Image
c:\users\admin\appdata\local\temp\fileopeninstaller.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\version.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\shell32.dll
c:\users\admin\appdata\local\temp\is-0o2a1.tmp\fileopeninstaller.tmp

PID
4088
CMD
"C:\Users\admin\AppData\Local\Temp\is-0O2A1.tmp\FileOpenInstaller.tmp" /SL5="$2011C,2952596,131072,C:\Users\admin\AppData\Local\Temp\FileOpenInstaller.exe"
Path
C:\Users\admin\AppData\Local\Temp\is-0O2A1.tmp\FileOpenInstaller.tmp
Indicators
No indicators
Parent process
FileOpenInstaller.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\users\admin\appdata\local\temp\is-0o2a1.tmp\fileopeninstaller.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shdocvw.dll
c:\program files\fileopen\services\fileopenbroker32.exe

PID
2440
CMD
"C:\Users\admin\AppData\Local\Temp\FileOpenInstaller.exe" /SPAWNWND=$20116 /NOTIFYWND=$2011C
Path
C:\Users\admin\AppData\Local\Temp\FileOpenInstaller.exe
Indicators
Parent process
FileOpenInstaller.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
FileOpen Systems, Inc.
Description
{cm:FileOpenClient} B979
Version
1.0.84.979
Modules
Image
c:\users\admin\appdata\local\temp\fileopeninstaller.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\version.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\shell32.dll
c:\users\admin\appdata\local\temp\is-soejc.tmp\fileopeninstaller.tmp

PID
3016
CMD
"C:\Users\admin\AppData\Local\Temp\is-SOEJC.tmp\FileOpenInstaller.tmp" /SL5="$20120,2952596,131072,C:\Users\admin\AppData\Local\Temp\FileOpenInstaller.exe" /SPAWNWND=$20116 /NOTIFYWND=$2011C
Path
C:\Users\admin\AppData\Local\Temp\is-SOEJC.tmp\FileOpenInstaller.tmp
Indicators
Parent process
FileOpenInstaller.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\users\admin\appdata\local\temp\is-soejc.tmp\fileopeninstaller.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\bcryptprimitives.dll
c:\users\admin\appdata\local\temp\is-vdcbj.tmp\utildll.dll
c:\windows\system32\psapi.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\program files\adobe\acrobat reader dc\reader\acrord32.exe
c:\windows\system32\imageres.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\msftedit.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll

PID
2444
CMD
"C:\Windows\system32\sc.exe" create FileOpenManager binpath= "\"C:\Program Files\FileOpen\Services\FileOpenManager32.exe\"" start= auto
Path
C:\Windows\system32\sc.exe
Indicators
No indicators
Parent process
FileOpenInstaller.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
A tool to aid in developing services for WindowsNT
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\sc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll

PID
1964
CMD
"C:\Windows\system32\sc.exe" description FileOpenManager "FileOpen Client Manager"
Path
C:\Windows\system32\sc.exe
Indicators
No indicators
Parent process
FileOpenInstaller.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
A tool to aid in developing services for WindowsNT
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\sc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll

PID
3496
CMD
"C:\Windows\system32\sc.exe" start FileOpenManager
Path
C:\Windows\system32\sc.exe
Indicators
No indicators
Parent process
FileOpenInstaller.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
A tool to aid in developing services for WindowsNT
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\sc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll

PID
3896
CMD
"C:\Program Files\FileOpen\Services\FileOpenManager32.exe"
Path
C:\Program Files\FileOpen\Services\FileOpenManager32.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
FileOpen Systems Inc.
Description
FileOpen Client - Manager Service
Version
1.9.7.1
Modules
Image
c:\program files\fileopen\services\fileopenmanager32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll

PID
2516
CMD
"C:\Program Files\FileOpen\Services\FileOpenBroker32.exe"
Path
C:\Program Files\FileOpen\Services\FileOpenBroker32.exe
Indicators
Parent process
FileOpenInstaller.tmp
User
admin
Integrity Level
MEDIUM
Version:
Company
FileOpen Systems Inc.
Description
FileOpen Client - Broker
Version
1.9.7.9
Modules
Image
c:\program files\fileopen\services\fileopenbroker32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wininet.dll
c:\windows\system32\nsi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\winspool.drv
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\profapi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\version.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\gpapi.dll

PID
3384
CMD
"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" installcomplete.pdf
Path
C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe
Indicators
No indicators
Parent process
FileOpenInstaller.tmp
User
admin
Integrity Level
MEDIUM
Exit code
1
Version:
Company
Adobe Systems Incorporated
Description
Adobe Acrobat Reader DC
Version
15.23.20070.215641
Modules
Image
c:\windows\system32\version.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msutb.dll
c:\windows\system32\msctf.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\winsta.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\user32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\kernelbase.dll
c:\systemroot\system32\ntdll.dll
c:\program files\adobe\acrobat reader dc\reader\acrord32.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\imm32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\ole32.dll
c:\windows\system32\mpr.dll
c:\windows\system32\kbdus.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\adobe\acrobat reader dc\reader\acrocef\rdrcef.exe

PID
3100
CMD
"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe" --type=renderer installcomplete.pdf
Path
C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe
Indicators
No indicators
Parent process
AcroRd32.exe
User
admin
Integrity Level
LOW
Exit code
1
Version:
Company
Adobe Systems Incorporated
Description
Adobe Acrobat Reader DC
Version
15.23.20070.215641
Modules
Image
c:\program files\adobe\acrobat reader dc\reader\acrord32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\shell32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\program files\adobe\acrobat reader dc\reader\acrord32.dll
c:\program files\adobe\acrobat reader dc\reader\agm.dll
c:\windows\system32\msvcp120.dll
c:\windows\system32\msvcr120.dll
c:\windows\system32\version.dll
c:\program files\adobe\acrobat reader dc\reader\bib.dll
c:\program files\adobe\acrobat reader dc\reader\cooltype.dll
c:\program files\adobe\acrobat reader dc\reader\ace.dll
c:\windows\system32\profapi.dll
c:\program files\adobe\acrobat reader dc\reader\plug_ins\fileopen.api
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc.dll
c:\program files\adobe\acrobat reader dc\reader\plug_ins\ppklite.api
c:\windows\system32\wsock32.dll
c:\program files\adobe\acrobat reader dc\reader\plug_ins\acroform.api
c:\windows\system32\sensapi.dll
c:\program files\adobe\acrobat reader dc\reader\axsle.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\program files\adobe\acrobat reader dc\reader\plug_ins\digsig.api
c:\program files\adobe\acrobat reader dc\reader\plug_ins\escript.api
c:\windows\system32\winmm.dll
c:\program files\adobe\acrobat reader dc\reader\plug_ins\annots.api
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\program files\adobe\acrobat reader dc\reader\axe8sharedexpat.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\adobe\acrobat reader dc\reader\sqlite.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\program files\adobe\acrobat reader dc\reader\bibutils.dll
c:\program files\adobe\acrobat reader dc\reader\adobexmp.dll

PID
3460
CMD
"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --backgroundcolor=16448250
Path
C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
Indicators
No indicators
Parent process
AcroRd32.exe
User
admin
Integrity Level
MEDIUM
Exit code
3221225547
Version:
Company
Adobe Systems Incorporated
Description
Adobe RdrCEF
Version
15.23.20053.211670
Modules
Image
c:\program files\adobe\acrobat reader dc\reader\acrocef\rdrcef.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\winmm.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\program files\adobe\acrobat reader dc\reader\acrocef\libcef.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\version.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\kbdus.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\audioses.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\apphelp.dll

PID
2628
CMD
"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --type=renderer --disable-3d-apis --disable-databases --disable-direct-npapi-requests --disable-file-system --disable-notifications --disable-shared-workers --disable-direct-write --lang=en-US --lang=en-US --log-severity=disable --product-version="ReaderServices/15.23.20053 Chrome/45.0.2454.85" --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=2 --gpu-rasterization-msaa-sample-count=8 --content-image-texture-target=3553 --video-image-texture-target=3553 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel="3460.0.600961886\1456672271" --allow-no-sandbox-job /prefetch:673131151
Path
C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
Indicators
No indicators
Parent process
RdrCEF.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Adobe Systems Incorporated
Description
Adobe RdrCEF
Version
15.23.20053.211670
Modules
Image
c:\program files\adobe\acrobat reader dc\reader\acrocef\rdrcef.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\winmm.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\program files\adobe\acrobat reader dc\reader\acrocef\libcef.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\version.dll
c:\windows\system32\cryptbase.dll

PID
2056
CMD
"C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe" --type=renderer --disable-3d-apis --disable-databases --disable-direct-npapi-requests --disable-file-system --disable-notifications --disable-shared-workers --disable-direct-write --lang=en-US --lang=en-US --log-severity=disable --product-version="ReaderServices/15.23.20053 Chrome/45.0.2454.85" --device-scale-factor=1 --enable-delegated-renderer --num-raster-threads=2 --gpu-rasterization-msaa-sample-count=8 --content-image-texture-target=3553 --video-image-texture-target=3553 --disable-accelerated-video-decode --disable-webrtc-hw-encoding --disable-gpu-compositing --channel="3460.1.238819469\1232740501" --allow-no-sandbox-job /prefetch:673131151
Path
C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
Indicators
No indicators
Parent process
RdrCEF.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Adobe Systems Incorporated
Description
Adobe RdrCEF
Version
15.23.20053.211670
Modules
Image
c:\program files\adobe\acrobat reader dc\reader\acrocef\rdrcef.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\winmm.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\program files\adobe\acrobat reader dc\reader\acrocef\libcef.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\version.dll
c:\windows\system32\cryptbase.dll

Registry activity

Total events
719
Read events
512
Write events
204
Delete events
3

Modification events

PID
Process
Operation
Key
Name
Value
3016
FileOpenInstaller.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Owner
C80B00006E6AD9EBB4A9D401
3016
FileOpenInstaller.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
SessionHash
31637D2BF52087A07A939D05B52FC3AEE19358D3158F58C71C715EA53F95B0EC
3016
FileOpenInstaller.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Sequence
1
3016
FileOpenInstaller.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
RegFiles0000
C:\Program Files\FileOpen\UtilDll.dll
3016
FileOpenInstaller.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
RegFilesHash
B666C90036E872214288A54A791DB41C1E9D5CECDC3CF72508871FD3D1967916
3016
FileOpenInstaller.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
FileOpenBroker
"C:\Program Files\FileOpen\Services\FileOpenBroker32.exe"
3016
FileOpenInstaller.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FileOpenClient_is1
Inno Setup: Setup Version
5.5.9 (u)
3016
FileOpenInstaller.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FileOpenClient_is1
Inno Setup: App Path
C:\Program Files\FileOpen
3016
FileOpenInstaller.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FileOpenClient_is1
InstallLocation
C:\Program Files\FileOpen\
3016
FileOpenInstaller.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FileOpenClient_is1
Inno Setup: Icon Group
FileOpen
3016
FileOpenInstaller.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FileOpenClient_is1
Inno Setup: User
admin
3016
FileOpenInstaller.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FileOpenClient_is1
Inno Setup: Setup Type
standard
3016
FileOpenInstaller.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FileOpenClient_is1
Inno Setup: Selected Components
pdf,pdf\dist
3016
FileOpenInstaller.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FileOpenClient_is1
Inno Setup: Deselected Components
pdf\trace
3016
FileOpenInstaller.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FileOpenClient_is1
Inno Setup: Language
en
3016
FileOpenInstaller.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FileOpenClient_is1
DisplayName
FileOpen Client B979
3016
FileOpenInstaller.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FileOpenClient_is1
UninstallString
"C:\Program Files\FileOpen\unins000.exe"
3016
FileOpenInstaller.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FileOpenClient_is1
QuietUninstallString
"C:\Program Files\FileOpen\unins000.exe" /SILENT
3016
FileOpenInstaller.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FileOpenClient_is1
DisplayVersion
B979
3016
FileOpenInstaller.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FileOpenClient_is1
Publisher
FileOpen Systems Inc.
3016
FileOpenInstaller.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FileOpenClient_is1
URLInfoAbout
http://www.fileopen.com/request-tech-support/
3016
FileOpenInstaller.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FileOpenClient_is1
HelpLink
http://www.fileopen.com/request-tech-support/
3016
FileOpenInstaller.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FileOpenClient_is1
NoModify
1
3016
FileOpenInstaller.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FileOpenClient_is1
NoRepair
1
3016
FileOpenInstaller.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FileOpenClient_is1
InstallDate
20190111
3016
FileOpenInstaller.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FileOpenClient_is1
EstimatedSize
6194
3016
FileOpenInstaller.tmp
delete key
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
3896
FileOpenManager32.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FileOpenWebPublisherScreenHookDriver
Type
1
3896
FileOpenManager32.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FileOpenWebPublisherScreenHookDriver
ErrorControl
0
3896
FileOpenManager32.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FileOpenWebPublisherScreenHookDriver
Start
4
3896
FileOpenManager32.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FileOpenWebPublisherScreenHookDriver
ImagePath
\??\C:\Program Files\FileOpen\Services\fileopen32.sys
3896
FileOpenManager32.exe
delete key
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FileOpenWebPublisherScreenHookDriver\Enum
3896
FileOpenManager32.exe
delete key
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\FileOpenWebPublisherScreenHookDriver
2516
FileOpenBroker32.exe
write
HKEY_CURRENT_USER\Software\FileOpen
Fowp3Uuid
2B71AE21C2AE6241A4B08A2C69CC5F4F1189A224AF7F3E96337B2CB24B85DBE6614EC3E73A8FB577
2516
FileOpenBroker32.exe
write
HKEY_CURRENT_USER\Software\FileOpen
Fowp3Madi
2B71AE21BFAB6237F4E1E44C7DB12C606D90D757
2516
FileOpenBroker32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FileOpenBroker32_RASAPI32
EnableFileTracing
0
2516
FileOpenBroker32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FileOpenBroker32_RASAPI32
EnableConsoleTracing
0
2516
FileOpenBroker32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FileOpenBroker32_RASAPI32
FileTracingMask
4294901760
2516
FileOpenBroker32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FileOpenBroker32_RASAPI32
ConsoleTracingMask
4294901760
2516
FileOpenBroker32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FileOpenBroker32_RASAPI32
MaxFileSize
1048576
2516
FileOpenBroker32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FileOpenBroker32_RASAPI32
FileDirectory
%windir%\tracing
2516
FileOpenBroker32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FileOpenBroker32_RASMANCS
EnableFileTracing
0
2516
FileOpenBroker32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FileOpenBroker32_RASMANCS
EnableConsoleTracing
0
2516
FileOpenBroker32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FileOpenBroker32_RASMANCS
FileTracingMask
4294901760
2516
FileOpenBroker32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FileOpenBroker32_RASMANCS
ConsoleTracingMask
4294901760
2516
FileOpenBroker32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FileOpenBroker32_RASMANCS
MaxFileSize
1048576
2516
FileOpenBroker32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FileOpenBroker32_RASMANCS
FileDirectory
%windir%\tracing
2516
FileOpenBroker32.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2516
FileOpenBroker32.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2516
FileOpenBroker32.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2516
FileOpenBroker32.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2516
FileOpenBroker32.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
3384
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c1
aFS
DOS
3384
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c1
tDIText
/C/Program Files/FileOpen/examples/installcomplete.pdf
3384
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c1
tFileName
installcomplete.pdf
3384
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c1
tFileSource
local
3384
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c1
sFileAncestors
5B5D00
3384
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c1
sDI
2F432F50726F6772616D2046696C65732F46696C654F70656E2F6578616D706C65732F696E7374616C6C636F6D706C6574652E70646600
3384
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c1
sDate
443A32303139303131313133353235375A00
3384
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c1
uFileSize
115646
3384
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFiles\c1
uPageCount
1
3384
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\Privileged
bProtectedMode
1
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\ExitSection
bLastExitNormal
0
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\DiskCabs
bForms_AdhocWorkflowBackup
0
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\DiskCabs
bJSCache_GlobData
1
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\DiskCabs
bJSCache_GlobSettings
0
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AVGeneral
bExpandRHPInViewer
1
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\DiskCabs
bJSCache_GlobSettings
1
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AVGeneral
bPromptBeforeClosingMultipleTabs
1
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFolders\c1
sDI
2F432F50726F6772616D2046696C65732F46696C654F70656E2F6578616D706C65732F00
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFolders\c1
tDIText
/C/Program Files/FileOpen/examples/
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFolders\c1
tDisplayText
examples
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AVGeneral\cRecentFolders\c1
aFS
DOS
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\RememberedViews\cNoCategoryFiles\c1
xID
A615913FDD20FB46856C284AA2CC3B8D
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\RememberedViews\cNoCategoryFiles\c1
iTime
1547214784
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\RememberedViews\cNoCategoryFiles\c1\cViewDef
iAVDocViewBottomSplitterPos
0
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\RememberedViews\cNoCategoryFiles\c1\cViewDef
iAVDocViewLeftSplitterPos
0
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\RememberedViews\cNoCategoryFiles\c1\cViewDef
bAVDocViewTabsShowing
1
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\RememberedViews\cNoCategoryFiles\c1\cViewDef
bShowingHUD
0
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\RememberedViews\cNoCategoryFiles\c1\cViewDef
bShowingPageGaps
1
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\RememberedViews\cNoCategoryFiles\c1\cViewDef\cTopLeftView
bShowingHUD
0
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\RememberedViews\cNoCategoryFiles\c1\cViewDef\cTopLeftView
bShowingPageGaps
1
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\RememberedViews\cNoCategoryFiles\c1\cViewDef\cTopLeftView
ipageRotation
0
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\RememberedViews\cNoCategoryFiles\c1\cViewDef\cTopLeftView
xpageViewBead
0000000000000000
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\RememberedViews\cNoCategoryFiles\c1\cViewDef\cTopLeftView
ipageViewLayoutMode
2
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\RememberedViews\cNoCategoryFiles\c1\cViewDef\cTopLeftView
ipageViewPageNum
0
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\RememberedViews\cNoCategoryFiles\c1\cViewDef\cTopLeftView
bpageViewStartThread
0
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\RememberedViews\cNoCategoryFiles\c1\cViewDef\cTopLeftView
ipageViewThreadIndex
4294967295
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\RememberedViews\cNoCategoryFiles\c1\cViewDef\cTopLeftView
ipageViewX
4294967171
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\RememberedViews\cNoCategoryFiles\c1\cViewDef\cTopLeftView
ipageViewY
0
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\RememberedViews\cNoCategoryFiles\c1\cViewDef\cTopLeftView
dpageViewZoom
1.000244
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\RememberedViews\cNoCategoryFiles\c1\cViewDef\cTopLeftView
ipageViewZoomType
1
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\RememberedViews\cNoCategoryFiles\c1\cViewDef
bbringToFront
1
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\RememberedViews\cNoCategoryFiles\c1\cViewDef
ioverViewMode
1
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\RememberedViews\cNoCategoryFiles\c1\cViewDef
ioverViewPos
0
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\RememberedViews\cNoCategoryFiles\c1\cViewDef
ipageRotation
0
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\RememberedViews\cNoCategoryFiles\c1\cViewDef
xpageViewBead
0000000000000000
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\RememberedViews\cNoCategoryFiles\c1\cViewDef
ipageViewLayoutMode
2
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\RememberedViews\cNoCategoryFiles\c1\cViewDef
ipageViewMaxVisPageNum
0
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\RememberedViews\cNoCategoryFiles\c1\cViewDef
ipageViewMinVisPageNum
0
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\RememberedViews\cNoCategoryFiles\c1\cViewDef
ipageViewPageNum
0
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\RememberedViews\cNoCategoryFiles\c1\cViewDef
bpageViewStartThread
0
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\RememberedViews\cNoCategoryFiles\c1\cViewDef
ipageViewThreadIndex
4294967295
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\RememberedViews\cNoCategoryFiles\c1\cViewDef
ipageViewX
4294967171
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\RememberedViews\cNoCategoryFiles\c1\cViewDef
ipageViewY
0
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\RememberedViews\cNoCategoryFiles\c1\cViewDef
dpageViewZoom
1.000244
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\RememberedViews\cNoCategoryFiles\c1\cViewDef
ipageViewZoomType
1
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\RememberedViews\cNoCategoryFiles\c1\cViewDef
xwindowFrame
000000002600000000050000B4020000
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\RememberedViews\cNoCategoryFiles\c1\cViewDef
bwindowMaximized
1
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\Workflows\cServices
bEpdfRhpExpanded
1
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\DiskCabs
bForms_AdhocWorkflow
0
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\Annots\cPrefs
bprintCommentPopups
0
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\Collab\cServerSettings
tCONFIG
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\Collab\cServerSettings
tDAVFDF
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\Collab\cServerSettings
tFSFDF
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\Collab\cServerSettings
tNONE
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\DiskCabs
bCollab_OfflineDocs
0
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\DC\DiskCabs
bCollab_Workflows
0
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\ExitSection
bLastExitNormal
1
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c0
tDescription
Create a PDF from any format
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c0
aID
CPDFAppFull
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c0
tPath
CPDF_Full.aapp
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c0
tTitle
Create PDF
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c1
tDescription
Convert PDFs to Word, Excel, PowerPoint and more
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c1
aID
EPDFAppFull
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c1
tPath
EPDF_Full.aapp
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c1
tTitle
Export PDF
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c2
tDescription
Add comments with highlights, sticky notes, and mark-up tools
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c2
aID
CommentApp
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c2
tPath
Comments.aapp
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c2
tTitle
Comment
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c3
tDescription
Fill and sign documents and forms electronically
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c3
aID
FillSignApp
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c3
tPath
FillSign.aapp
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c3
tTitle
Fill & Sign
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c4
tDescription
Get signatures from others and track results
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c4
aID
CollectSignaturesApp
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c4
tPath
CollectSignatures.aapp
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c4
tTitle
Send for Signature
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c5
tDescription
Send documents, track views and downloads
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c5
aID
SendAppFull
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c5
tPath
TrackedSend.aapp
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c5
tTitle
Send & Track
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c6
tDescription
Add stamps such as 'approved' or 'draft'
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c6
aID
StampApp
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c6
tPath
Stamp.aapp
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c6
bShowLabels
1
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c6
tTitle
Stamp
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c7
tDescription
Digitally sign or certify documents and validate authenticity
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c7
aID
CertificatesApp
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c7
tPath
Certificates_R.aapp
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c7
tTitle
Certificates
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c8
tDescription
Measure distance, area, and perimeter of objects
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c8
aID
MeasureApp
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c8
tPath
Measure.aapp
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c8
tTitle
Measure
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c9
tDescription
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c9
aID
ToolsCenter
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c9
tPath
AppCenter_R.aapp
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c9
bShowLabels
0
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c9
tTitle
Tools
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c10
tDescription
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c10
aID
AVHome
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c10
tPath
Home.aapp
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c10
tTitle
Home
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c11
tDescription
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c11
aID
Viewer
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c11
tPath
Viewer.aapp
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c11
tTitle
Viewer
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c12
tDescription
Convert PDFs to Word, Excel, PowerPoint and more
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c12
aID
EPDFApp
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c12
bInline
1
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c12
tPath
EPDF_RHP.aapp
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c12
tTitle
Export PDF
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c13
tDescription
Create a PDF from any format
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c13
aID
CPDFApp
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c13
tPath
CPDF_RHP.aapp
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c13
tTitle
Create PDF
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c14
tDescription
Combine and arrange files into a single PDF
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c14
aID
CombinePDFRdrApp
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c14
tPath
Combine_R_RHP.aapp
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c14
tTitle
Combine Files
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c15
tDescription
Delete, insert, extract, or rotate pages
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c15
aID
PagesRdrApp
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c15
tPath
Pages_R_RHP.aapp
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c15
tTitle
Organize Pages
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c16
tDescription
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c16
aID
EditPDFRdrApp
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c16
tPath
Edit_R_RHP.aapp
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c16
tTitle
Edit PDF
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c17
tDescription
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c17
aID
EditPDFRdrAppFull
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c17
bInline
0
3100
AcroRd32.exe
write
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\AcroApp\cRegistered\c17
tPath
Edit_R_Full.aapp

Files activity

Executable files
11
Suspicious files
7
Text files
14
Unknown types
9

Dropped files

PID Process Filename Type
3168 FileOpenInstaller.exe C:\Users\admin\AppData\Local\Temp\is-0O2A1.tmp\FileOpenInstaller.tmp executable
3016 FileOpenInstaller.tmp C:\Program Files\FileOpen\Services\FileOpenBroker32.exe executable
3016 FileOpenInstaller.tmp C:\Program Files\FileOpen\Services\fileopen32.sys executable
3016 FileOpenInstaller.tmp C:\Program Files\Adobe\Acrobat Reader DC\Reader\plug_ins\FileOpen.api executable
3016 FileOpenInstaller.tmp C:\Program Files\FileOpen\Services\FileOpenManager32.exe executable
3016 FileOpenInstaller.tmp C:\Program Files\FileOpen\unins000.exe executable
3016 FileOpenInstaller.tmp C:\Users\admin\AppData\Local\Temp\is-VDCBJ.tmp\UtilDll.dll executable
2440 FileOpenInstaller.exe C:\Users\admin\AppData\Local\Temp\is-SOEJC.tmp\FileOpenInstaller.tmp executable
3016 FileOpenInstaller.tmp C:\Program Files\Adobe\Acrobat Reader DC\Reader\plug_ins\KbdHook.dll executable
3016 FileOpenInstaller.tmp C:\Program Files\FileOpen\Services\FileOpenScreenHook32.dll executable
3016 FileOpenInstaller.tmp C:\Program Files\FileOpen\UtilDll.dll executable
3100 AcroRd32.exe C:\Users\admin\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessages sqlite
2516 FileOpenBroker32.exe C:\Users\admin\AppData\Roaming\FileOpen\Fowpmadi.txt binary
3016 FileOpenInstaller.tmp C:\Users\admin\AppData\Local\Temp\Setup Log 2019-01-11 #001.txt text
3016 FileOpenInstaller.tmp C:\Program Files\FileOpen\unins000.dat dat
3016 FileOpenInstaller.tmp C:\Program Files\FileOpen\unins000.msg binary
3016 FileOpenInstaller.tmp C:\ProgramData\FileOpen\Updates\Lists\fotkPrs.lcd text
3016 FileOpenInstaller.tmp C:\ProgramData\FileOpen\Updates\Lists\fotkRds.lcd text
3016 FileOpenInstaller.tmp C:\ProgramData\FileOpen\Updates\Lists\is-CL8OR.tmp ––
3016 FileOpenInstaller.tmp C:\ProgramData\FileOpen\Updates\Lists\is-KU3LR.tmp ––
3016 FileOpenInstaller.tmp C:\ProgramData\FileOpen\Updates\Lists\fotkNis.lcd text
3016 FileOpenInstaller.tmp C:\ProgramData\FileOpen\Updates\Lists\fotkDrs.lcd text
3016 FileOpenInstaller.tmp C:\ProgramData\FileOpen\Updates\Lists\fotkCnfs.lcd text
3016 FileOpenInstaller.tmp C:\ProgramData\FileOpen\Updates\Lists\fotkLsts.lcd text
3016 FileOpenInstaller.tmp C:\ProgramData\FileOpen\Updates\Lists\fotkLngs.lcd text
3016 FileOpenInstaller.tmp C:\ProgramData\FileOpen\Updates\Lists\fotkBus.lcd text
3016 FileOpenInstaller.tmp C:\ProgramData\FileOpen\Updates\Lists\is-98DR4.tmp ––
3016 FileOpenInstaller.tmp C:\ProgramData\FileOpen\Updates\Lists\is-P2S6M.tmp ––
3016 FileOpenInstaller.tmp C:\ProgramData\FileOpen\Updates\Lists\is-5TL03.tmp ––
3016 FileOpenInstaller.tmp C:\ProgramData\FileOpen\Updates\Lists\is-64K6R.tmp ––
3016 FileOpenInstaller.tmp C:\ProgramData\FileOpen\Updates\Lists\is-RND2B.tmp ––
3016 FileOpenInstaller.tmp C:\ProgramData\FileOpen\Updates\Lists\is-86PTS.tmp ––
3016 FileOpenInstaller.tmp C:\ProgramData\FileOpen\Updates\L10n\fotk_fr.lcd text
3016 FileOpenInstaller.tmp C:\ProgramData\FileOpen\Updates\L10n\fotk_zh.lcd text
3016 FileOpenInstaller.tmp C:\ProgramData\FileOpen\Updates\L10n\fotk_ja.lcd text
3016 FileOpenInstaller.tmp C:\ProgramData\FileOpen\Updates\L10n\fotk_de.lcd text
3016 FileOpenInstaller.tmp C:\ProgramData\FileOpen\Updates\L10n\is-5MQMV.tmp ––
3016 FileOpenInstaller.tmp C:\ProgramData\FileOpen\Updates\L10n\is-JA187.tmp ––
3016 FileOpenInstaller.tmp C:\ProgramData\FileOpen\Updates\L10n\is-SF4SR.tmp ––
3016 FileOpenInstaller.tmp C:\ProgramData\FileOpen\Updates\L10n\is-NULBO.tmp ––
3460 RdrCEF.exe C:\Users\admin\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\data_1 binary
3016 FileOpenInstaller.tmp C:\Program Files\FileOpen\Services\is-PGKEC.tmp ––
3100 AcroRd32.exe C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\TMGrpPrm.sav binary
3016 FileOpenInstaller.tmp C:\Program Files\FileOpen\Services\is-C63AO.tmp ––
3100 AcroRd32.exe C:\Users\admin\AppData\Local\Adobe\Acrobat\DC\SharedDataEvents sqlite
3016 FileOpenInstaller.tmp C:\Program Files\FileOpen\Services\is-J21AF.tmp ––
3100 AcroRd32.exe C:\Users\admin\AppData\Local\Adobe\Acrobat\DC\SharedDataEvents-journal ––
3016 FileOpenInstaller.tmp C:\Program Files\FileOpen\Services\is-JVVJF.tmp ––
3100 AcroRd32.exe C:\Users\admin\AppData\Local\Adobe\Acrobat\DC\IconCacheRdr65536.dat binary
3016 FileOpenInstaller.tmp C:\Program Files\Adobe\Acrobat Reader DC\Reader\plug_ins\is-V6QQT.tmp ––
3100 AcroRd32.exe C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobSettings text
3016 FileOpenInstaller.tmp C:\Program Files\Adobe\Acrobat Reader DC\Reader\plug_ins\is-5M5FE.tmp ––
3016 FileOpenInstaller.tmp C:\Program Files\FileOpen\examples\installcomplete.pdf pdf
3016 FileOpenInstaller.tmp C:\Program Files\FileOpen\examples\is-7H71J.tmp ––
3100 AcroRd32.exe C:\Users\admin\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessages sqlite
3016 FileOpenInstaller.tmp C:\Program Files\FileOpen\is-6FH5F.tmp ––
3100 AcroRd32.exe C:\Users\admin\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessages-journal ––
3016 FileOpenInstaller.tmp C:\Program Files\FileOpen\is-PENCN.tmp ––
3100 AcroRd32.exe C:\Users\admin\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessages sqlite
3100 AcroRd32.exe C:\Users\admin\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessages sqlite
3100 AcroRd32.exe C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\TMDocs.sav binary

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
1
Threats
0

HTTP requests

No HTTP requests.

Connections

PID Process IP ASN CN Reputation
2516 FileOpenBroker32.exe 64.106.211.88:443 DataPipe, Inc. US unknown

DNS requests

Domain IP Reputation
plugin.fileopen.com 64.106.211.88
unknown

Threats

No threats detected.

Debug output strings

Process Message
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat
FileOpenInstaller.tmp AcroFind.cpp(113) : atlTraceGeneral - Checking filesystem for C:\Program Files\Adobe\Acrobat 5.0\Acrobat