General Info

File name

npp.7.7.1.Installer.exe

Full analysis
https://app.any.run/tasks/20851705-dc85-4be2-a192-cd46b4a3be8f
Verdict
Malicious activity
Analysis date
9/11/2019, 04:01:43
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5

a327dd44a4e2f0e35364bde7c4a59718

SHA1

071a81782d88810b0084bd2162c67cf0ff3ad13f

SHA256

6787c524b0ac30a698237ffb035f932d7132343671b8fe8f0388ed380d19a51c

SSDEEP

98304:LvP59bXolEMWzIcUKUwQOC8bz3JICi29jv:LzXol70/U5wBf3Jli29jv

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
300 seconds
Additional time used
240 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (75.0.3770.100)
  • Google Update Helper (1.3.34.7)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.7.2 (4.7.03062)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (14.21.27702.2)
  • Microsoft Visual C++ 2019 X86 Additional Runtime - 14.21.27702 (14.21.27702)
  • Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.21.27702 (14.21.27702)
  • Mozilla Firefox 68.0.1 (x86 en-US) (68.0.1)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • Update for Microsoft .NET Framework 4.7.2 (KB4087364) (1)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB4019990
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads dropped or rewritten executable
  • svchost.exe (PID: 852)
  • notepad++.exe (PID: 408)
  • explorer.exe (PID: 276)
  • notepad++.exe (PID: 3468)
  • gup.exe (PID: 3784)
  • regsvr32.exe (PID: 3716)
  • npp.7.7.1.Installer.exe (PID: 2624)
Application was dropped or rewritten from another process
  • notepad++.exe (PID: 3372)
  • notepad++.exe (PID: 3468)
  • gup.exe (PID: 3784)
  • notepad++.exe (PID: 408)
Registers / Runs the DLL via REGSVR32.EXE
  • npp.7.7.1.Installer.exe (PID: 2624)
Creates files in the user directory
  • notepad++.exe (PID: 408)
  • npp.7.7.1.Installer.exe (PID: 2624)
Executed via COM
  • explorer.exe (PID: 3176)
Creates COM task schedule object
  • regsvr32.exe (PID: 3716)
Creates files in the program directory
  • npp.7.7.1.Installer.exe (PID: 2624)
Executable content was dropped or overwritten
  • npp.7.7.1.Installer.exe (PID: 2624)
Creates a software uninstall entry
  • npp.7.7.1.Installer.exe (PID: 2624)

No info indicators.

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable MS Visual C++ (generic) (67.4%)
.dll
|   Win32 Dynamic Link Library (generic) (14.2%)
.exe
|   Win32 Executable (generic) (9.7%)
.exe
|   Generic Win/DOS Executable (4.3%)
.exe
|   DOS Executable Generic (4.3%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2018:12:15 23:24:36+01:00
PEType:
PE32
LinkerVersion:
6
CodeSize:
26112
InitializedDataSize:
141824
UninitializedDataSize:
2048
EntryPoint:
0x34a5
OSVersion:
4
ImageVersion:
6
SubsystemVersion:
4
Subsystem:
Windows GUI
FileVersionNumber:
7.7.1.0
ProductVersionNumber:
7.7.1.0
FileFlagsMask:
0x0000
FileFlags:
(none)
FileOS:
Win32
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
English (U.S.)
CharacterSet:
Unicode
CompanyName:
FileDescription:
Notepad++ : a free (GNU) source code editor
FileVersion:
7.7.1.0
LegalCopyright:
Copyleft 1998-2017 by Don HO
ProductName:
Notepad++
ProductVersion:
7.71
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
15-Dec-2018 22:24:36
Detected languages
English - United States
CompanyName:
FileDescription:
Notepad++ : a free (GNU) source code editor
FileVersion:
7.7.1.0
LegalCopyright:
Copyleft 1998-2017 by Don HO
ProductName:
Notepad++
ProductVersion:
7.71
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x000000D8
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
5
Time date stamp:
15-Dec-2018 22:24:36
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x00006409 0x00006600 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.41619
.rdata 0x00008000 0x00001396 0x00001400 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 5.15491
.data 0x0000A000 0x00020358 0x00000600 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 4.0044
.ndata 0x0002B000 0x0001A000 0x00000000 IMAGE_SCN_CNT_UNINITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.rsrc 0x00045000 0x000261E0 0x00026200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 5.73113
Resources
1

2

3

4

5

102

103

104

105

106

107

110

111

202

203

204

205

206

207

211

302

303

304

305

306

307

311

402

403

404

405

406

407

411

502

503

504

505

506

507

511

602

603

604

605

606

607

611

702

703

704

705

706

707

711

802

803

804

805

806

807

811

Imports
    KERNEL32.dll

    USER32.dll

    GDI32.dll

    SHELL32.dll

    ADVAPI32.dll

    COMCTL32.dll

    ole32.dll

Exports

    No exports.

Screenshots

Processes

Total processes
47
Monitored processes
11
Malicious processes
5
Suspicious processes
1

Behavior graph

+
drop and start start npp.7.7.1.installer.exe no specs npp.7.7.1.installer.exe regsvr32.exe no specs explorer.exe no specs explorer.exe no specs notepad++.exe gup.exe notepad++.exe svchost.exe explorer.exe no specs notepad++.exe
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
852
CMD
C:\Windows\system32\svchost.exe -k netsvcs
Path
C:\Windows\System32\svchost.exe
Indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Host Process for Windows Services
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\gpsvc.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\nsi.dll
c:\windows\system32\sysntfy.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\themeservice.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\profsvc.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\atl.dll
c:\windows\system32\winsta.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\slc.dll
c:\windows\system32\sens.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\shsvcs.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\schedsvc.dll
c:\windows\system32\pcwum.dll
c:\windows\system32\shell32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\authz.dll
c:\windows\system32\ubpm.dll
c:\windows\system32\ktmw32.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\credssp.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\fveapi.dll
c:\windows\system32\tbs.dll
c:\windows\system32\fvecerts.dll
c:\windows\system32\logoncli.dll
c:\windows\system32\wiarpc.dll
c:\windows\system32\samlib.dll
c:\windows\system32\taskcomp.dll
c:\windows\system32\version.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\netjoin.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\ikeext.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\wbem\wmisvc.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\iphlpsvc.dll
c:\windows\system32\firewallapi.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\wdscore.dll
c:\windows\system32\srvsvc.dll
c:\windows\system32\browser.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\vssapi.dll
c:\windows\system32\vsstrace.dll
c:\windows\system32\sscore.dll
c:\windows\system32\clusapi.dll
c:\windows\system32\cryptdll.dll
c:\windows\system32\resutils.dll
c:\windows\system32\samcli.dll
c:\windows\system32\nci.dll
c:\windows\system32\netprofm.dll
c:\windows\system32\spinf.dll
c:\windows\system32\propsys.dll
c:\windows\system32\wbem\wbemcore.dll
c:\windows\system32\wbem\esscli.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\wmiutils.dll
c:\windows\system32\wbem\repdrvfs.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\wbem\wmiprvsd.dll
c:\windows\system32\ncobjapi.dll
c:\windows\system32\wbem\wbemess.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\npmproxy.dll
c:\windows\system32\sxs.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\tschannel.dll
c:\windows\system32\wbem\ncprov.dll
c:\windows\system32\qmgr.dll
c:\windows\system32\bitsperf.dll
c:\windows\system32\bitsigd.dll
c:\windows\system32\upnp.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\ssdpapi.dll
c:\windows\system32\wuaueng.dll
c:\windows\system32\esent.dll
c:\windows\system32\winspool.drv
c:\windows\system32\cabinet.dll
c:\windows\system32\mspatcha.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wmsgapi.dll
c:\windows\system32\wer.dll
c:\windows\system32\netcfgx.dll
c:\windows\system32\hnetcfg.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\ndiscapcfg.dll
c:\windows\system32\rascfg.dll
c:\windows\system32\mprapi.dll
c:\windows\system32\tcpipcfg.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\es.dll
c:\windows\system32\aelupsvc.dll
c:\windows\system32\windanr.exe
c:\windows\system32\appinfo.dll
c:\users\admin\appdata\local\temp\npp.7.7.1.installer.exe
c:\program files\notepad++\notepad++.exe
c:\program files\notepad++\updater\gup.exe
c:\program files\notepad++\nppshell_06.dll
c:\windows\system32\mmcss.dll
c:\windows\system32\avrt.dll

PID
276
CMD
C:\Windows\Explorer.EXE
Path
C:\Windows\explorer.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
1073807364
Version:
Company
Microsoft Corporation
Description
Windows Explorer
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\slc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\profapi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\iconcodecservice.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sndvolsso.dll
c:\windows\system32\hid.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\timedate.cpl
c:\windows\system32\atl.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\actxprxy.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\userenv.dll
c:\windows\system32\shacct.dll
c:\windows\system32\samlib.dll
c:\windows\system32\samcli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\msftedit.dll
c:\windows\system32\msls31.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\authui.dll
c:\windows\system32\cryptui.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\gameux.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\wer.dll
c:\windows\system32\msiltcfg.dll
c:\windows\system32\version.dll
c:\windows\system32\msi.dll
c:\windows\system32\winsta.dll
c:\windows\system32\psapi.dll
c:\windows\system32\networkexplorer.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wdmaud.drv
c:\windows\system32\ksuser.dll
c:\windows\system32\avrt.dll
c:\windows\system32\audioses.dll
c:\windows\system32\msacm32.drv
c:\windows\system32\msacm32.dll
c:\windows\system32\midimap.dll
c:\windows\system32\msutb.dll
c:\windows\system32\stobject.dll
c:\windows\system32\batmeter.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\es.dll
c:\windows\system32\prnfldr.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dxp.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\syncreg.dll
c:\windows\ehome\ehsso.dll
c:\windows\system32\netshell.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\alttab.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\pnidui.dll
c:\windows\system32\qutil.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\npmproxy.dll
c:\windows\system32\wlanapi.dll
c:\windows\system32\wlanutil.dll
c:\windows\system32\wwanapi.dll
c:\windows\system32\wwapi.dll
c:\windows\system32\qagent.dll
c:\windows\system32\srchadmin.dll
c:\windows\system32\sxs.dll
c:\windows\system32\bthprops.cpl
c:\windows\system32\ieframe.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\synccenter.dll
c:\windows\system32\actioncenter.dll
c:\windows\system32\imapi2.dll
c:\windows\system32\hgcpl.dll
c:\windows\system32\provsvc.dll
c:\windows\system32\netprofm.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\fxsst.dll
c:\windows\system32\fxsapi.dll
c:\windows\system32\fxsresm.dll
c:\windows\system32\wscinterop.dll
c:\windows\system32\wscapi.dll
c:\windows\system32\wscui.cpl
c:\windows\system32\werconcpl.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\wercplsupport.dll
c:\windows\system32\msxml6.dll
c:\windows\system32\hcproviders.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\mpr.dll
c:\windows\system32\drprov.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\thumbcache.dll
c:\windows\system32\winanr.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\users\admin\appdata\local\temp\npp.7.7.1.installer.exe
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\program files\notepad++\notepad++.exe
c:\windows\system32\twext.dll
c:\windows\system32\zipfldr.dll
c:\program files\winrar\rarext.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\syncui.dll
c:\windows\system32\synceng.dll
c:\program files\notepad++\nppshell_06.dll
c:\windows\system32\acppage.dll
c:\windows\system32\sendmail.dll
c:\windows\system32\mydocs.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\audiodev.dll
c:\windows\system32\wmvcore.dll
c:\windows\system32\wmasf.dll
c:\windows\system32\ehstorapi.dll

PID
3728
CMD
"C:\Users\admin\AppData\Local\Temp\npp.7.7.1.Installer.exe"
Path
C:\Users\admin\AppData\Local\Temp\npp.7.7.1.Installer.exe
Indicators
No indicators
Parent process
explorer.exe
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
Don HO [email protected]
Description
Notepad++ : a free (GNU) source code editor
Version
7.7.1.0
Modules
Image
c:\users\admin\appdata\local\temp\npp.7.7.1.installer.exe
c:\systemroot\system32\ntdll.dll

PID
2624
CMD
"C:\Users\admin\AppData\Local\Temp\npp.7.7.1.Installer.exe"
Path
C:\Users\admin\AppData\Local\Temp\npp.7.7.1.Installer.exe
Indicators
Parent process
explorer.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Don HO [email protected]
Description
Notepad++ : a free (GNU) source code editor
Version
7.7.1.0
Modules
Image
c:\users\admin\appdata\local\temp\npp.7.7.1.installer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\version.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\shdocvw.dll
c:\users\admin\appdata\local\temp\nswa186.tmp\langdll.dll
c:\users\admin\appdata\local\temp\nswa186.tmp\system.dll
c:\windows\system32\riched20.dll
c:\users\admin\appdata\local\temp\nswa186.tmp\installoptions.dll
c:\windows\system32\comdlg32.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\users\admin\appdata\local\temp\nswa186.tmp\nsdialogs.dll
c:\users\admin\appdata\local\temp\nswa186.tmp\userinfo.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\program files\notepad++\notepad++.exe
c:\windows\system32\regsvr32.exe
c:\windows\system32\netutils.dll

PID
3716
CMD
regsvr32 /s "C:\Program Files\Notepad++\NppShell_06.dll"
Path
C:\Windows\system32\regsvr32.exe
Indicators
No indicators
Parent process
npp.7.7.1.Installer.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft(C) Register Server
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\program files\notepad++\nppshell_06.dll
c:\windows\system32\msimg32.dll

PID
2428
CMD
"C:\Windows\explorer.exe" "C:\Program Files\Notepad++\notepad++.exe"
Path
C:\Windows\explorer.exe
Indicators
No indicators
Parent process
npp.7.7.1.Installer.exe
User
admin
Integrity Level
HIGH
Exit code
1
Version:
Company
Microsoft Corporation
Description
Windows Explorer
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\slc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\actxprxy.dll

PID
3176
CMD
C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding
Path
C:\Windows\explorer.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
1073807364
Version:
Company
Microsoft Corporation
Description
Windows Explorer
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\slc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\actxprxy.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\program files\notepad++\notepad++.exe
c:\windows\system32\mpr.dll

PID
408
CMD
"C:\Program Files\Notepad++\notepad++.exe"
Path
C:\Program Files\Notepad++\notepad++.exe
Indicators
Parent process
explorer.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Don HO [email protected]
Description
Notepad++ : a free (GNU) source code editor
Version
7.71
Modules
Image
c:\program files\notepad++\notepad++.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\program files\notepad++\scilexer.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\propsys.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\program files\notepad++\updater\gup.exe
c:\windows\system32\windowscodecs.dll
c:\program files\notepad++\plugins\mimetools\mimetools.dll
c:\program files\notepad++\plugins\nppconverter\nppconverter.dll
c:\program files\notepad++\plugins\nppexport\nppexport.dll

PID
3784
CMD
"C:\Program Files\Notepad++\updater\gup.exe" -v7.71
Path
C:\Program Files\Notepad++\updater\gup.exe
Indicators
Parent process
notepad++.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Don HO [email protected]
Description
WinGup for Notepad++
Version
5.1
Modules
Image
c:\program files\notepad++\updater\gup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\notepad++\updater\libcurl.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\schannel.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll

PID
3468
CMD
"C:\Program Files\Notepad++\notepad++.exe" "C:\Program Files\Notepad++\change.log"
Path
C:\Program Files\Notepad++\notepad++.exe
Indicators
Parent process
npp.7.7.1.Installer.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Don HO [email protected]
Description
Notepad++ : a free (GNU) source code editor
Version
7.71
Modules
Image
c:\program files\notepad++\notepad++.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\program files\notepad++\scilexer.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll

PID
3372
CMD
"C:\Program Files\Notepad++\notepad++.exe" "C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe"
Path
C:\Program Files\Notepad++\notepad++.exe
Indicators
Parent process
explorer.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Don HO [email protected]
Description
Notepad++ : a free (GNU) source code editor
Version
7.71
Modules
Image
c:\program files\notepad++\notepad++.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\program files\notepad++\scilexer.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll

Registry activity

Total events
1703
Read events
1417
Write events
282
Delete events
4

Modification events

PID
Process
Operation
Key
Name
Value
852
svchost.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{24A94EE9-F062-4F07-A2D2-2D97993814D4}
DynamicInfo
030000002FA8CFCCA9E1D40186BDD57ED146D5010400014000000000
276
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\NccQngn\Ybpny\Grzc\acc.7.7.1.Vafgnyyre.rkr
00000000000000000000000000000000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
276
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000001C0000002500000093800C00090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101
276
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\NccQngn\Ybpny\Grzc\acc.7.7.1.Vafgnyyre.rkr
000000000000000000000000654D0000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
276
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000001C00000025000000F8CD0C00090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101
276
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\Abgrcnq++\abgrcnq++.rkr
000000000000000000000000B9370000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
276
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000001C00000025000000B1050D00090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101
276
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
LanguageList
en-US
276
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\Abgrcnq++\abgrcnq++.rkr
000000000000000001000000B9370000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
276
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000001C00000026000000B1050D00090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101
276
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\Abgrcnq++\abgrcnq++.rkr
00000000000000000100000038710000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
276
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000001C00000026000000303F0D00090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101
276
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ApplicationDestinations
MaxEntries
15
276
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StuckRects2
Settings
28000000FFFFFFFF02000000030000003E0000001E000000FEFFFFFFB402000002050000D2020000
276
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams\Desktop
TaskbarWinXP
0C000000080000000100000000000000AA4F2868486AD0118C7800C04FD918B400000000400D000000000000160000000000000000000000160000000000000001000000
276
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\BagMRU
NodeSlots
02
276
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\BagMRU
MRUListEx
FFFFFFFF
276
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Bags\1\Desktop
FFlags
1075839524
276
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Bags\1\Desktop
Mode
1
276
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Bags\1\Desktop
LogicalViewMode
3
276
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Bags\1\Desktop
IconSize
48
276
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Bags\1\Desktop
ColInfo
00000000000000000000000000000000FDDFDFFD100000000000000000000000040000001800000030F125B7EF471A10A5F102608C9EEBAC0A000000A000000030F125B7EF471A10A5F102608C9EEBAC0C00000050000000A66A63283D95D211B5D600C04FD918D00B0000007800000030F125B7EF471A10A5F102608C9EEBAC0E00000078000000
276
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Bags\1\Desktop
Sort
000000000000000000000000000000000100000030F125B7EF471A10A5F102608C9EEBAC0A00000001000000
276
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Bags\1\Desktop
GroupView
0
276
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Bags\1\Desktop
GroupByKey:FMTID
{00000000-0000-0000-0000-000000000000}
276
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Bags\1\Desktop
GroupByKey:PID
0
276
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Bags\1\Desktop
GroupByDirection
1
276
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell\Bags\1\Desktop
ItemPos1280x720x96(1)
000000000000000000000000000000000D0000000200000014001F7840F05F6481501B109F0800AA002F954E580000000200000074003A00E10700001C4D676620004143524F42417E312E4C4E4B0000580008000400EFBE1C4D67661C4D67662A000000D0E400000000020000000000000000000000000000004100630072006F0062006100740020005200650061006400650072002000440043002E006C006E006B0000001C000D000000EC01000062003A00C50300001C4D7C60200043436C65616E65722E6C6E6B0000460008000400EFBE1C4D7C601C4D7C602A000000A6C40000000003000000000000000000000000000000430043006C00650061006E00650072002E006C006E006B0000001C00580000006400000072003A00F70700001C4D7265200046494C455A497E312E4C4E4B0000560008000400EFBE1C4D3D621C4D72652A000000E3D90000000002000000000000000000000000000000460069006C0065005A0069006C006C006100200043006C00690065006E0074002E006C006E006B0000001C000D000000640000005E003A0051040000774E5198200046697265666F782E6C6E6B00440008000400EFBE1C4D7D57774E51982A00000010720000000003000000000000000000000000000000460069007200650066006F0078002E006C006E006B0000001A000D000000C60000006C003A0099080000774E6A982000474F4F474C457E312E4C4E4B0000500008000400EFBE1C4D59591C4D59592A0000005CBB000000000300000000000000000000000000000047006F006F0067006C00650020004300680072006F006D0065002E006C006E006B0000001C000D0000002801000058003A00EF0600001C4DD05D20004F706572612E6C6E6B00400008000400EFBE1C4DCF5D1C4DCF5D2A000000E3C600000000010000000000000000000000000000004F0070006500720061002E006C006E006B00000018000D0000008A01000058003A00F00400001E4DF06E2000536B7970652E6C6E6B00400008000400EFBE1E4DF06E1E4DF06E2A000000A8C8000000000500000000000000000000000000000053006B007900700065002E006C006E006B00000018000D0000004E02000072003A00000400001C4DA8602000564C434D45447E312E4C4E4B0000560008000400EFBE1C4DA8601C4DA8602A00000097D2000000000100000000000000000000000000000056004C00430020006D006500640069006100200070006C0061007900650072002E006C006E006B0000001C0058000000C60000005E0032001F0B0000AC4E5315200066616E6261636B2E72746600440008000400EFBEAC4E53152B4F39102A000000CECA0000000012000000000000000000000000000000660061006E006200610063006B002E0072007400660000001A0058000000280100005C00320014170000F24C0C0C200069666175746F2E6A70670000420008000400EFBEF24C0C0C2B4F39102A0000009CCA0000000019000000000000000000000000000000690066006100750074006F002E006A007000670000001A00580000008A01000078003200110B0000944C27102000494E54524F447E312E52544600005C0008000400EFBE944C27102B4F39102A000000E8CA000000000900000000000000000000000000000069006E00740072006F00640075006300740069006F006E00720075006E006E0069006E0067002E0072007400660000001C0058000000EC010000620032003B0C0000934D965A20006D6F746F726B69742E7274660000460008000400EFBE934D965A2B4F39102A000000EACA000000000D0000000000000000000000000000006D006F0074006F0072006B00690074002E0072007400660000001C00580000004E02000066003200C16800004A4C2E5E20004E49434547527E312E504E4700004A0008000400EFBE4A4C2E5E2B4F39102A0000001C0A00000000150000000000000000000000000000006E00690063006500670072006F0075006E0064002E0070006E00670000001C00A300000002000000640032000F0B0000DA4A6006200053484F574E547E312E5254460000480008000400EFBEDA4A60062B4F39102A000000E2CA000000000C000000000000000000000000000000730068006F0077006E0074007200650065002E0072007400660000001C00A3000000640000006A003200441D0000CF4EE24A20005350454349467E312E504E4700004E0008000400EFBECF4EE24A2B4F39102A00000084B800000000050000000000000000000000000000007300700065006300690066006900650064006100730073002E0070006E00670000001C00A3000000C600000064003A00D10300002B4F531020004E4F544550417E312E4C4E4B0000480008000400EFBE2B4F53102B4F53102A00000058CE00000000020000000000000000000000000000004E006F00740065007000610064002B002B002E006C006E006B0000001C00A3000000C600000000000000
276
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\TrayNotify
LastAdvertisement
1278FFAFD546D501
276
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\TrayNotify
UserStartTime
319EE624BB3DD301
276
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer
CleanShutdown
1
276
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Providers\EventLog\{01979c6a-42fa-414c-b8aa-eee2c8202018}
LastKnownState
3C0042006F006F006B006D00610072006B004C006900730074003E000D000A00200020003C0042006F006F006B006D00610072006B0020004300680061006E006E0065006C003D0027004D006900630072006F0073006F00660074002D00570069006E0064006F00770073002D00570069006E0064006F00770073004200610063006B00750070002F0041006300740069006F006E00430065006E00740065007200270020005200650063006F0072006400490064003D00270034002700200049007300430075007200720065006E0074003D002700740072007500650027002F003E000D000A003C002F0042006F006F006B006D00610072006B004C006900730074003E000000000000000000000020000000640000000000000000000000010000000100000000000000000000000200000002000000000000000000000010000000650000000000000000000000000000000000000010FB710178E80F00
276
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Providers\EventLog\{945a8954-c147-4acd-923f-40c45405a658}
LastKnownState
3C0042006F006F006B006D00610072006B004C006900730074003E000D000A00200020003C0042006F006F006B006D00610072006B0020004300680061006E006E0065006C003D0027004D006900630072006F0073006F00660074002D00570069006E0064006F00770073002D00570069006E0064006F007700730055007000640061007400650043006C00690065006E0074002F004F007000650072006100740069006F006E0061006C00270020005200650063006F0072006400490064003D0027003100370031002700200049007300430075007200720065006E0074003D002700740072007500650027002F003E000D000A003C002F0042006F006F006B006D00610072006B004C006900730074003E00000000000000000000000000200000002A00000000000000000000000000000001000000000000000000000003000000030000000000000000000000
276
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Providers\EventLog\{11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78}
LastKnownState
3C0042006F006F006B006D00610072006B004C006900730074003E000D000A00200020003C0042006F006F006B006D00610072006B0020004300680061006E006E0065006C003D0027004D006900630072006F0073006F00660074002D00570069006E0064006F00770073002D00570069006E0064006F0077007300200044006500660065006E006400650072002F00570048004300270020005200650063006F0072006400490064003D00270034002700200049007300430075007200720065006E0074003D002700740072007500650027002F003E000D000A003C002F0042006F006F006B006D00610072006B004C006900730074003E0000009C534C74200000006500000000000000000000000100000001000000000000000000000001000000010000000000000000000000
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\notepad++.exe
C:\Program Files\Notepad++\notepad++.exe
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Notepad++
C:\Program Files\Notepad++
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
DisplayName
Notepad++ (32-bit x86)
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
Publisher
Notepad++ Team
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MajorVersion
7
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MinorVersion
71
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
UninstallString
C:\Program Files\Notepad++\uninstall.exe
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
DisplayIcon
C:\Program Files\Notepad++\notepad++.exe
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
DisplayVersion
7.7.1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
URLInfoAbout
http://notepad-plus-plus.org/
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
VersionMajor
7
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
VersionMinor
71
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
NoModify
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
NoRepair
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
EstimatedSize
8586
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSectionUsed
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_C
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_C++
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Java
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_C#
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_HTML
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_RC
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_SQL
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_PHP
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_CSS
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_VB
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Perl
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_JavaScript
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Python
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_ActionScript
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_LISP
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_VHDL
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_TeX
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_DocBook
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_NSIS
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_CMAKE
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_BATCH
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_CoffeeScript
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_BaanC
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Lua
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_AutoIt
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_NppExport
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_MimeTools
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Converter
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_AutoUpdater
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_PluginsAdmin
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_afrikaans
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_albanian
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_arabic
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_aragonese
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_aranese
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_azerbaijani
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_basque
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_belarusian
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_bengali
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_bosnian
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_brazilian_portuguese
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_breton
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_bulgarian
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_catalan
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_chineseTraditional
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_chineseSimplified
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_corsican
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_croatian
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_czech
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_danish
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_dutch
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_english_customizable
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_esperanto
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_estonian
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_extremaduran
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_farsi
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_finnish
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_french
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_friulian
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_galician
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_georgian
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_german
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_greek
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_gujarati
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_hebrew
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_hindi
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_hungarian
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_indonesian
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_italian
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_japanese
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_kannada
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_kazakh
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_korean
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_kyrgyz
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_latvian
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_ligurian
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_lithuanian
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_luxembourgish
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_macedonian
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_malay
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_marathi
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_mongolian
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_norwegian
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_nynorsk
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_occitan
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_polish
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_portuguese
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_punjabi
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_romanian
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_russian
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_samogitian
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_sardinian
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_serbian
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_serbianCyrillic
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_sinhala
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_slovak
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_slovenian
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_spanish
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_spanish_ar
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_swedish
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_tagalog
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_tajik
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_tamil
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_tatar
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_telugu
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_thai
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_turkish
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_ukrainian
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_urdu
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_uyghur
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_uzbek
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_uzbekCyrillic
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_vietnamese
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_welsh
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_kurdish
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_piglatin
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_zulu
0
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_BlackBoard
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Choco
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_HelloKitty
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_MonoIndustrial
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Monokai
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Obsidian
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_PlasticCodeWrap
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_RubyBlue
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Twilight
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_VibrantInk
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_DeepBlack
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_vimDarkBlue
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Bespin
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Zenburn
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Solarized
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Solarized-light
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_HotFudgeSundae
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_khaki
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_MossyLawn
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Navajo
1
2624
npp.7.7.1.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_explorerContextMenu
1
3716
regsvr32.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\ANotepad++
3716
regsvr32.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}\InprocServer32
3716
regsvr32.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}\Settings
3716
regsvr32.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}
3716
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}
ANotepad++
3716
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}\InprocServer32
C:\Program Files\Notepad++\NppShell_06.dll
3716
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}\InprocServer32
ThreadingModel
Apartment
3716
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}\Settings
Title
Edit with &Notepad++
3716
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}\Settings
Path
C:\Program Files\Notepad++\notepad++.exe
3716
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}\Settings
Custom
3716
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}\Settings
ShowIcon
1
3716
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}\Settings
Dynamic
1
3716
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}\Settings
Maxtext
25
3716
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\ANotepad++
{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}
3176
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3176
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
408
notepad++.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
LanguageList
en-US
408
notepad++.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
408
notepad++.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3468
notepad++.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
LanguageList
en-US
3372
notepad++.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
LanguageList
en-US

Files activity

Executable files
15
Suspicious files
2
Text files
152
Unknown types
4

Dropped files

PID
Process
Filename
Type
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\LangDLL.dll
executable
MD5: ab1db56369412fe8476fefffd11e4cc0
SHA256: 6f14c8f01f50a30743dac68c5ac813451463dfb427eb4e35fcdfe2410e1a913b
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\UserInfo.dll
executable
MD5: 9eb662f3b5fbda28bffe020e0ab40519
SHA256: 9aa388c7de8e96885adcb4325af871b470ac50edb60d4b0d876ad43f5332ffd1
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\plugins\NppConverter\NppConverter.dll
executable
MD5: b09d236a685cf78936040ddddd2d92e2
SHA256: 1f94d389a06453b6d470d0aef05565901a41918b322a1c36f3c72ea0dcacb2d1
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\plugins\mimeTools\mimeTools.dll
executable
MD5: c6f9848553c00503e27f103bb3677a98
SHA256: bbefbea628d78a7a42228b2fd2bee0166b5c5bba2af23e413a0893095a8e6421
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\updater\libcurl.dll
executable
MD5: 5e7da2437af5dbeb5f5fb925b6502992
SHA256: 4f4c040500351065dfa2628b4c29ef0c2c63b7648e04e5ede68fc7dc2b98e421
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nsDialogs.dll
executable
MD5: 466179e1c8ee8a1ff5e4427dbb6c4a01
SHA256: 1e40211af65923c2f4fd02ce021458a7745d28e2f383835e3015e96575632172
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\InstallOptions.dll
executable
MD5: 05bf02da51e717f79f6b5cbea7bc0710
SHA256: ca092ba7f275b0c9000098cdd1a9876fe8dc050fcb40a0e8a1ab8335236e9dc5
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\NppShell_06.dll
executable
MD5: 1f37145219c34952b1cfbac4e0ed7a8d
SHA256: c0a08629c4fb173bd6a8facfa1e5925aa08b017be8e69605eab7100618d54437
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\System.dll
executable
MD5: 0d7ad4f45dc6f5aa87f606d0331c6901
SHA256: 3eb38ae99653a7dbc724132ee240f6e5c4af4bfe7c01d31d23faf373f9f2eaca
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\uninstall.exe
executable
MD5: 1ff8a862cd7f44d6e0531b40c7d7289b
SHA256: 5ff7a866c0cce74680b01142bb9613388fef23b5cd68215c02dfe9baccc88487
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\plugins\Config\nppPluginList.dll
executable
MD5: e2e112c8e40eb34b9c99e46d0e2c9b26
SHA256: 08e33daa11f590ac3b8384680453a614cd4bbe983b3d2712844c62ba2e70f252
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\updater\GUP.exe
executable
MD5: b3c2f7893c82e76fb1f977f8d0a275d2
SHA256: 7961a3074719166a8cdd416ec57f49739666cd503a49605e0e31f5de33506e6d
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\SciLexer.dll
executable
MD5: 5922e6d5399bfd40a076352ccf54c348
SHA256: 1a05072095113ceeb31c7c50720f42049b149952c3327702f134dd491a1c0ef2
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\notepad++.exe
executable
MD5: 0251a839e38ecbe73a5b52e6c7926b47
SHA256: 360b12ccfa33c6d2021bf34162b111ffc2f5939b0524b2e045cd682d93318d69
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\plugins\NppExport\NppExport.dll
executable
MD5: 9db561b8e19541f5d58e1ceae971c1fa
SHA256: 3c0b56fd66aee3f3f02ea3998c6d4e9fa053faaa055e08fd44d8f0d62100934d
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\extremaduran.xml
xml
MD5: 896b0f1f0854f3bcc23a80c99dcebd47
SHA256: 87e0372bfd2b84316adf2c7d3130fcf2415a96ec2c8bcd5da6f1a8a3a807c8d2
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\turkish.xml
xml
MD5: 6b5d7190e9af58c43afcbe80807b3e0f
SHA256: e315dadbca8df57b80ba1ee3f2c685b201a29399e736c97debf82a9789183ba9
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\uzbekCyrillic.xml
xml
MD5: 71b7ce4804f337f3d5c4fea4a0733691
SHA256: 380e17fd360658921ea937043e540b2af642a7307be691f5c58b825623b61a99
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\uyghur.xml
xml
MD5: a5d2661cab9fae284200b5cd84496b41
SHA256: f5d24a6c678b1b54539adeafd2bc2697738f44cea6c184fa442980f1440e5afd
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\vietnamese.xml
xml
MD5: 4648aecae4e9d1df3ca32d9a0cba8fed
SHA256: 747d88fd1df6f7a703fdd0904b50ff32c3d6d2d26203e0ae07b44786b44a9961
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\zulu.xml
xml
MD5: 9440a55f71dac040b123de16d6557951
SHA256: 16ef44efd21a556cfed5aa07b70437a16016754fcd3ce2a9e7048061716591df
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\ukrainian.xml
xml
MD5: 2ad1d6c0d74e402c854df769a8196880
SHA256: 38d0e8cccb1030ba3314511573ed58fcf9ad24d32de8110f6fced82262585b4d
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\telugu.xml
xml
MD5: a8b6a302f3bda0eeae95e5214df33ec4
SHA256: 82b4b16ee06e668e4ff30e71fcbf42623cf30dc14177c570a7ad1f47c0284e0c
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\uzbek.xml
xml
MD5: 8d5d53622c0bd306f5bcbd785328ead3
SHA256: 1e94b2d6c7a0f3a29ed7065a592fab68ffcb442f6b6eb7a78f4f875c689dadd6
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\thai.xml
xml
MD5: 8d02b72cdcce6c5a4db56eebba394824
SHA256: 8ce450bcfd9b9617f4e0969ad4e201480b255d473cb1383c90761cc28cbd7ecc
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\urdu.xml
xml
MD5: cf965dfcf2257d8046c453ac36fcf65e
SHA256: 0b685abaea6232f3e99d563f01613161251e51aba6a62d83cb306aa5f2d396d5
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\welsh.xml
xml
MD5: 538acafd2ef4e67581a908f970838626
SHA256: 11fd56a75e14493a7305d6cd2aa79dd6990465eb0dec8bdf6354dd6e5db35634
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\tajikCyrillic.xml
xml
MD5: c28fc035726b0fe6f56c129d87c2aabc
SHA256: 70a7f699ee317a25cb74524995037b145477b4df0c39d674381ff5c8895fb63f
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\swedish.xml
xml
MD5: a41e0bfa49dd28206c2e9fd65880e2d5
SHA256: b5123cd6d4764f901b4387119df5a738451afe9625a68e9c4ab7f992f533d9f1
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\tatar.xml
xml
MD5: 84c32874e0fbc009202c86781cf6a6b6
SHA256: 0b20a37e6512a5a3e0c92075db9eb179a156e5e20f9fe52c3260daf8c77825a3
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\tagalog.xml
xml
MD5: 04e3e27d9d635c6b23c8e40dcbbdd442
SHA256: 047c63c449c5e2a9a4f97637c741eb07e6ec034bc829d85c6565bb0292c1cd72
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\spanish_ar.xml
xml
MD5: e6e44ee7c6b6a0ff89f0fe490f3c11fc
SHA256: 2fadeca7c44132ef9a9243bd67eee23c93a25f96bc6c80b81d527d18128d284d
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\tamil.xml
xml
MD5: abc0ae5ed0002512221d682263e41204
SHA256: e23759fd6d60ef9728b620a1a8316fc049ccbf93445a91a1a85d27c4e25f3f15
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\romanian.xml
xml
MD5: b9ef29e90195ced6138e3c780858d024
SHA256: 511e3b29f50c46324b636c8ebbe02d2c9c3dc0839b7f3fa5ebaff422c387f5aa
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\spanish.xml
xml
MD5: 822489dc4c8085d014fb508c76289747
SHA256: 23b6520c0d7b3d7e80086b0714f0668a08e6b0dbea7a493cb0e320b8c552be02
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\punjabi.xml
xml
MD5: 1b2298a7b847f23751010f2b01e7a2ab
SHA256: e3e009b986ed53654ea1c89d828ba3998039db4fae20a877f097e41a2ebb7771
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\slovenian.xml
xml
MD5: 2d0d8cdcb5375130e8cba2061df596ea
SHA256: 7b06c50ce90928f455131c070486e2f6f2d6e6ab71fdf7b703ee81ee211bb51e
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\slovak.xml
xml
MD5: e56b5a5257bf4e743e9abb688b9e7215
SHA256: 52b86604adc29058a0efe7109857cc37cb452fd46f6210467543af2bf81b8b3e
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\serbianCyrillic.xml
xml
MD5: e6c94316e6d065533305b94e7d5af2bc
SHA256: 289d7cdd9d9af5b2992e3b0ac38022f91e3d9dc0051e40733983e26e2ddcf594
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\samogitian.xml
xml
MD5: ebba131558f344afe63e1c5718d0f7ad
SHA256: 75eca9974de1fca41651975a92f374660e1a7c273a3d1dab0ef6dd573230878b
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\sardinian.xml
xml
MD5: 064889342004d04b1de62578aa733216
SHA256: 0169ebd43b3cec4a4f3b0143a2af6f07ec9bf73cb04882a3d4507f01931c08de
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\russian.xml
xml
MD5: 435f3d4ae5cff009d5e5ec356042cbe7
SHA256: ab2423bff4feb6c11b5dccf2d35adc4bb4a7046db00e24a66d697540d9519612
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\serbian.xml
xml
MD5: 174e7dc367ff1c213432b891f11d25bb
SHA256: 1a07c6a9c2639fa12bb000f599498ddf84827449afbb7952f4bdc4cf526c2117
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\sinhala.xml
xml
MD5: 9986ce0334af5335ae8c7e5a3cbc818b
SHA256: a8b55a8115a50bd3b7b07c359c49fe7da48a5acf1dacc2c0e3708f6f48636fd6
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\norwegian.xml
xml
MD5: f5519b853316445aab668c1dfd480f87
SHA256: bb9a79755d37d449acff570c20e78a9e0c58482414435cf0f493e15e6216fce3
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\occitan.xml
xml
MD5: 282135aa211f86afebb1be689de3480c
SHA256: a65ef81488df5ddd0cdcc6e65be1b6992b79197fb7980740a750d2f5f5def463
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\polish.xml
xml
MD5: b6fe2b47e9118deeedba46078bad74d3
SHA256: aab6f7be1c52762cd91d7424adeec856beb2aead9051f62b2591657b82618681
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\piglatin.xml
xml
MD5: e57e7d60833241e6307f5666fb7682cc
SHA256: 1fec93f265e064820f37cc450b8cb8c60b9250bffb4bf1612a70e81527068010
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\marathi.xml
xml
MD5: ce4757e3935343d472515cf9b936d7e4
SHA256: 8b7545558bc73329f6caa27b5aa6203220d7a58ea3b37e9c346e636aaf70146c
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\portuguese.xml
xml
MD5: bbdcaf6faf7f8548c07f2bb8e617a15e
SHA256: 80b8d3026279141c07722981cc3c6f356674099fd02b8f82b74104fe625e2236
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\kyrgyz.xml
xml
MD5: ad3a31d477ad1e09dc3f6911c1f50d1e
SHA256: 4964c0b9f36b7fec44ec0805ba153d88293311cd703680719187cdaa68fbd090
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\mongolian.xml
xml
MD5: 7ff28b9242fe6bd774fcd71fbed5563d
SHA256: 5d35c3c2f10b6f6923c0b11bd7d82f569ba6a0a8fb854aac20988c77d35bf934
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\nynorsk.xml
xml
MD5: 694867a6ade700da42a55da24da74200
SHA256: 319a9e846a610811fdf12b96bf352e4e07f2d7de5a6bec3000cebc1b1e21a1fe
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\malay.xml
text
MD5: 3158e10e8a9b3c0e84a770f5f11aaa1f
SHA256: 690416e418c9821bfe71805f76d9e18ee39fd092742d173cc9fe595268b131fa
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\latvian.xml
xml
MD5: 170d9e9a92a604a309259d3d6f3b9bb6
SHA256: bbaa6bc087ab351b182d204a60eab8bc93bd5e75ca2a4a4eaf80b1d5e0fec59b
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\macedonian.xml
xml
MD5: 59f590ee75294f37ccb5ed1c7a441a11
SHA256: 59dbcc4618fa64eebd71808b16b4736b7af8855bef760aec3eb31c6f8f5f470e
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\lithuanian.xml
xml
MD5: 98f5a618f8cf3ca48774c15ca95bc2bb
SHA256: fb94b9381592015b27e12358c44a522409ec5c180fec694b2ddceff960294d0c
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\luxembourgish.xml
xml
MD5: cc2d7d26c9d221def534845ec7453ddb
SHA256: b73cb0703537af9d58c2e1f040f2e7f741199eef954d5e109eb301fc4498ffe0
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\ligurian.xml
xml
MD5: 58a86031153e6bd8ae1ad5bf80fcc894
SHA256: 5fad85ea1c785dca218106e2b409c20b3cb103e8cdc87c542aae5d630599c33b
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\japanese.xml
xml
MD5: 76e62d9c62bea373eb90bebf31da09e8
SHA256: 5333dbb1359c8428750442aa18279a4eb1f72e4568f1d43a4c2277ca825a5420
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\kannada.xml
xml
MD5: f0baf174376d1811fd49d05ace8eb0c6
SHA256: 99f75ff79aad8084802bf1d52e7dc78eef18194d399c5248eb205db85348955d
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\kurdish.xml
xml
MD5: 713c7613217038dead56ba13741d70b5
SHA256: 6a54a7235f8f4cbf5cb4c34f6bdf0bf9ee0d7e3ac62654d5c46e2fdf71868593
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\indonesian.xml
xml
MD5: 258f097d09f9878310e7900bb35cbff3
SHA256: bf7292893bd1700d22e328c4b542929122a027e504a179d7270637e5476befe5
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\gujarati.xml
xml
MD5: 5e8d9609900189b29b660d673a78e015
SHA256: 50c0e7a18c922bef1a758cff70d55df46913dddc22ca792e1b55b05a5b29c502
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\korean.xml
xml
MD5: a81c00ae49aeb5c5ded60220e6e42199
SHA256: 50b2b6820683551838ea1533d21624dac75daded6ce9d4227153a4f2986cdf4d
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\hungarian.xml
xml
MD5: b49cd98b5a75f5a2320427653a1a1782
SHA256: 951a0bd8e663bf9a43dbc7e083d7de92defab68836a07422033e4915765b1a86
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\italian.xml
xml
MD5: 384f12abbc790c175e57f873f3becfb2
SHA256: 500cfbf34b04f1299e61fe1473b73e0963024c53e6435e719b23298138d1d338
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\kazakh.xml
xml
MD5: 42d3d22d81645a44258aa730177896db
SHA256: 3942e9c344acae7caa9d28a758b4df80c1211bab80ac88d81449101f9b943c66
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\hindi.xml
xml
MD5: 4325a5b17ec69576fd080ebf39829c88
SHA256: 73dcf8bd373d63df5919aab42bb1bf0763b245d1a2b7ef31142b7d6cda7e5dc8
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\greek.xml
xml
MD5: 109f64488a006665d76621dcd30e7ef7
SHA256: d65afc086673dc165ce82dd831b5f04c75d7d43c50957475e1c90f25766ad5da
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\hebrew.xml
xml
MD5: 07c8ebe76b6352401c0e9c84956d727f
SHA256: 58585868a8164b247c53ad3646076e3404a4fd854ee3632ca9841c1ba3d210d6
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\kabyle.xml
xml
MD5: ec924dd39f1e36164ef4e93cd5883a2d
SHA256: 56714b11409a13fcd706f2d73674919a0bb70c80c7ec18eccf865ad67ad7b48f
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\friulian.xml
xml
MD5: 6d4c069b4c4517f68657be1641bec299
SHA256: d4ffe0a2b5e35fede7e6244be9823e1e946c60db1635e6d3f753e6df938e4b3d
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\estonian.xml
xml
MD5: a12e2854f772938fd4ccd55345dadd4b
SHA256: f71e4b0ba4fbf616af8f1568f2160d527b78fcf711132c4a38e0bd5378902237
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\german.xml
xml
MD5: 355b310c4e264a059f7ace7bf26ed8fa
SHA256: 95ebc8459d0c7e217e45a2062221832d0bae29eca359ec38b2e450913d16590e
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\esperanto.xml
xml
MD5: 4abf56d03e149ee0569619bbc11815a5
SHA256: e1486a8120d1ef7998b5335536a3a4877fdcb630f87ed9ca7b307ac075b313c6
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\galician.xml
xml
MD5: 191cc6b7ed37fad274f985d7329bd048
SHA256: 89a20e547d17b1006698cd35fbad772403033420808c8299206a8e299961d83e
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\farsi.xml
xml
MD5: 9ddc0ac1e17a56703a3e0a7acb8d0e2a
SHA256: d0acda01c7bb500072f00af882297d08a14821811931e862b5225bef97ab6336
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\french.xml
xml
MD5: 9f90a6c8c9db6894bb578f39014ecea0
SHA256: 497f8bf1660f90a8f0cd7f409c7a7df3cf2e040a8594bb039edf54e399fe61d2
852
svchost.exe
C:\Windows\appcompat\programs\RecentFileCache.bcf
txt
MD5: 12b7daaeac62822d64b1dc9cf00a1959
SHA256: d0b7f56e9304f87e9f14abf6c9d4349a9778c2fa788da8b62b5d31c286ca87a1
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\english_customizable.xml
xml
MD5: ba660fd5e124a627e7b5b1d53a6ceae5
SHA256: db1c55427bf83385e8713460d515d05aa79b9829be85515f1e46ab1a2cdc198b
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\finnish.xml
xml
MD5: 99d18eeaa47569147a0395948cb9c7d6
SHA256: 691d523b2a8c2ea14eb5e5259eed9e9de1853b2c2fd8badc77164f2cca2dd006
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\georgian.xml
xml
MD5: cada78594c9838103c479dbda55c9e05
SHA256: b319b96cb4eece88c0cf88b557ce56ce5abe85bdf0a6a1007b64310a708a6572
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\danish.xml
xml
MD5: afdca23414d2fa05e0edfed63dc68bd1
SHA256: 3ce52cb27a70640c8f4578ff52f71de18282d54ab91d1db7658be64c6a316d6c
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\corsican.xml
xml
MD5: 2762c8551adc0138beb86c304bd678df
SHA256: 9cc651eca1140c53634b1106a00bf8df96c8b4db49b68dbf165e1feae0740ee5
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\english.xml
xml
MD5: d8a7706a2beecb30ac7c3d3746a484b3
SHA256: 658973437807ed8450fbdf34b265ff0b9db7381a71888baeb0d42a72f6614111
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\catalan.xml
xml
MD5: be294c1890b57df605d743846802e835
SHA256: 03e2d93f71ae1b27d0695c14af7b820862737b4bf32ccc5fa29e68006ce32e32
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\bulgarian.xml
xml
MD5: 01672d373b82117e742b61dd94897777
SHA256: 72dd265c9ecca8d6630fef06215b6886f0a1991aa3f0fa5d1115cd761e1d0cbb
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\chinese.xml
xml
MD5: adfe78c0a6a1f7f940f0ffd5658b7a77
SHA256: 09ebf7a1fddcffecf9c678509112abdf049497494b933a4afd4cf8693b424d37
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\chineseSimplified.xml
xml
MD5: 8b1fd4c62d772ff4e2e8cd86f9daa996
SHA256: db470e2927688c424ba8a3838d673b8fe42699e51a4e1b4e9c8824089b3b337d
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\brazilian_portuguese.xml
xml
MD5: c5ac706ffe3cc6abb54272e49d42de5d
SHA256: 690897901b9880c4b4247d5a75140f4ef9804fddd4b1ffe6fbc89d4f9952e520
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\breton.xml
xml
MD5: a28d31b3147d47670455aa249df9e3a8
SHA256: 7d8569dca0eef5ccd411287ed72f70da19f92b96e05e2bfd294263098e3ed38d
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\czech.xml
xml
MD5: 40fb19e6e72098f1fcc013562e210d4c
SHA256: e2f164416ddf1f6c09bbc8c33600886f35116c170a9837c940bf1c4e1a75eafa
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\croatian.xml
xml
MD5: cec164119c1295583fe3326f6710253c
SHA256: 12fe4e0941c20088f10a19487aeddc57ca96ff8ace34ccfbc2cfcb2388c17173
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\bosnian.xml
xml
MD5: 6b036835ed9d1ee92cd9bd4c76f41bbd
SHA256: 06ce39e85fc9acd72888da5871fae4d18aa2c5bb6a9fa0c9eca459cf0e949a63
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\dutch.xml
xml
MD5: 6ce9f0ae41286f01ccf83b64d48cc238
SHA256: 4dc9faf1ba2806b6ff3f70264c46e2d70007af6f5dafe6fe9d306c3c07eda610
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\bengali.xml
xml
MD5: d081b39bf7a87b8ccd3caa5e9d15087c
SHA256: 5ecd5febabcb4b4616035fab1b567bf2a0ff8b2ded72d74e6ea5511671814484
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\basque.xml
xml
MD5: 7ef1dd1b3280122bac0a69063249fd46
SHA256: 1047a56b9ea18bafbb7fd03daa190cb980883694dfd7fc1556136ab81834d489
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\aragonese.xml
xml
MD5: ff161db746ade330439882ba0640d2ea
SHA256: 1db8eeb9c6cae8705cacfc3043a7556678e9ed52162fb8ec536c5befc19343a9
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\arabic.xml
xml
MD5: 4c43fa51c53e259e9c0df42eab235849
SHA256: f4bb70b47614e639d2035ecf94e4f74413312f7ae593d60a916d940cf3639554
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\belarusian.xml
xml
MD5: fd060d45654fa3adec00f943349a535b
SHA256: 1c616bcd978b6f7feb5035c232024baa895f9787183898e4672f70ea3d1ded9c
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\albanian.xml
xml
MD5: 5803d49d9a1320f50394a0ab36c427b6
SHA256: 508ddd0bd359666186a34b1249b55de31062f2eb4323bce01409e602e7fc0b64
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\afrikaans.xml
xml
MD5: c2f475cc2b49d3aee490c9059529744a
SHA256: 5d285d98f8891bcf73a770fde00c3215062842224b81c4e70537569712f84570
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\azerbaijani.xml
xml
MD5: 8cd5c70b03ef9c48585c06fa149f9fcd
SHA256: d2e185e9c8b1e7d994dcb3b44748f1b499f18ca22a573f452a9b0d791344c448
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\nppLocalization\aranese.xml
xml
MD5: 333a18acb93ba083e86679c065b69d15
SHA256: de5da809aa6e44c4e6a01c3b5fb7da5a66d9683cb905416f3fcff2ed413ea7c6
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsrA166.tmp
––
MD5:  ––
SHA256:  ––
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\localization\english.xml
xml
MD5: d8a7706a2beecb30ac7c3d3746a484b3
SHA256: 658973437807ed8450fbdf34b265ff0b9db7381a71888baeb0d42a72f6614111
408
notepad++.exe
C:\Users\admin\AppData\Roaming\Notepad++\plugins\Config\converter.ini
text
MD5: f70f579156c93b097e656caba577a5c9
SHA256: b926498a19ca95dc28964b7336e5847107dd3c0f52c85195c135d9dd6ca402d4
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Roaming\Notepad++\userDefineLangs\userDefinedLang-markdown.default.modern.xml
text
MD5: e6edb9c859b5b97800da9c664a0606c8
SHA256: b7a3e70c69f661e76cc7b6279db21fb32f275a8a3c205a75ae22e40224136031
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\change.log
text
MD5: a22774dd659f1995936abf93a601b052
SHA256: 66c4cc847e2f75699b54b54edbc5625d425a1b0856cf991153b9d167dae8540d
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\readme.txt
text
MD5: 5c52adcd2bcc000a8b4bd5eb36b84cde
SHA256: f09758a2c953bdd2b817441e9a00255d3685c99369468c2695f0ca39aaaa5e6b
852
svchost.exe
C:\Windows\appcompat\programs\RecentFileCache.bcf
txt
MD5: 16c244c8c678eb02e71992e125b1260b
SHA256: 92eeea4b4ce5441be7be507f51b2f879bb7b095c1372dfba41dd321dc27d4147
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\functionList.xml
xml
MD5: bd8d804a62a5b9392885a6904033f0bf
SHA256: ea1e92c06735a137cd03c36a252027c013e9224dd3013fbe3ddd5c5c0098b2b9
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\stylers.model.xml
xml
MD5: 46fc329be6615da0c27f5bbc80fad64c
SHA256: 5f57890b3f39889ac6ca376ab1debf5d2ae2df531c5284f70e13f6106204cb83
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\langs.model.xml
xml
MD5: e77c570ce893a40a76ac0f1b75d8c9f7
SHA256: edfd1ba2ed1f8b75aa95c4eed0a574f88787b60c8f5466182a90141819dc1d68
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\LICENSE
text
MD5: 397ad6fd5743ecc1826add6ea0fb0af4
SHA256: b2a74140769dc8bd34cb72bd2d177e58522e69427f39651b738011f244f835bd
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\contextMenu.xml
xml
MD5: a7998766b85ee71ff1d82a1198988529
SHA256: aa48a7c2ec3ed377c42c293f732807572f2ea305c9771b6ea210e7b92ef2c199
408
notepad++.exe
C:\Users\admin\AppData\Roaming\Notepad++\shortcuts.xml
text
MD5: ad21a64014891793dd9b21d835278f36
SHA256: c24699c9d00abdd510140fe1b2ace97bfc70d8b21bf3462ded85afc4f73fe52f
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\updater\README.md
text
MD5: 9f56b12cbffcfad543fb1f91e3955f1b
SHA256: aef40520cf12a0842097e8cfbeb9d9128f52573e5f90ca12d4a0a9045978547e
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\updater\LICENSE
text
MD5: 8e3494bf8cf1967afd3b1016fbbe5bb0
SHA256: 319917f5ccd09878db6f67c9a77dee846055644ca49eb535628b9e020a87261e
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\updater\gup.xml
xml
MD5: b023cc4d768b34a5401f317479740a53
SHA256: d3e6404c7286961cbab82d4c49f82bcb166db9b5a13eacaa0eeb59a0709a0c14
408
notepad++.exe
C:\Users\admin\AppData\Roaming\Notepad++\stylers.xml
xml
MD5: 46fc329be6615da0c27f5bbc80fad64c
SHA256: 5f57890b3f39889ac6ca376ab1debf5d2ae2df531c5284f70e13f6106204cb83
408
notepad++.exe
C:\Users\admin\AppData\Roaming\Notepad++\langs.xml
xml
MD5: e77c570ce893a40a76ac0f1b75d8c9f7
SHA256: edfd1ba2ed1f8b75aa95c4eed0a574f88787b60c8f5466182a90141819dc1d68
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\ioSpecial.ini
text
MD5: 8a440898d04e7e5fd21d745c79a4459a
SHA256: d1db74bb8e579bdad4d08b4ae688bec2cc355528b3fefc4f6c7c8cc7d76a9c66
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\autoCompletion\autoit.xml
xml
MD5: 24091974377d7e76106add1210d5853a
SHA256: 07cb7ea3f8d1eee1142bcdf876e29f14e6ae2a72ef28f2310263da531c7e8711
276
explorer.exe
C:\Users\admin\AppData\Local\IconCache.db
binary
MD5: 4743bf48f886ee04803001ef4d04ea01
SHA256: d2f9a3f64a058308b157e82159cc872bbaa87c1b537774fed9bd2127934c48ba
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\autoCompletion\lua.xml
xml
MD5: bdb4f044ba52f6a83953ffd659c9252a
SHA256: 3daa67cc9dd0370566566ce0492597a3698b7d9edd361a759c58e1fbd7abb349
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\autoCompletion\cmake.xml
xml
MD5: 6c33239d9a59e3b2aa74913b117b2342
SHA256: 55f04796c0dfb130cf438a01ae8e7f96d99a9320a2d9c8e66a9a670640ca5cc9
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\autoCompletion\BaanC.xml
xml
MD5: 2537a01a4619a19962fb1b85cbee9a13
SHA256: 9780d21f36eca4cb7f85c67fe9113c3c223822662812f6ab533c011cd2f56e7e
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\autoCompletion\coffee.xml
xml
MD5: 633f1e56a9f5b7e1c7c75e6dff944b25
SHA256: 46d379e7ad5565fc197a32b62d04ceb1be4452af2ae45663415809bc7badb0bd
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\autoCompletion\nsis.xml
xml
MD5: 7985ac923ccbf94742d29d96c405c843
SHA256: 5c1482f16fc8a1b99ec87eb4edef5c1d3f2d1c750f1647416369c6124498ad3e
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\autoCompletion\batch.xml
xml
MD5: 713831a4916810500b39efbdb41435a2
SHA256: d43ce011aa2d5a946c36b4c3a6a0a98fd9570253bc461a267d3b44aaec3cb6b0
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\autoCompletion\tex.xml
xml
MD5: 03f74d2063099160e73faa1a5dee7f9a
SHA256: d19fe5a6b68b50e0820641489fd73368ba4ba58adb07948e39073ddce8e08d37
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\autoCompletion\vhdl.xml
xml
MD5: 1ba07e9e9c7ccbf095fee8c248375527
SHA256: 29967c6650ce9fce73b7b9dda3390ae3b5cff4ad8ef2265f2c6980da55f42f97
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\autoCompletion\lisp.xml
xml
MD5: 310ae71e554b99a4c71b546097de55c0
SHA256: 83478867f319bf093ce02f0c98a88b183862c235025580cca9ec7a9515521833
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\autoCompletion\xml.xml
xml
MD5: 432b0a7d34b59ad7512c347f8670ff23
SHA256: 7cdfb59901b0dbda488745f9bd749ce9a1c3e228931162e3a5764c5674330601
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\autoCompletion\python.xml
xml
MD5: 7bedd66d0b8a71da1467f63db6184420
SHA256: cc27e0ea6542eb7bb249d169f42f9ac6fcbb794c2ef5d85f2b502e124ceef916
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\autoCompletion\perl.xml
xml
MD5: 244eb5c1e91dc112130252fe58e49b13
SHA256: e38a882b09330b6dbd56a2a4a90882c371a3c3eb7d29ceae9520a647c185b627
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\autoCompletion\actionscript.xml
xml
MD5: f8876462309eeb4204eaaf5777dc4eea
SHA256: 7bdab6f3b572773331a17bfbb6cc4bbd71dfd89e4f11e404b7466925678a3a26
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\autoCompletion\javascript.xml
xml
MD5: 30fc91a7c5194ef8d67e1c7e2fd6f697
SHA256: 7f0564f983478207754a58e66ee6865b8699bd3b9f4fd5c385126d46d7148831
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\autoCompletion\vb.xml
xml
MD5: cb6d0cff9916fa1eae0a4faafc9db82a
SHA256: 74b6701e0c8f2c92eedd563165b61d4813f519f3747b67b3a043a4b85de41401
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\autoCompletion\php.xml
xml
MD5: 1e9d31476dddc00249463ede7ba491d7
SHA256: 43391307f2829b77df05725a13670f6ad0650f8b92b4503cba65d7901e1dda10
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\autoCompletion\css.xml
xml
MD5: d2affd6da8aa4fd9457db7b0dcb87517
SHA256: 776187ab9beec87648e5701137f153adeef88c579b15b181c5d4eee2f02262f8
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\autoCompletion\sql.xml
xml
MD5: 056b92b4d2e16984505990cf379b5486
SHA256: 620fe159db5ce323b78b4768f9f6a3a95ca2c4fa4806ea5145afadac21dcc74d
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\autoCompletion\rc.xml
xml
MD5: 12b972b69130e664e50ac111d298379b
SHA256: 12ad067aa1227b92141bbf9faca8efa74549cff6dabde85899db9272eb7e2dff
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\autoCompletion\java.xml
xml
MD5: 4690cead3d2bffe2ed519f6ea5002266
SHA256: 862a83be2906ce28b6d3f1fdfb589d18cd6e971a7eaa51a1c7096cfff929b35b
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\autoCompletion\cs.xml
xml
MD5: c9bc2acde59532d2a9b65e7f9cd55d4f
SHA256: 32076a244afd75a07cd38f1fa27b08eea3a4a697111cde8a1cb636c46c708c17
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\autoCompletion\html.xml
xml
MD5: 4025e1158c027cf56c2625e65eb724ec
SHA256: 4300b3a71f387c91548984d017033884e176546ad5b74bac2e4df59caa163530
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\autoCompletion\cpp.xml
xml
MD5: e60ca42b12a8e816892894d321ab8d00
SHA256: b97ffa556f93ec4c51208b2aea4f3d69411404c27f6ea12608ae84bedbd76418
2624
npp.7.7.1.Installer.exe
C:\Program Files\Notepad++\autoCompletion\c.xml
xml
MD5: c92c0a8fa14eb590fdc13287b26689db
SHA256: 2ad09d23098049d7541c703684bca446ccf6f1024a182e7dc30c378efb1b2109
408
notepad++.exe
C:\Users\admin\AppData\Roaming\Notepad++\config.xml
xml
MD5: df9a1844bb482fa3f2372f2925333f22
SHA256: d03cd2e8275f3d18bdf894b4301a00e4d0a551f4c33f1dcf1191b571376e1942
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\ioSpecial.ini
text
MD5: f3a17f770a7c033ae1a437ad622b63b6
SHA256: 2ca06e9ca24ac9f22495c5ff2be17d8b48813147c9fc9f2b258b0a1c71d0f6bc
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\ioSpecial.ini
text
MD5: cbb9a2bc1ef4dbb61fe57108860b3746
SHA256: 9fdb9e92ae8826aa8952cabcfab5f11219212b8f7220eeeb812d151adbba9782
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\modern-header.bmp
image
MD5: 56da15fdb8d96f8f5c649dcb5e79d775
SHA256: bb90d4338d2474138473e6b16e94b0237ee847bea45019ed0dd4439c71bd233e
2624
npp.7.7.1.Installer.exe
C:\Users\admin\AppData\Local\Temp\nswA186.tmp\modern-wizard.bmp
image
MD5: c2cf6928a3ab574a5548b4dc1c38b6c0
SHA256: 2125550c12fa512782f2016e802d70bc51f4a06017cfbd4176b4a994eb2542f0
2624
npp.7.7.1.Installer.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++.lnk
lnk
MD5: bad10cb28933508709cbe37b33cc9342
SHA256: 8605d3d608c79dba60c3ddbae170d5fe2748eaa34121ba2a0944861b6ea6dc79
2624
npp.7.7.1.Installer.exe
C:\Users\Public\Desktop\Notepad++.lnk
lnk
MD5: 3fd19f964983c47505c98d467f96a71e
SHA256: abd39e4457fcc25d1ff58a5cecff9abb65f24dce13978fc04e83f52fb83cae43
408
notepad++.exe
C:\Users\admin\AppData\Roaming\Notepad++\session.xml
text
MD5: b0f20c6670209b8402e0c1102f7d3aef
SHA256: 767c95c4e748234c92e6176865b7428f347792d8d831bab22009827305830110
276
explorer.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x000000000000001c.db
binary
MD5: c156da38d6c46988b19e54ec7f3ac7cd
SHA256: fac68cb7c6e7ed30f7ecad7eef4867fb3d3d18a2ad35d371aaf701e8fd96e073

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
0
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

No HTTP requests.

Connections

PID Process IP ASN CN Reputation
3784 gup.exe 37.59.28.236:443 OVH SAS FR whitelisted

DNS requests

Domain IP Reputation
notepad-plus-plus.org 37.59.28.236
whitelisted

Threats

No threats detected.

Debug output strings

Process Message
notepad++.exe ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe ED255D9151912E40DF048A56288E969A8D0DAFA3