General Info

File name

thhjgjk.exe

Full analysis
https://app.any.run/tasks/226e4ff1-50f5-49f7-aeae-854ea0b901e8
Verdict
Malicious activity
Analysis date
4/15/2019, 08:08:07
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

9d6d30a67013a7853e8055770b9e0cb4

SHA1

6a93ea252a6d08d32ba18255d347b9e7bc0f8c43

SHA256

6cb18148a9f9b7e810975b1eccc74ae1e9d1785c80408090706f69e2957ad217

SSDEEP

98304:h9U0Sp0651HvOIGbQyGUu2wJuKSfUvOpgZs4Jni:ND82IGUzX2MofTAJni

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (73.0.3683.75)
  • Google Update Helper (1.3.33.23)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 65.0.2 (x86 en-US) (65.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads the Task Scheduler COM API
  • dreamplan.exe (PID: 2660)
  • nchsetup.exe (PID: 3888)
  • dreamplan.exe (PID: 4044)
Application was dropped or rewritten from another process
  • dreamplan.exe (PID: 3232)
  • dreamplan.exe (PID: 2660)
  • nchsetup.exe (PID: 3888)
  • dreamplan.exe (PID: 2748)
  • dreamplan.exe (PID: 4044)
  • zlib1.exe (PID: 3420)
  • infozip3.exe (PID: 1912)
Starts Internet Explorer
  • dreamplan.exe (PID: 2748)
Modifies files in Chrome extension folder
  • chrome.exe (PID: 2652)
Executable content was dropped or overwritten
  • infozip3.exe (PID: 1912)
  • nchsetup.exe (PID: 3888)
  • thhjgjk.exe (PID: 2412)
  • zlib1.exe (PID: 3420)
Creates files in the user directory
  • dreamplan.exe (PID: 2748)
Creates a software uninstall entry
  • nchsetup.exe (PID: 3888)
Starts itself from another location
  • nchsetup.exe (PID: 3888)
Creates files in the program directory
  • infozip3.exe (PID: 1912)
  • zlib1.exe (PID: 3420)
  • nchsetup.exe (PID: 3888)
Modifies the open verb of a shell class
  • nchsetup.exe (PID: 3888)
Adds / modifies Windows certificates
  • iexplore.exe (PID: 3600)
Reads settings of System Certificates
  • iexplore.exe (PID: 3600)
Reads Internet Cache Settings
  • iexplore.exe (PID: 2168)
Application launched itself
  • iexplore.exe (PID: 3600)
  • chrome.exe (PID: 2652)
Reads internet explorer settings
  • iexplore.exe (PID: 2168)
Changes settings of System certificates
  • iexplore.exe (PID: 3600)
Creates files in the user directory
  • FlashUtil32_26_0_0_131_ActiveX.exe (PID: 3680)
  • iexplore.exe (PID: 2168)
Changes internet zones settings
  • iexplore.exe (PID: 3600)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable MS Visual C++ (generic) (67.4%)
.dll
|   Win32 Dynamic Link Library (generic) (14.2%)
.exe
|   Win32 Executable (generic) (9.7%)
.exe
|   Generic Win/DOS Executable (4.3%)
.exe
|   DOS Executable Generic (4.3%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2014:12:18 01:47:27+01:00
PEType:
PE32
LinkerVersion:
8
CodeSize:
1536
InitializedDataSize:
4144640
UninitializedDataSize:
null
EntryPoint:
0x11d4
OSVersion:
4
ImageVersion:
null
SubsystemVersion:
4
Subsystem:
Windows GUI
FileVersionNumber:
0.0.0.0
ProductVersionNumber:
0.0.0.0
FileFlagsMask:
0x0017
FileFlags:
(none)
FileOS:
Win32
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
English (Australian)
CharacterSet:
Unicode
CompanyName:
NCH Software
FileDescription:
DreamPlan Home Design Software
FileVersion:
1.31
ProductVersion:
1.31
ProductName:
DreamPlan
LegalCopyright:
NCH Software
InternalName:
DreamPlan
OriginalFileName:
DreamPlan.exe
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
18-Dec-2014 00:47:27
Detected languages
English - Australia
CompanyName:
NCH Software
FileDescription:
DreamPlan Home Design Software
FileVersion:
1.31
ProductVersion:
1.31
ProductName:
DreamPlan
LegalCopyright:
NCH Software
InternalName:
DreamPlan
OriginalFilename:
DreamPlan.exe
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x000000D8
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
5
Time date stamp:
18-Dec-2014 00:47:27
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x0000058B 0x00000600 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 5.55311
.rdata 0x00002000 0x000008BA 0x00000A00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 3.86466
.data 0x00003000 0x00000004 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0.0611629
.rsrc 0x00004000 0x003F2EC4 0x003F3000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 7.99969
.reloc 0x003F7000 0x00000124 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_DISCARDABLE,IMAGE_SCN_MEM_READ 2.02672
Resources
1

2

95

99

Imports
    SETUPAPI.dll

    ole32.dll

    SHELL32.dll

    USER32.dll

    KERNEL32.dll

Exports

    No exports.

Screenshots

Processes

Total processes
62
Monitored processes
27
Malicious processes
4
Suspicious processes
1

Behavior graph

+
drop and start start drop and start drop and start drop and start drop and start thhjgjk.exe no specs thhjgjk.exe nchsetup.exe zlib1.exe infozip3.exe dreamplan.exe no specs dreamplan.exe no specs iexplore.exe iexplore.exe flashutil32_26_0_0_131_activex.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs dreamplan.exe no specs dreamplan.exe no specs chrome.exe no specs chrome.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
2744
CMD
"C:\Users\admin\AppData\Local\Temp\thhjgjk.exe"
Path
C:\Users\admin\AppData\Local\Temp\thhjgjk.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
NCH Software
Description
DreamPlan Home Design Software
Version
1.31
Modules
Image
c:\users\admin\appdata\local\temp\thhjgjk.exe
c:\systemroot\system32\ntdll.dll

PID
2412
CMD
"C:\Users\admin\AppData\Local\Temp\thhjgjk.exe"
Path
C:\Users\admin\AppData\Local\Temp\thhjgjk.exe
Indicators
Parent process
––
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
NCH Software
Description
DreamPlan Home Design Software
Version
1.31
Modules
Image
c:\users\admin\appdata\local\temp\thhjgjk.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\propsys.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\sspicli.dll
c:\users\admin\appdata\local\temp\n1s\nchsetup.exe
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\mpr.dll

PID
3888
CMD
"C:\Users\admin\AppData\Local\Temp\n1s\nchsetup.exe" -installer "C:\Users\admin\AppData\Local\Temp\thhjgjk.exe" -instdata "C:\Users\admin\AppData\Local\Temp\n1s\nchdata.dat"
Path
C:\Users\admin\AppData\Local\Temp\n1s\nchsetup.exe
Indicators
Parent process
thhjgjk.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
NCH Software
Description
DreamPlan Home Design Software
Version
1.31
Modules
Image
c:\users\admin\appdata\local\temp\n1s\nchsetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\d3d9.dll
c:\windows\system32\version.dll
c:\windows\system32\d3d8thk.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\opengl32.dll
c:\windows\system32\glu32.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\duser.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\profapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\apphelp.dll
c:\program files\nch software\dreamplan\zlib1.exe
c:\program files\nch software\dreamplan\infozip3.exe
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\program files\nch software\dreamplan\dreamplan.exe
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\taskschd.dll

PID
3420
CMD
"C:\Program Files\NCH Software\DreamPlan\zlib1.exe" -LQUIET -instby fiDreamPlan
Path
C:\Program Files\NCH Software\DreamPlan\zlib1.exe
Indicators
Parent process
nchsetup.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\program files\nch software\dreamplan\zlib1.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\devrtl.dll

PID
1912
CMD
"C:\Program Files\NCH Software\DreamPlan\infozip3.exe" -LQUIET -instby fiDreamPlan
Path
C:\Program Files\NCH Software\DreamPlan\infozip3.exe
Indicators
Parent process
nchsetup.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\program files\nch software\dreamplan\infozip3.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\devrtl.dll

PID
2748
CMD
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe"
Path
C:\Program Files\NCH Software\DreamPlan\dreamplan.exe
Indicators
No indicators
Parent process
nchsetup.exe
User
admin
Integrity Level
MEDIUM
Exit code
1
Version:
Company
NCH Software
Description
DreamPlan Home Design Software
Version
1.31
Modules
Image
c:\program files\nch software\dreamplan\dreamplan.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\d3d9.dll
c:\windows\system32\version.dll
c:\windows\system32\d3d8thk.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\opengl32.dll
c:\windows\system32\glu32.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\msasn1.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\asycfilt.dll
c:\windows\system32\profapi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\duser.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wscapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\program files\internet explorer\iexplore.exe

PID
4044
CMD
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -installsched
Path
C:\Program Files\NCH Software\DreamPlan\dreamplan.exe
Indicators
No indicators
Parent process
nchsetup.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
NCH Software
Description
DreamPlan Home Design Software
Version
1.31
Modules
Image
c:\program files\nch software\dreamplan\dreamplan.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\d3d9.dll
c:\windows\system32\version.dll
c:\windows\system32\d3d8thk.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\opengl32.dll
c:\windows\system32\glu32.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\xmllite.dll

PID
3600
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" -nohome
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
dreamplan.exe
User
admin
Integrity Level
MEDIUM
Exit code
1
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\cryptbase.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\ieui.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\clbcatq.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\url.dll
c:\windows\system32\version.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\propsys.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\msfeeds.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\mlang.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\credssp.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\linkinfo.dll

PID
2168
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3600 CREDAT:71937
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
iexplore.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\psapi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\comdlg32.dll
c:\program files\internet explorer\ieshims.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rsaenh.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mlang.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\apphelp.dll
c:\program files\java\jre1.8.0_92\bin\ssv.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\version.dll
c:\progra~1\micros~1\office14\urlredir.dll
c:\windows\system32\secur32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\progra~1\micros~1\office14\msohev.dll
c:\program files\java\jre1.8.0_92\bin\jp2ssv.dll
c:\program files\java\jre1.8.0_92\bin\msvcr100.dll
c:\program files\java\jre1.8.0_92\bin\deploy.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\sxs.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\credssp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\p2pcollab.dll
c:\windows\system32\qagentrt.dll
c:\windows\system32\fveui.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\feclient.dll
c:\windows\system32\imgutil.dll
c:\windows\system32\iepeers.dll
c:\windows\system32\winspool.drv
c:\windows\system32\pngfilt.dll
c:\windows\system32\jscript.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\macromed\flash\flash32_26_0_0_131.ocx
c:\windows\system32\winmm.dll
c:\windows\system32\dsound.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\mscms.dll
c:\windows\system32\dinput8.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\devrtl.dll

PID
3680
CMD
C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exe -Embedding
Path
C:\Windows\system32\Macromed\Flash\FlashUtil32_26_0_0_131_ActiveX.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Adobe Systems Incorporated
Description
Adobe® Flash® Player Installer/Uninstaller 26.0 r0
Version
26,0,0,131
Modules
Image
c:\windows\system32\macromed\flash\flashutil32_26_0_0_131_activex.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\secur32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\version.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\riched20.dll
c:\windows\system32\cryptui.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\ws2help.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\psapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\macromed\flash\flashutil32_26_0_0_131_activex.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\dinput8.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mlang.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll

PID
2652
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe"
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Google Inc.
Description
Google Chrome
Version
73.0.3683.75
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ole32.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\hid.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\credui.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\winusb.dll
c:\windows\system32\msi.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\mscms.dll
c:\windows\system32\winsta.dll
c:\windows\system32\wlanapi.dll
c:\windows\system32\wlanutil.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\wpc.dll
c:\windows\system32\samlib.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\firewallapi.dll
c:\windows\system32\kbdus.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\wship6.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\imagehlp.dll
c:\program files\winrar\rarext.dll
c:\program files\microsoft office\office14\olkfstub.dll
c:\progra~1\micros~1\office14\mlshext.dll
c:\program files\microsoft office\office14\onfilter.dll
c:\program files\microsoft office\office14\visshe.dll
c:\program files\common files\microsoft shared\office14\msoshext.dll
c:\program files\microsoft office\office14\msohevi.dll
c:\windows\system32\mf.dll
c:\windows\system32\shdocvw.dll
c:\program files\filezilla ftp client\fzshellext.dll
c:\windows\system32\syncui.dll
c:\program files\notepad++\nppshell_06.dll
c:\program files\windows sidebar\sbdrop.dll
c:\windows\system32\stobject.dll
c:\windows\system32\cryptext.dll
c:\windows\system32\colorui.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_child.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\winspool.drv
c:\windows\system32\comdlg32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll

PID
1892
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=73.0.3683.75 --initial-client-data=0x7c,0x80,0x84,0x78,0x88,0x6f390f18,0x6f390f28,0x6f390f34
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Google Inc.
Description
Google Chrome
Version
73.0.3683.75
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll

PID
680
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=2292 --on-initialized-event-handle=308 --parent-handle=312 /prefetch:6
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Google Inc.
Description
Google Chrome
Version
73.0.3683.75
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ole32.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_watcher.dll

PID
2920
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=984,10471421602987816216,9195365636733696653,131072 --enable-features=PasswordImport --gpu-preferences=KAAAAAAAAACAAwAAAQAAAAAAAAAAAGAAAAAAAAEAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=13137580520778189954 --mojo-platform-channel-handle=960 --ignored=" --type=renderer " /prefetch:2
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Version:
Company
Google Inc.
Description
Google Chrome
Version
73.0.3683.75
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dxva2.dll
c:\program files\google\chrome\application\73.0.3683.75\d3dcompiler_47.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\program files\google\chrome\application\73.0.3683.75\swiftshader\libglesv2.dll
c:\program files\google\chrome\application\73.0.3683.75\swiftshader\libegl.dll

PID
1528
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=984,10471421602987816216,9195365636733696653,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=network --service-request-channel-token=2492864280029478442 --mojo-platform-channel-handle=1520 /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Google Inc.
Description
Google Chrome
Version
73.0.3683.75
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ntmarta.dll

PID
3956
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=984,10471421602987816216,9195365636733696653,131072 --enable-features=PasswordImport --service-pipe-token=8362495666016400075 --lang=en-US --instant-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=8362495666016400075 --renderer-client-id=6 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2012 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Version:
Company
Google Inc.
Description
Google Chrome
Version
73.0.3683.75
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
1904
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=984,10471421602987816216,9195365636733696653,131072 --enable-features=PasswordImport --service-pipe-token=14287177073372191272 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=14287177073372191272 --renderer-client-id=7 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2144 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Version:
Company
Google Inc.
Description
Google Chrome
Version
73.0.3683.75
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
1496
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=984,10471421602987816216,9195365636733696653,131072 --enable-features=PasswordImport --service-pipe-token=18273682474355044070 --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=18273682474355044070 --renderer-client-id=4 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2316 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
73.0.3683.75
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
2112
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=984,10471421602987816216,9195365636733696653,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=9818927836897056484 --mojo-platform-channel-handle=3080 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
73.0.3683.75
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3444
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=984,10471421602987816216,9195365636733696653,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=5170061697397386687 --mojo-platform-channel-handle=3204 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
73.0.3683.75
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3984
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=984,10471421602987816216,9195365636733696653,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=15702344400985119975 --mojo-platform-channel-handle=3192 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
73.0.3683.75
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
1372
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=984,10471421602987816216,9195365636733696653,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=11726258901282103827 --mojo-platform-channel-handle=3296 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
73.0.3683.75
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3828
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --field-trial-handle=984,10471421602987816216,9195365636733696653,131072 --enable-features=PasswordImport --lang=en-US --service-sandbox-type=utility --service-request-channel-token=11669002125412677185 --mojo-platform-channel-handle=3300 --ignored=" --type=renderer " /prefetch:8
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
73.0.3683.75
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

PID
3232
CMD
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -suite
Path
C:\Program Files\NCH Software\DreamPlan\dreamplan.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
NCH Software
Description
DreamPlan Home Design Software
Version
1.31
Modules
Image
c:\program files\nch software\dreamplan\dreamplan.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\d3d9.dll
c:\windows\system32\version.dll
c:\windows\system32\d3d8thk.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\opengl32.dll
c:\windows\system32\glu32.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\cryptbase.dll

PID
2660
CMD
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe"
Path
C:\Program Files\NCH Software\DreamPlan\dreamplan.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
1
Version:
Company
NCH Software
Description
DreamPlan Home Design Software
Version
1.31
Modules
Image
c:\program files\nch software\dreamplan\dreamplan.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\d3d9.dll
c:\windows\system32\version.dll
c:\windows\system32\d3d8thk.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\opengl32.dll
c:\windows\system32\glu32.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\asycfilt.dll
c:\windows\system32\profapi.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\duser.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\psapi.dll

PID
3504
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=984,10471421602987816216,9195365636733696653,131072 --enable-features=PasswordImport --disable-gpu-sandbox --use-gl=disabled --gpu-preferences=KAAAAAAAAACAAwAAAQAAAAAAAAAAAGAAAAAAAAEAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=6542280493724198755 --mojo-platform-channel-handle=3424 /prefetch:2
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Google Inc.
Description
Google Chrome
Version
73.0.3683.75
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\avrt.dll
c:\windows\system32\ksuser.dll
c:\windows\system32\msmpeg2vdec.dll
c:\windows\system32\evr.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\slc.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\dxva2.dll

PID
2456
CMD
"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=984,10471421602987816216,9195365636733696653,131072 --enable-features=PasswordImport --disable-gpu-compositing --service-pipe-token=1672968582392971916 --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=1672968582392971916 --renderer-client-id=14 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2724 /prefetch:1
Path
C:\Program Files\Google\Chrome\Application\chrome.exe
Indicators
No indicators
Parent process
chrome.exe
User
admin
Integrity Level
LOW
Version:
Company
Google Inc.
Description
Google Chrome
Version
73.0.3683.75
Modules
Image
c:\program files\google\chrome\application\chrome.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\google\chrome\application\73.0.3683.75\chrome_child.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dbghelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\cryptbase.dll

Registry activity

Total events
1442
Read events
1015
Write events
422
Delete events
5

Modification events

PID
Process
Operation
Key
Name
Value
1528
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
LanguageList
en-US
2412
thhjgjk.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2412
thhjgjk.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3888
nchsetup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Name
nchsetup.exe
3888
nchsetup.exe
write
HKEY_CURRENT_USER\Software\NCH Software\DreamPlan\Settings
InstalledByAdmin
1
3888
nchsetup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3888
nchsetup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3888
nchsetup.exe
write
HKEY_CURRENT_USER\Software\NCH Software\DreamPlan\Settings
InstallerPath
C:\Program Files\NCH Software\DreamPlan
3888
nchsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\NCH Software\DreamPlan\Settings
InstallerPath
C:\Program Files\NCH Software\DreamPlan
3888
nchsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DreamPlan
DisplayName
DreamPlan Home Design Software
3888
nchsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DreamPlan
Publisher
NCH Software
3888
nchsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DreamPlan
UninstallString
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -uninstall
3888
nchsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DreamPlan
DisplayIcon
C:\Program Files\NCH Software\DreamPlan\dreamplan.exe
3888
nchsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DreamPlan
Version
1.31
3888
nchsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DreamPlan
DisplayVersion
1.31
3888
nchsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DreamPlan
URLInfoAbout
www.nchsoftware.com/design/support.html
3888
nchsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DreamPlan
URLUpdateInfo
www.nchsoftware.com/design/index.html
3888
nchsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DreamPlan
VersionMajor
1
3888
nchsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DreamPlan
VersionMinor
31
3888
nchsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DreamPlan
InstallLocation
C:\Program Files\NCH Software\DreamPlan
3888
nchsetup.exe
write
HKEY_CURRENT_USER\Software\NCH Software\DreamPlan\Settings
UseMetric
0
3888
nchsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\NCH Software\DreamPlan\Capabilities\FileAssociations
.ddp
NCH.DreamPlan.ddp
3888
nchsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\NCH Software\DreamPlan\Capabilities
ApplicationDescription
DreamPlan Home Design Software
3888
nchsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\RegisteredApplications
DreamPlan
Software\NCH Software\DreamPlan\Capabilities
3888
nchsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\NCH.DreamPlan.ddp
DreamPlan Home Design Software
3888
nchsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\NCH.DreamPlan.ddp\DefaultIcon
C:\Program Files\NCH Software\DreamPlan\dreamplan.exe,0
3888
nchsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\NCH.DreamPlan.ddp\shell
Open
3888
nchsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\NCH.DreamPlan.ddp\shell\open\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" "%L"
3888
nchsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\dreamplan.exe\shell\open\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" "%L"
3888
nchsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\dreamplan.exe\shell
Open
3888
nchsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\dreamplan.exe\DefaultIcon
C:\Program Files\NCH Software\DreamPlan\dreamplan.exe,0
3888
nchsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\dreamplan.exe
DreamPlan Home Design Software
3888
nchsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.ddp\OpenWithProgIds
NCH.DreamPlan.ddp
3888
nchsetup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ddp\UserChoice
Progid
NCH.DreamPlan.ddp
3888
nchsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
57
3888
nchsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.ddp
DreamPlan.BAK
3888
nchsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.ddp
NCH.DreamPlan.ddp
3888
nchsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
58
3888
nchsetup.exe
write
HKEY_CURRENT_USER\Software\NCH Software\DreamPlan\Settings
CheckForDownloadContent
1
3888
nchsetup.exe
write
HKEY_CURRENT_USER\Software\NCH Software\DreamPlan\Settings
IsGridOn
1
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\Windows.IsoFile\shell\open\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind ExpressBurn "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\Windows.IsoFile\DefaultIcon
%SystemRoot%\system32\shell32.dll,19
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\.moh
mohfile
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\mohfile
Unhandled Extension Handler Finder
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\mohfile\shell\open\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind IMS "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\mohfile\DefaultIcon
%SystemRoot%\system32\shell32.dll,19
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\.ivr
ivrfile
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\ivrfile
Unhandled Extension Handler Finder
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\ivrfile\shell\open\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind IVM "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\ivrfile\DefaultIcon
%SystemRoot%\system32\shell32.dll,19
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\.meo
meofile
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\meofile
Unhandled Extension Handler Finder
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\meofile\shell\open\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Meo "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\meofile\DefaultIcon
%SystemRoot%\system32\shell32.dll,19
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\.mpdp
mpdpfile
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\mpdpfile
Unhandled Extension Handler Finder
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\mpdpfile\shell\open\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind MixPad "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\mpdpfile\DefaultIcon
%SystemRoot%\system32\shell32.dll,19
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\.dct
dctfile
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\dctfile
Unhandled Extension Handler Finder
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\dctfile\shell\open\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Scribe "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\dctfile\DefaultIcon
%SystemRoot%\system32\shell32.dll,19
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\.dss
dssfile
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\dssfile
Unhandled Extension Handler Finder
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\dssfile\shell\open\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Scribe "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\dssfile\DefaultIcon
%SystemRoot%\system32\shell32.dll,19
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\.ds2
ds2file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\ds2file
Unhandled Extension Handler Finder
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\ds2file\shell\open\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Scribe "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\ds2file\DefaultIcon
%SystemRoot%\system32\shell32.dll,19
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\.vpj
vpjfile
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\vpjfile
Unhandled Extension Handler Finder
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\vpjfile\shell\open\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind VideoPad "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\vpjfile\DefaultIcon
%SystemRoot%\system32\shell32.dll,19
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\.spj
spjfile
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\spjfile
Unhandled Extension Handler Finder
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\spjfile\shell\open\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind PhotoStage "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\spjfile\DefaultIcon
%SystemRoot%\system32\shell32.dll,19
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.wav\Shell\NCHeditsound\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind WavePad "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.wav\Shell\NCHeditsound
Edit sound file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.mp3\Shell\NCHeditsound\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind WavePad "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.mp3\Shell\NCHeditsound
Edit sound file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.wma\Shell\NCHeditsound\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind WavePad "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.wma\Shell\NCHeditsound
Edit sound file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.m4a\Shell\NCHeditsound\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind WavePad "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.m4a\Shell\NCHeditsound
Edit sound file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.aiff\Shell\NCHeditsound\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind WavePad "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.aiff\Shell\NCHeditsound
Edit sound file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.aif\Shell\NCHeditsound\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind WavePad "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.aif\Shell\NCHeditsound
Edit sound file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.ogg\Shell\NCHeditsound\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind WavePad "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.ogg\Shell\NCHeditsound
Edit sound file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.voc\Shell\NCHeditsound\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind WavePad "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.voc\Shell\NCHeditsound
Edit sound file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.au\Shell\NCHeditsound\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind WavePad "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.au\Shell\NCHeditsound
Edit sound file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.aac\Shell\NCHeditsound\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind WavePad "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.aac\Shell\NCHeditsound
Edit sound file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\.vox
voxfile
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\voxfile\Shell\NCHeditsound\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind WavePad "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\voxfile\Shell\NCHeditsound
Edit sound file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\voxfile\Shell
open
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.wav\Shell\NCHconvertsound\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Switch "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.wav\Shell\NCHconvertsound
Convert sound file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.mp3\Shell\NCHconvertsound\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Switch "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.mp3\Shell\NCHconvertsound
Convert sound file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.wma\Shell\NCHconvertsound\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Switch "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.wma\Shell\NCHconvertsound
Convert sound file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.flac\Shell\NCHconvertsound\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Switch "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.flac\Shell\NCHconvertsound
Convert sound file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\.gsm
gsmfile
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\gsmfile\Shell\NCHconvertsound\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Switch "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\gsmfile\Shell\NCHconvertsound
Convert sound file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\gsmfile\Shell
open
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.aac\Shell\NCHconvertsound\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Switch "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.aac\Shell\NCHconvertsound
Convert sound file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.au\Shell\NCHconvertsound\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Switch "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.au\Shell\NCHconvertsound
Convert sound file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\voxfile\Shell\NCHconvertsound\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Switch "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\voxfile\Shell\NCHconvertsound
Convert sound file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\ds2file\shell\NCHconvertsound\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Switch "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\ds2file\shell\NCHconvertsound
Convert sound file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\ds2file\shell
open
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.aiff\Shell\NCHconvertsound\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Switch "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.aiff\Shell\NCHconvertsound
Convert sound file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.aif\Shell\NCHconvertsound\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Switch "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.aif\Shell\NCHconvertsound
Convert sound file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.mpeg\Shell\NCHeditvideo\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind VideoPad "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.mpeg\Shell\NCHeditvideo
Edit video file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.avi\Shell\NCHeditvideo\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind VideoPad "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.avi\Shell\NCHeditvideo
Edit video file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.mpg\Shell\NCHeditvideo\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind VideoPad "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.mpg\Shell\NCHeditvideo
Edit video file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.divx\Shell\NCHeditvideo\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind VideoPad "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.divx\Shell\NCHeditvideo
Edit video file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.asf\Shell\NCHeditvideo\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind VideoPad "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.asf\Shell\NCHeditvideo
Edit video file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.mov\Shell\NCHeditvideo\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind VideoPad "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.mov\Shell\NCHeditvideo
Edit video file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.mp4\Shell\NCHeditvideo\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind VideoPad "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.mp4\Shell\NCHeditvideo
Edit video file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\.xvid
xvidfile
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\xvidfile\Shell\NCHeditvideo\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind VideoPad "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\xvidfile\Shell\NCHeditvideo
Edit video file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\xvidfile\Shell
open
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.mpeg2\Shell\NCHeditvideo\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind VideoPad "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.mpeg2\Shell\NCHeditvideo
Edit video file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.m4v\Shell\NCHeditvideo\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind VideoPad "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.m4v\Shell\NCHeditvideo
Edit video file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.vob\Shell\NCHeditvideo\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind VideoPad "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.vob\Shell\NCHeditvideo
Edit video file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.mpeg\Shell\NCHconvertvideo\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Prism "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.mpeg\Shell\NCHconvertvideo
Convert video file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.avi\Shell\NCHconvertvideo\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Prism "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.avi\Shell\NCHconvertvideo
Convert video file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.mpg\Shell\NCHconvertvideo\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Prism "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.mpg\Shell\NCHconvertvideo
Convert video file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.divx\Shell\NCHconvertvideo\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Prism "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.divx\Shell\NCHconvertvideo
Convert video file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.asf\Shell\NCHconvertvideo\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Prism "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.asf\Shell\NCHconvertvideo
Convert video file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.mov\Shell\NCHconvertvideo\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Prism "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.mov\Shell\NCHconvertvideo
Convert video file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.mp4\Shell\NCHconvertvideo\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Prism "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.mp4\Shell\NCHconvertvideo
Convert video file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\xvidfile\Shell\NCHconvertvideo\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Prism "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\xvidfile\Shell\NCHconvertvideo
Convert video file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.mpeg2\Shell\NCHconvertvideo\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Prism "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.mpeg2\Shell\NCHconvertvideo
Convert video file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.m4v\Shell\NCHconvertvideo\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Prism "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.m4v\Shell\NCHconvertvideo
Convert video file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.vob\Shell\NCHconvertvideo\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Prism "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\VLC.vob\Shell\NCHconvertvideo
Convert video file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\jpegfile\Shell\NCHconvertimage\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Pixillion "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\jpegfile\Shell\NCHconvertimage
Convert image file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\jpegfile\Shell
open
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\giffile\Shell\NCHconvertimage\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Pixillion "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\giffile\Shell\NCHconvertimage
Convert image file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\giffile\Shell
open
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\Paint.Picture\Shell\NCHconvertimage\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Pixillion "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\Paint.Picture\Shell\NCHconvertimage
Convert image file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\Paint.Picture\Shell
open
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\pngfile\Shell\NCHconvertimage\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Pixillion "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\pngfile\Shell\NCHconvertimage
Convert image file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\pngfile\Shell
open
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\.nef
neffile
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\neffile\Shell\NCHconvertimage\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Pixillion "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\neffile\Shell\NCHconvertimage
Convert image file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\neffile\Shell
open
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\TIFImage.Document\Shell\NCHconvertimage\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Pixillion "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\TIFImage.Document\Shell\NCHconvertimage
Convert image file
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\TIFImage.Document\Shell
open
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\jpegfile\Shell\NCHslideshow\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind PhotoStage "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\jpegfile\Shell\NCHslideshow
Create slideshow
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\giffile\Shell\NCHslideshow\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind PhotoStage "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\giffile\Shell\NCHslideshow
Create slideshow
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\Paint.Picture\Shell\NCHslideshow\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind PhotoStage "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\Paint.Picture\Shell\NCHslideshow
Create slideshow
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\pngfile\Shell\NCHslideshow\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind PhotoStage "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\pngfile\Shell\NCHslideshow
Create slideshow
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\neffile\Shell\NCHslideshow\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind PhotoStage "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\neffile\Shell\NCHslideshow
Create slideshow
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\Word.Document.8\Shell\NCHconvertdoc\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Doxillion "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\Word.Document.8\Shell\NCHconvertdoc
Convert file type
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\Word.Document.12\Shell\NCHconvertdoc\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Doxillion "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\Word.Document.12\Shell\NCHconvertdoc
Convert file type
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\.wp
wpfile
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\wpfile\Shell\NCHconvertdoc\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Doxillion "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\wpfile\Shell\NCHconvertdoc
Convert file type
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\wpfile\Shell
open
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\AcroExch.Document.DC\Shell\NCHconvertdoc\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Doxillion "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\AcroExch.Document.DC\Shell\NCHconvertdoc
Convert file type
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\Word.RTF.8\Shell\NCHconvertdoc\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Doxillion "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\Word.RTF.8\Shell\NCHconvertdoc
Convert file type
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\Word.OpenDocumentText.12\Shell\NCHconvertdoc\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Doxillion "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\Word.OpenDocumentText.12\Shell\NCHconvertdoc
Convert file type
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\Word.OpenDocumentText.12\Shell
open
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\.wpd
wpdfile
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\wpdfile\Shell\NCHconvertdoc\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Doxillion "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\wpdfile\Shell\NCHconvertdoc
Convert file type
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\wpdfile\Shell
open
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\htmlfile\Shell\NCHconvertdoc\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind Doxillion "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\htmlfile\Shell\NCHconvertdoc
Convert file type
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\WinRAR\Shell\NCHextract\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind ExpressZip "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\WinRAR\Shell\NCHextract
Extract with Express Zip
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\WinRAR\Shell
open
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\.tar.gz
tar.gzfile
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\tar.gzfile\Shell\NCHextract\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind ExpressZip "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\tar.gzfile\Shell\NCHextract
Extract with Express Zip
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\tar.gzfile\Shell
open
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\Windows.IsoFile\shell\NCHextract\command
"C:\Program Files\NCH Software\DreamPlan\dreamplan.exe" -extfind ExpressZip "%L"
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\Windows.IsoFile\shell\NCHextract
Extract with Express Zip
3888
nchsetup.exe
write
HKEY_CLASSES_ROOT\Windows.IsoFile\shell
open
3888
nchsetup.exe
write
HKEY_CURRENT_USER\Software\NCH Software\DreamPlan\Settings
InstallDate
1555308512
3888
nchsetup.exe
write
HKEY_CURRENT_USER\Software\NCH Software\DreamPlan\Settings
InstallDateFirst
1555308512
3888
nchsetup.exe
write
HKEY_CURRENT_USER\Software\NCH Software\DreamPlan\Settings
CurrentVersion
1.31
3888
nchsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\NCH Software\DreamPlan\Software
Installer
C:\Program Files\NCH Software\DreamPlan\dreamplansetup_v1.31.exe
3420
zlib1.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\NCH Software\Components\zlib1
Path
C:\Program Files\NCH Software\Components\zlib1\zlib1.dll
3420
zlib1.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\NCH Software\Components\zlib1
Version
1.23
3420
zlib1.exe
write
HKEY_CURRENT_USER\Software\NCH Software\Components\zlib1
Path
C:\Program Files\NCH Software\Components\zlib1\zlib1.dll
3420
zlib1.exe
write
HKEY_CURRENT_USER\Software\NCH Software\Components\zlib1
Version
1.23
3420
zlib1.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\NCH Swift Sound\Components\zlib1
Path
C:\Program Files\NCH Software\Components\zlib1\zlib1.dll
3420
zlib1.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\NCH Swift Sound\Components\zlib1
Version
1.23
3420
zlib1.exe
write
HKEY_CURRENT_USER\Software\NCH Swift Sound\Components\zlib1
Path
C:\Program Files\NCH Software\Components\zlib1\zlib1.dll
3420
zlib1.exe
write
HKEY_CURRENT_USER\Software\NCH Swift Sound\Components\zlib1
Version
1.23
1912
infozip3.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\NCH Software\Components\infozip3
Path
C:\Program Files\NCH Software\Components\infozip3\unzip32.dll
1912
infozip3.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\NCH Software\Components\infozip3
Version
1.01
1912
infozip3.exe
write
HKEY_CURRENT_USER\Software\NCH Software\Components\infozip3
Path
C:\Program Files\NCH Software\Components\infozip3\unzip32.dll
1912
infozip3.exe
write
HKEY_CURRENT_USER\Software\NCH Software\Components\infozip3
Version
1.01
1912
infozip3.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\NCH Swift Sound\Components\infozip3
Path
C:\Program Files\NCH Software\Components\infozip3\unzip32.dll
1912
infozip3.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\NCH Swift Sound\Components\infozip3
Version
1.01
1912
infozip3.exe
write
HKEY_CURRENT_USER\Software\NCH Swift Sound\Components\infozip3
Path
C:\Program Files\NCH Software\Components\infozip3\unzip32.dll
1912
infozip3.exe
write
HKEY_CURRENT_USER\Software\NCH Swift Sound\Components\infozip3
Version
1.01
2748
dreamplan.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Name
dreamplan.exe
2748
dreamplan.exe
write
HKEY_CURRENT_USER\Software\NCH Software\DreamPlan\Software
SVar
LLIBShowSuiteButtonOff
2748
dreamplan.exe
write
HKEY_CURRENT_USER\Software\NCH Software\DreamPlan\Settings
CheckForDownloadContent
0
2748
dreamplan.exe
write
HKEY_CURRENT_USER\Software\NCH Software\DreamPlan\MainWindow
X
636
2748
dreamplan.exe
write
HKEY_CURRENT_USER\Software\NCH Software\DreamPlan\MainWindow
Y
323
2748
dreamplan.exe
write
HKEY_CURRENT_USER\Software\NCH Software\DreamPlan\MainWindow
Width
112
2748
dreamplan.exe
write
HKEY_CURRENT_USER\Software\NCH Software\DreamPlan\MainWindow
Height
46
2748
dreamplan.exe
write
HKEY_CURRENT_USER\Software\NCH Software\DreamPlan\MainWindow
Maximized
0
2748
dreamplan.exe
write
HKEY_CURRENT_USER\Software\NCH Software\DreamPlan\Settings
Thanks
1
2748
dreamplan.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2748
dreamplan.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2748
dreamplan.exe
write
HKEY_CURRENT_USER\Software\NCH Software\DreamPlan\Settings
Runs
1
2748
dreamplan.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\NCH Software\DreamPlan\Settings
RelatedRuns
1
4044
dreamplan.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Name
dreamplan.exe
4044
dreamplan.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\NCH Software\DreamPlan\Scheduler
SevenDays
1
3600
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
CompatibilityFlags
0
3600
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3600
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3600
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
SecuritySafe
1
3600
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3600
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000071000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3600
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
{EAD82261-5F44-11E9-A370-5254004A04AF}
0
3600
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Type
4
3600
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Count
1
3600
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Time
E307040001000F00060008002A006003
3600
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Type
4
3600
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Count
1
3600
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Time
E307040001000F00060008002A006003
3600
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
FullScreen
no
3600
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Window_Placement
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF20000000200000004003000078020000
3600
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\Links
Order
08000000020000000C01000001000000020000007E0000000000000070003200EC000000464B245120005355474745537E312E55524C0000540008000400EFBE454B974D464B24512A000000F94300000000020000000000000000000000000000005300750067006700650073007400650064002000530069007400650073002E00750072006C0000001C00000000000000820000000100000074003200E2000000464B24512000574542534C497E312E55524C0000580008000400EFBE454B864A464B24512A000000743E0000000003000000000000000000000000000000570065006200200053006C006900630065002000470061006C006C006500720079002E00750072006C0000001C00000000000000
3600
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Type
3
3600
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Count
1
3600
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Time
E307040001000F00060008002B003400
3600
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
LoadTime
16
3600
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Type
3
3600
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Count
1
3600
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Time
E307040001000F00060008002B004300
3600
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
LoadTime
72
3600
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Type
3
3600
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Count
1
3600
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Time
E307040001000F00060008002B009100
3600
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
LoadTime
65
3600
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D27CDB6E-AE6D-11CF-96B8-444553540000}\iexplore
Type
1
3600
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D27CDB6E-AE6D-11CF-96B8-444553540000}\iexplore
Count
1
3600
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D27CDB6E-AE6D-11CF-96B8-444553540000}\iexplore
Time
E307040001000F00060008002D007003
3600
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019041520190416
CachePath
%USERPROFILE%\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019041520190416
3600
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019041520190416
CachePrefix
:2019041520190416:
3600
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019041520190416
CacheLimit
8192
3600
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019041520190416
CacheOptions
11
3600
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019041520190416
CacheRepair
0
3600
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\WindowsSearch
UpgradeTime
1C94B5B051F3D401
3600
iexplore.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
LanguageList
en-US
3600
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A
Blob
0F00000001000000140000000F6AAD4C3FE04619CDC8B2BD655AA1A26042E6500B000000010000005400000053007400610072006600690065006C006400200043006C00610073007300200032002000430065007200740069006600690063006100740069006F006E00200041007500740068006F007200690074007900000053000000010000004800000030463021060B6086480186FD6D0107170330123010060A2B0601040182373C0101030200C03021060B6086480186FD6E0107170330123010060A2B0601040182373C0101030200C009000000010000002A000000302806082B0601050507030106082B0601050507030206082B0601050507030406082B060105050703036200000001000000200000001465FA205397B876FAA6F0A9958E5590E40FCC7FAA4FB7C2C8677521FB5FB658140000000100000014000000BF5FB7D1CEDD1F86F45B55ACDCD710C20EA988E71D000000010000001000000090C4F4233B006B7BFAA6ADCD8F577D77030000000100000014000000AD7E1C28B064EF8F6003402014C3D0E3370EB58A2000000001000000130400003082040F308202F7A003020102020100300D06092A864886F70D01010505003068310B300906035504061302555331253023060355040A131C537461726669656C6420546563686E6F6C6F676965732C20496E632E31323030060355040B1329537461726669656C6420436C61737320322043657274696669636174696F6E20417574686F72697479301E170D3034303632393137333931365A170D3334303632393137333931365A3068310B300906035504061302555331253023060355040A131C537461726669656C6420546563686E6F6C6F676965732C20496E632E31323030060355040B1329537461726669656C6420436C61737320322043657274696669636174696F6E20417574686F7269747930820120300D06092A864886F70D01010105000382010D00308201080282010100B732C8FEE971A60485AD0C1164DFCE4DEFC80318873FA1ABFB3CA69FF0C3A1DAD4D86E2B5390FB24A43E84F09EE85FECE52744F528A63F7BDEE02AF0C8AF532F9ECA0501931E8F661C39A74DFA5AB673042566EB777FE759C64A99251454EB26C7F37F19D530708FAFB0462AFFADEB29EDD79FAA0487A3D4F989A5345FDB43918236D9663CB1B8B982FD9C3A3E10C83BEF0665667A9B19183DFF71513C302E5FBE3D7773B25D066CC323569A2B8526921CA702B3E43F0DAF087982B8363DEA9CD335B3BC69CAF5CC9DE8FD648D1780336E5E4A5D99C91E87B49D1AC0D56E1335235EDF9B5F3DEFD6F776C2EA3EBB780D1C42676B04D8F8D6DA6F8BF244A001AB020103A381C53081C2301D0603551D0E04160414BF5FB7D1CEDD1F86F45B55ACDCD710C20EA988E73081920603551D2304818A3081878014BF5FB7D1CEDD1F86F45B55ACDCD710C20EA988E7A16CA46A3068310B300906035504061302555331253023060355040A131C537461726669656C6420546563686E6F6C6F676965732C20496E632E31323030060355040B1329537461726669656C6420436C61737320322043657274696669636174696F6E20417574686F72697479820100300C0603551D13040530030101FF300D06092A864886F70D01010505000382010100059D3F889DD1C91A55A1AC69F3F359DA9B01871A4F57A9A179092ADBF72FB21ECCC75E6AD88387A197EF49353E7706415862BF8E58B80A673FECB3DD21661FC954FA72CC3D4C40D881AF779E837ABBA2C7F534178ED91140F4FC2C2A4D157FA7625D2E25D3000B201A1D68F917B8F4BD8BED2859DD4D168B1783C8B265C72D7AA5AABC53866DDD57A4CAF820410B68F0F4FB74BE565D7A79F5F91D85E32D95BEF5719043CC8D1F9A000A8729E95522580023EAE31243295B4708DD8C416A6506A8E521AA41B4952195B97DD134AB13D6ADBCDCE23D39CDBD3E7570A1185903C922B48F9CD55E2AD7A5B6D40A6DF8B74011469A1F790E62BF0F97ECE02F1F1794
3600
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A
3600
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\AD7E1C28B064EF8F6003402014C3D0E3370EB58A
Blob
190000000100000010000000FD960962AC6938E0D4B0769AA1A64E260B000000010000005400000053007400610072006600690065006C006400200043006C00610073007300200032002000430065007200740069006600690063006100740069006F006E00200041007500740068006F007200690074007900000053000000010000004800000030463021060B6086480186FD6D0107170330123010060A2B0601040182373C0101030200C03021060B6086480186FD6E0107170330123010060A2B0601040182373C0101030200C009000000010000002A000000302806082B0601050507030106082B0601050507030206082B0601050507030406082B060105050703036200000001000000200000001465FA205397B876FAA6F0A9958E5590E40FCC7FAA4FB7C2C8677521FB5FB658140000000100000014000000BF5FB7D1CEDD1F86F45B55ACDCD710C20EA988E71D000000010000001000000090C4F4233B006B7BFAA6ADCD8F577D77030000000100000014000000AD7E1C28B064EF8F6003402014C3D0E3370EB58A2000000001000000130400003082040F308202F7A003020102020100300D06092A864886F70D01010505003068310B300906035504061302555331253023060355040A131C537461726669656C6420546563686E6F6C6F676965732C20496E632E31323030060355040B1329537461726669656C6420436C61737320322043657274696669636174696F6E20417574686F72697479301E170D3034303632393137333931365A170D3334303632393137333931365A3068310B300906035504061302555331253023060355040A131C537461726669656C6420546563686E6F6C6F676965732C20496E632E31323030060355040B1329537461726669656C6420436C61737320322043657274696669636174696F6E20417574686F7269747930820120300D06092A864886F70D01010105000382010D00308201080282010100B732C8FEE971A60485AD0C1164DFCE4DEFC80318873FA1ABFB3CA69FF0C3A1DAD4D86E2B5390FB24A43E84F09EE85FECE52744F528A63F7BDEE02AF0C8AF532F9ECA0501931E8F661C39A74DFA5AB673042566EB777FE759C64A99251454EB26C7F37F19D530708FAFB0462AFFADEB29EDD79FAA0487A3D4F989A5345FDB43918236D9663CB1B8B982FD9C3A3E10C83BEF0665667A9B19183DFF71513C302E5FBE3D7773B25D066CC323569A2B8526921CA702B3E43F0DAF087982B8363DEA9CD335B3BC69CAF5CC9DE8FD648D1780336E5E4A5D99C91E87B49D1AC0D56E1335235EDF9B5F3DEFD6F776C2EA3EBB780D1C42676B04D8F8D6DA6F8BF244A001AB020103A381C53081C2301D0603551D0E04160414BF5FB7D1CEDD1F86F45B55ACDCD710C20EA988E73081920603551D2304818A3081878014BF5FB7D1CEDD1F86F45B55ACDCD710C20EA988E7A16CA46A3068310B300906035504061302555331253023060355040A131C537461726669656C6420546563686E6F6C6F676965732C20496E632E31323030060355040B1329537461726669656C6420436C61737320322043657274696669636174696F6E20417574686F72697479820100300C0603551D13040530030101FF300D06092A864886F70D01010505000382010100059D3F889DD1C91A55A1AC69F3F359DA9B01871A4F57A9A179092ADBF72FB21ECCC75E6AD88387A197EF49353E7706415862BF8E58B80A673FECB3DD21661FC954FA72CC3D4C40D881AF779E837ABBA2C7F534178ED91140F4FC2C2A4D157FA7625D2E25D3000B201A1D68F917B8F4BD8BED2859DD4D168B1783C8B265C72D7AA5AABC53866DDD57A4CAF820410B68F0F4FB74BE565D7A79F5F91D85E32D95BEF5719043CC8D1F9A000A8729E95522580023EAE31243295B4708DD8C416A6506A8E521AA41B4952195B97DD134AB13D6ADBCDCE23D39CDBD3E7570A1185903C922B48F9CD55E2AD7A5B6D40A6DF8B74011469A1F790E62BF0F97ECE02F1F1794
2168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012019041520190416
CachePath
%USERPROFILE%\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012019041520190416
2168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012019041520190416
CachePrefix
:2019041520190416:
2168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012019041520190416
CacheLimit
8192
2168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012019041520190416
CacheOptions
11
2168
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012019041520190416
CacheRepair
0
2168
iexplore.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012018082820180829
2652
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
failed_count
0
2652
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
2
2652
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
2652
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
01000000
2652
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
1
2652
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
dr
1
2652
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome
UsageStatsInSample
0
2652
chrome.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
usagestats
0
2652
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
metricsid
2652
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
metricsid_installdate
0
2652
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
metricsid_enableddate
0
2652
chrome.exe
delete key
HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
2652
chrome.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\_NumAccounts
aggregate
sum()
2652
chrome.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\_NumAccounts
S-1-5-21-1302019708-1500728564-335382590-1000
1
2652
chrome.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\_NumSignedIn
aggregate
sum()
2652
chrome.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}\_NumSignedIn
S-1-5-21-1302019708-1500728564-335382590-1000
0
2652
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics
user_experience_metrics.stability.exited_cleanly
0
2652
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
lastrun
13199782137114625
2652
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E
LanguageList
en-US
2652
chrome.exe
delete key
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
2652
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
aapocclcgogkmnckokdopfmhonfmgoek
01B541F00AB5E4F0F57AA94BAFBA1EA7736585D937462546279CB55426994D52
2652
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
ahfgeienlihckogmohjhadlkjgocpleb
15B1C3FE35F29528448F36A72A4DFBC58A8083C7190559D25865779166D220A2
2652
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
aohghmighlieiainnegkcijnfilokake
A0B5D754326E19892BF44F4C454FABB73347BEA87C7FD97EEF418710346DFB84
2652
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
apdfllckaahabafndbhieahigkjlhalf
83A14C46E6B408213C5B4AEA64F4D052F73EF85F54E26440C1517C373772134E
2652
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
blpcfgokakmgnkcojhhkbfbldkacnbeo
6F2102A62F478BE7AB1D7C255780B8254F79AAB99A95A44ACAD6B5FDDF3CD03F
2652
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
felcaaldnbdncclmgdcncolpebgiejap
D5C78FE2EE468F3B3928DDF4660C2902D5AB9F385B4227BC0F162113217890D7
2652
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
gfdkimpbcpahaombhbimeihdjnejgicl
D6B079666F209503A09486C70AC09307652A0F7F783166A999B27C99D0DA79E2
2652
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
ghbmnnjooekpmoecnnnilnnbdlolhkhi
DA3BC389A567F426762BF922ABF0CA80A4DAD81EEB2FCE06A00D739B39DE332F
2652
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
kmendfapggjehodndflmmgagdbamhnfd
00175B8120231631976CA8B862A3416996C9373BA3D289F0619DDA992973DDFA
2652
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
mfehgcgbbipciphmccgaenjidiccnmng
63355C14E8C7DF9A075F2EDDEA6F2807DC8166B83F96F4C975B9B6554C6324D7
2652
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
mhjfbmdgcfjbbpaeojofohoefgiehjai
0E265BFED6F1C7D5F0A9BD790C50BB30E78E959631D51EEBB8BB0DE73E65763C
2652
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
neajdppkdcdipfabeoofebfddakdcjhd
04A45240BDA55E8777FA04357712CA6DD942253A21323E4C7D3CCF769B34BFED
2652
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nkeimhogjdpnpccoofpliimaahmaaome
EFA63CBF982B82CF44E63E567FF3BB95FE3F51570D9A0CED8846E77B13199169
2652
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
nmmhkkegccagdldgiimedpiccmgmieda
30A7F4150A4B47DA903EF20FE9D37AB365B86DE8B88555D9D107E9CFE6690256
2652
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
pjkljhegncpnkpknbcohdijeoejaedia
A4FB6FA302457BF7A7B7C7091FDF227FFF72862F991CB296C6FDF6AE9A03FB3D
2652
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\PreferenceMACs\Default\extensions.settings
pkedcjkdefgpdelpbcmbmeomcjbeemfm
5B31D6F0A1F1F386E3C33C8722F0028F166091DB0E12516898398A00C5ACF342
680
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
2652-13199782136364625
259
3232
dreamplan.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Name
dreamplan.exe
2660
dreamplan.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Name
dreamplan.exe
2660
dreamplan.exe
write
HKEY_CURRENT_USER\Software\NCH Software\DreamPlan\MainWindow
X
636
2660
dreamplan.exe
write
HKEY_CURRENT_USER\Software\NCH Software\DreamPlan\MainWindow
Y
323
2660
dreamplan.exe
write
HKEY_CURRENT_USER\Software\NCH Software\DreamPlan\MainWindow
Width
112
2660
dreamplan.exe
write
HKEY_CURRENT_USER\Software\NCH Software\DreamPlan\MainWindow
Height
46
2660
dreamplan.exe
write
HKEY_CURRENT_USER\Software\NCH Software\DreamPlan\MainWindow
Maximized
0
2660
dreamplan.exe
write
HKEY_CURRENT_USER\Software\NCH Software\DreamPlan\Settings
Runs
2
2660
dreamplan.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\NCH Software\DreamPlan\Settings
RelatedRuns
2

Files activity

Executable files
8
Suspicious files
115
Text files
284
Unknown types
62

Dropped files

PID
Process
Filename
Type
3888
nchsetup.exe
C:\Program Files\NCH Software\DreamPlan\dreamplansetup_v1.31.exe
executable
MD5: 9d6d30a67013a7853e8055770b9e0cb4
SHA256: 6cb18148a9f9b7e810975b1eccc74ae1e9d1785c80408090706f69e2957ad217
1912
infozip3.exe
C:\Program Files\NCH Software\Components\infozip3\unzip32.dll
executable
MD5: 201ded44e217f29fbfa89e602bf0d460
SHA256: c80777f83aa4e77d03a6a4e682a8aa073bac77bb1f1b01fd4feb2ffea010d796
3888
nchsetup.exe
C:\Program Files\NCH Software\DreamPlan\infozip3.exe
executable
MD5: 8578b729c10cc0bff2fa019f01a77df3
SHA256: 6b19fc7d0d3781c5ed6659ea4a55c92d6b9fd50a7e108ccf02a6a2cf6ae223bf
3420
zlib1.exe
C:\Program Files\NCH Software\Components\zlib1\zlib1.dll
executable
MD5: 80e41408f6d641dc1c0f5353a0cc8125
SHA256: b09537250201236472ccd3caff5c0c12a5fad262e1e951350e9e5ed2a81d9dde
3888
nchsetup.exe
C:\Program Files\NCH Software\DreamPlan\zlib1.exe
executable
MD5: e82a358f2ec5a1599d41844e55077daa
SHA256: 27a1713ce7cae13de3d00d9dd768c6b77ffcbee513878e64880c11424ee36271
3888
nchsetup.exe
C:\Program Files\NCH Software\DreamPlan\dreamplan.exe
executable
MD5: 6394fbfadab8fdaa6faf0cb65b227770
SHA256: ec0563d1d958edec4d10f08fbafcdeffdbdd33d147b3582ad71ed2bdaae45803
2412
thhjgjk.exe
C:\Users\admin\AppData\Local\Temp\n1s\nchsetup.exe
executable
MD5: 6394fbfadab8fdaa6faf0cb65b227770
SHA256: ec0563d1d958edec4d10f08fbafcdeffdbdd33d147b3582ad71ed2bdaae45803
1912
infozip3.exe
C:\Program Files\NCH Software\Components\infozip3\zip32z64.dll
executable
MD5: af6ca2826a4707e927b04b2456637b43
SHA256: 1b12dcd09e25dcc874d1b544c093cd6d7810f1fa7bada211ff53ef0dfcafa877
2168
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IG3FJSAF\reddit_16[1].png
image
MD5: 85e80be0c7b80be8c6a0eab67f448a1b
SHA256: acbde46032fca0d5b66b140dd42f1931b503af55c7c3661c240fb911eba7a947
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State
text
MD5: 41931b81c3c24c87d41f878048815cf9
SHA256: 178294256802aad46f84e38d7dcc4d5d28dfc50555a7ae28ce5f39c99e361c78
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State~RF120ab6.TMP
text
MD5: 41931b81c3c24c87d41f878048815cf9
SHA256: 178294256802aad46f84e38d7dcc4d5d28dfc50555a7ae28ce5f39c99e361c78
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\fc3dc1f3-02c7-44d3-8667-de7a44f31434.tmp
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\index-dir\the-real-index
pi2
MD5: fd674fae003ff47201d29cb6253e1a6c
SHA256: b1ce9e7e2eab112ad726bd5e239e28b4733e2b5f914ebd0f572d40c7a9969b2a
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\index-dir\the-real-index~RF11fcfb.TMP
pi2
MD5: fd674fae003ff47201d29cb6253e1a6c
SHA256: b1ce9e7e2eab112ad726bd5e239e28b4733e2b5f914ebd0f572d40c7a9969b2a
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\index-dir\temp-index
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences
text
MD5: 507951b3469f33363686407543174719
SHA256: fbbb82ecbcfd1d0cea6fa6b9fec57210a5f77bb6eae2d338cd5551b361ce6415
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF11f634.TMP
text
MD5: 507951b3469f33363686407543174719
SHA256: fbbb82ecbcfd1d0cea6fa6b9fec57210a5f77bb6eae2d338cd5551b361ce6415
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\4a307955-5d16-4a5f-aee8-ef44ed9c5c5c.tmp
––
MD5:  ––
SHA256:  ––
2660
dreamplan.exe
C:\Users\admin\AppData\Local\Temp\~DF048BCF43B710C1B0.TMP
––
MD5:  ––
SHA256:  ––
2660
dreamplan.exe
C:\Users\admin\AppData\Local\Temp\DreamPlanCounts.txt
vxd
MD5: 1dad1923be4c77a0ea21001ccb011655
SHA256: 8d5ec139edf2add2bc5aee0a8b8724cab76c5dd19dfc37210136daf3be6a3149
2660
dreamplan.exe
C:\Users\admin\AppData\Roaming\DreamPlan.dmp
dmp
MD5: d64231d1eea3e28deb14d322e14e095f
SHA256: b59792aa063d87e9e5b56b3bf0760fcbf72477824c24b7461ee78c90f4c75308
2660
dreamplan.exe
C:\Users\admin\AppData\Local\Temp\_dreamplan_rl_admin
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences~RF11e089.TMP
text
MD5: e86816dc70a5c3be471e082b99236325
SHA256: 39c99b6c3246576372830ee96c896519566c9e83a0e2b310b59708e7e45cc2b9
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
text
MD5: e86816dc70a5c3be471e082b99236325
SHA256: 39c99b6c3246576372830ee96c896519566c9e83a0e2b310b59708e7e45cc2b9
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\85c664ba-054f-4c49-96d1-59dc2dc82e2f.tmp
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\28da9c56fde4021055a681112c092453f74d8dd8\index.txt
binary
MD5: b89242953463ebd8836ea0f8db33dc8f
SHA256: 06a6449abe903c521235967730bda1f74547630bc010336490ada3a57422dd1b
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\28da9c56fde4021055a681112c092453f74d8dd8\index.txt~RF11d85c.TMP
binary
MD5: b89242953463ebd8836ea0f8db33dc8f
SHA256: 06a6449abe903c521235967730bda1f74547630bc010336490ada3a57422dd1b
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\28da9c56fde4021055a681112c092453f74d8dd8\index.txt.tmp
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Session Storage\CURRENT
text
MD5: 46295cac801e5d4857d09837238a6394
SHA256: 0f1bad70c7bd1e0a69562853ec529355462fcd0423263a3d39d6d0d70b780443
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Session Storage\MANIFEST-000001
binary
MD5: 5af87dfd673ba2115e2fcf5cfdb727ab
SHA256: f9d31b278e215eb0d0e9cd709edfa037e828f36214ab7906f612160fead4b2b4
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Session Storage\000001.dbtmp
––
MD5:  ––
SHA256:  ––
1528
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity
text
MD5: 672e53b1a38afa05deaf0f79a1d2d8b8
SHA256: aeb5dc65b7838625af582a554bc7750573c739a8e95917be5279a72120a2a8b0
1528
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\TransportSecurity~RF11d203.TMP
text
MD5: 672e53b1a38afa05deaf0f79a1d2d8b8
SHA256: aeb5dc65b7838625af582a554bc7750573c739a8e95917be5279a72120a2a8b0
1528
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\422452e1-b578-4012-a4f4-4f783d35590f.tmp
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences
text
MD5: 1bbc0311cf136b5d94a69adb9e67bc2d
SHA256: 8a5244e56bc35e252096ee91d285586a596d0d98234759aaa5d1fc0811c115ae
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Preferences~RF11cd40.TMP
text
MD5: 1bbc0311cf136b5d94a69adb9e67bc2d
SHA256: 8a5244e56bc35e252096ee91d285586a596d0d98234759aaa5d1fc0811c115ae
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\bfa068a7-a8ee-44dc-928c-3913a6403fc8.tmp
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State~RF11cce2.TMP
text
MD5: 221af60b6232e58cd93e77dc20c62a0b
SHA256: e2da811fa054194f8880fb161d89d59ee5720fbf382c85bce0903c12650c9899
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Local State
text
MD5: 221af60b6232e58cd93e77dc20c62a0b
SHA256: e2da811fa054194f8880fb161d89d59ee5720fbf382c85bce0903c12650c9899
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\6b07555b-daf7-416e-a6c1-7515c87186ae.tmp
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\28da9c56fde4021055a681112c092453f74d8dd8\974cc4d3-b201-4c90-86cf-39a81799d944\bd2ac9401e71e2d5_0
binary
MD5: 7b696da67f1c15cea269da6cee3e9623
SHA256: 089c68444054e4f231622b29b88209a4df3375c824a7dcd4d387656bbaee37df
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\28da9c56fde4021055a681112c092453f74d8dd8\974cc4d3-b201-4c90-86cf-39a81799d944\5ca50924ce3c5c59_0
binary
MD5: f9f9541bdc36d3be8a617556c12bf0eb
SHA256: 2cb454e29635deb20505f184a7be7c392671db3ed39e3dbb7ae4983ba96b8ea0
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\28da9c56fde4021055a681112c092453f74d8dd8\974cc4d3-b201-4c90-86cf-39a81799d944\bd2ac9401e71e2d5_1
binary
MD5: 3ee40be692bd2c3700fdd73433a8d552
SHA256: f3e572545c397d5736fca698c6917259a15f38bf9fc39067d9369c150564d353
1528
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000007
binary
MD5: b8eeb644fd1709162862a6d2457bc27b
SHA256: 81d825a53f4ef8457dc2e362275e6a05472986fa333dff79eeb1b731fe48cfd5
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\28da9c56fde4021055a681112c092453f74d8dd8\974cc4d3-b201-4c90-86cf-39a81799d944\index-dir\the-real-index
binary
MD5: 5bf7d0192a6423ff31c458af201d5151
SHA256: f952667a958e659b254ba986a825e34a6078cee99cdcfd3260c38eb899628f1b
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\28da9c56fde4021055a681112c092453f74d8dd8\974cc4d3-b201-4c90-86cf-39a81799d944\index
text
MD5: 54cb446f628b2ea4a5bce5769910512e
SHA256: fbcfe23a2ecb82b7100c50811691dde0a33aa3da8d176be9882a9db485dc0f2d
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\CacheStorage\28da9c56fde4021055a681112c092453f74d8dd8\index.txt
binary
MD5: 8e0c192510609de5333fdceee4e297df
SHA256: 1d920fb24b6dc0d05c4817f5aaab3d0f15a011092530e979b9e6683d874b6099
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\ScriptCache\2cc80dabc69f58b6_1
binary
MD5: 9c10268b7afb2bafd86d6981d40b7eb9
SHA256: 8b6a35a71e142ba717a26f44cd2ebf5c816908a7e0ce7b365fb5bfcf2b1cab0d
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\ScriptCache\2cc80dabc69f58b6_0
binary
MD5: 800c842f1bd784fba047c6af739f8ab5
SHA256: 6aa132e52b080856c4d72bef42c18744d515a649b04ec0ed6e3f17e71899f32d
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\ScriptCache\index-dir\the-real-index
binary
MD5: 17069d4466574d30e9d8c3955514420f
SHA256: ac14218d6a375289ea31790f4ed9920ab6f5ceea7405bf7ac305c2fb68846d22
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\Database\CURRENT
text
MD5: 46295cac801e5d4857d09837238a6394
SHA256: 0f1bad70c7bd1e0a69562853ec529355462fcd0423263a3d39d6d0d70b780443
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\Database\000001.dbtmp
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\Database\MANIFEST-000001
binary
MD5: 5af87dfd673ba2115e2fcf5cfdb727ab
SHA256: f9d31b278e215eb0d0e9cd709edfa037e828f36214ab7906f612160fead4b2b4
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Service Worker\ScriptCache\index
text
MD5: 54cb446f628b2ea4a5bce5769910512e
SHA256: fbcfe23a2ecb82b7100c50811691dde0a33aa3da8d176be9882a9db485dc0f2d
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\7319.128.0.1_0
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\Temp\scoped_dir2652_18118\CRX_INSTALL
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\zh_TW\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\zh\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\vi\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\uk\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\th\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\ta\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\tr\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\te\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\sw\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\sv\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\sl\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\sr\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\ru\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\sk\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\ro\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\pt\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\pl\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\nl\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\hu\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\hi\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\gu\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\fi\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\id\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\nb\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\ko\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\fr\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\ja\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\it\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\hr\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\fa\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\mr\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\lv\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\fil\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\kn\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\ml\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\ms\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\lt\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\bg\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\cs\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\am\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\bn\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\el\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\ca\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\en\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\ar\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\et\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\da\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\de\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\es\messages.json
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\manifest.json
––
MD5:  ––
SHA256:  ––
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\mirroring_webrtc.js
text
MD5: 05b6b803898b50ba46ef100bb9138371
SHA256: eec784d4a6209d32f263f4873ea9a9a79a226dbf8f6e9c487ed75bef4af8d1af
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_metadata\verified_contents.json
text
MD5: 22e79719df0f623df7392be3060a23d7
SHA256: 69eec99c7e6aa1826baa0583c8b566e79163c27291ac91798970bf45c0910749
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\mirroring_hangouts.js
text
MD5: 3878dc32ddab95c95655212b22995d89
SHA256: 337298f720e5eda9946adc0cfdf5a95fe99f27505a2e00f7cc4801e71c563e19
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\material_css_min.css
text
MD5: 3358ffd27f0e24441652d11d0a923386
SHA256: f64ef9e918ec588cf8fdf6f3c2adadda4d08123bde180527277dd9832ef84ab5
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\feedback_script.js
text
MD5: a351ee4448c90d82b5b16b93203c32d8
SHA256: bf5f5a4d40f0701083c29f0e0c2415f0afd77b859a321bfbf2003c699101e7d0
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\mirroring_common.js
text
MD5: 601e598f3fbbc2d67c0e2e9e3397a5ac
SHA256: 299341580def7206225a92624bcbecadaeb7676747d87d94dad3783e7c262390
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\feedback.html
html
MD5: d8999d70edf2140409a700ba5590c7e6
SHA256: 36e036646c0550b5bc3aa5e2c961851e9fb84f6afa126edf0f91f93d18a6f12f
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\mirroring_cast_streaming.js
text
MD5: 6943caa86048b3b27cf034306017866b
SHA256: 503cad31f78ed39b56fe99d0b0f46854cc0e436bf6b16a8bdb2ad71cee78b415
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\feedback.css
text
MD5: d8ee20737329319bfa1acbb0e6c219a6
SHA256: a582fc20dbcad1918000b690eb8f237ec14e5b836fd7f799c35702d88dbe6862
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\common.js
text
MD5: 6da98ef1c025dc449057575d55549186
SHA256: 92c09d1a78ef6ff9fdfaa9ae5b4c610876bc0799f7311b9c8194780581e7ca5e
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\cast_setup\devices.html
html
MD5: 8388cc359430657e940186a45deddc5c
SHA256: 25e58675bc9d45f7c860e01637326a661f68a1d360e2508706eccfa408edd23f
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\cast_setup\setup.html
html
MD5: 8388cc359430657e940186a45deddc5c
SHA256: 25e58675bc9d45f7c860e01637326a661f68a1d360e2508706eccfa408edd23f
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\cast_setup\offers.html
html
MD5: 8388cc359430657e940186a45deddc5c
SHA256: 25e58675bc9d45f7c860e01637326a661f68a1d360e2508706eccfa408edd23f
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\cast_setup\index.html
html
MD5: d6129176a40c5f18d1e4b692d37f9bc2
SHA256: d2792c70ef575d9d822ad6e2b804bec13a274aec969b0f8d7b0db8b35dbfa834
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\cast_setup\cast_app_redirect.js
text
MD5: a2a7a6c00091ead24b4476bc6131c8f9
SHA256: 753c002de0970d0732be1cacba9ac3e38e75b28d2e8221f9fa7fbb477011b71a
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\cast_game_sender.js
text
MD5: 0b363a38dfb5f71870c6cce3314a81f0
SHA256: 09583d0b906e1be8707d53ce5ad33ef35de2ae33887767bbf206068f67508383
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\cast_setup\cast_app.js
text
MD5: 3c9d2a76ce88f23b2ce051444667862c
SHA256: 17942f2e603c99fd2c571f42229fc7a6242095dcf74d3e4d219f7fd2ec290db1
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\cast_setup\chromecast_logo_grey.png
image
MD5: a7099e08e14f10d8f47a0cd7b8bc003b
SHA256: 59fe744de6c2636df554075ffb1c28aa3f8fd75830434e28c1f85b19eb9d566b
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\cast_setup\cast_app_min.css
text
MD5: acf54711f0b70a104e4e3afad9142856
SHA256: deb1d6a67165e2225d1d4b8b3cf50299078b20b733516622600e4cd032dd6d2b
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\cast_sender.js
text
MD5: 4811c1bad63fad553090315710df4522
SHA256: 0ed8e460ad47eb6b3bb6151cc1eaa0d67554266ae0b543addc8c4b200accbb4b
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\background_script.js
text
MD5: 36db5de50640307501492aa794718ef0
SHA256: 346468148d51c889c0662f5229df9890dea98ac5353ae5759a4c7e1f75a2d59d
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\angular.js
text
MD5: cc86f1d45febd80dd24791d59b2aa616
SHA256: f321dc8d9a4d8a779add44180974e59a43d5bd10744542a768c1b15d7e63a832
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\uk\messages.json
text
MD5: ae50bf36f89d4706da22d21959863425
SHA256: 6b7f56819e94b99b792fe0c11273e259ce18c7fb57392bb47be8b0fd29b24e7d
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\vi\messages.json
html
MD5: 47bbd75f76e25d79ea10f2014f7d9bc7
SHA256: 53b2b2454bb45be824119b15dda1ea2226958794fc259d80f0347d1bc706eb7b
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\zh_TW\messages.json
html
MD5: c6f48c269246a6fa0e2f0b396b7604df
SHA256: 81bc1bc507238ab26ffaf68003d811fd603e5f4bdc1b0b94d0f4506cbbe97241
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\zh\messages.json
html
MD5: 0a57b005bd27db7a0070f914c354a072
SHA256: 91a4c7d3fbd1e41d0801029bda6f14e52c8653a648fc5f39fe1f046564d0f60b
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\ta\messages.json
text
MD5: 5f7b6880dbea25f769f97d2c99e7b7f6
SHA256: 5a22269c0eda694e0131b0ac52ebfdf828aad3c735b592a54d210f6b8db0ab82
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\te\messages.json
text
MD5: cebd49bb6f838e23140cee4118c76dfb
SHA256: 0b71586dee26943b55899583ad4355b8f4007a4853510364faa76a99ba9a0566
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\sv\messages.json
html
MD5: cf637a380c4aecd9778a46a19108c406
SHA256: 4010ebf76c0af564b9c3026b98ff2885af77955be12d77a05a508ff7d5f8366d
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\sw\messages.json
html
MD5: 1712a3588bafaee411bc46ec5dcb8ca2
SHA256: 8485722d70475c9d98a8a7d6d2613117149bfaea487ad7f92d9a6e094de949f0
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\tr\messages.json
html
MD5: 2b0dfabc643cff3ec13e96e3ec842258
SHA256: 816add33835ba6028915b4532d5b45a71a280de6788398b008bd60733326ceb7
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\th\messages.json
html
MD5: 84140112d747bd5176c96a374a18ad1a
SHA256: b60a1cbb9ac067f4e903170c8564e4bc2c3572f76a5b09bbeedbd6e1b88df1e1
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\ro\messages.json
html
MD5: 2228b9adecbfb55d24890c9510f20b5b
SHA256: d2ce829cc617a8d01c366ec60d1718f52c63f1a9515fb0b1611e55b22f909c69
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\sr\messages.json
text
MD5: 59cdbb02241ab4e8a3e4421ee7800474
SHA256: 4d71ed4a97228755c0861b04da1a4c97eef7562406afc29e4213faba36fa3511
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\sk\messages.json
html
MD5: 7c3596001e0e44f016816e422f664763
SHA256: d4f5ccd81ed83b460fe2dc51a8415076716c0aa593edb28bbbbaf76a2a49ca47
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\ru\messages.json
text
MD5: e61ccfd8f13aa36fef4fd8d651aca7aa
SHA256: 04c6ac4f77a59052f5ceb07c06e6e1cf311b5d5231e8732d837c7f936c3ae219
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\sl\messages.json
html
MD5: 22a021701f9572cb94606ad35a9be88a
SHA256: 6adf87ecfc785e46593f8a8975989d344dfec3ac0e5672c394d999b7eef70a2c
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\nb\messages.json
html
MD5: 3f56c75fcbcc66ba27df14b9ca5a1119
SHA256: d09c1ed9753d6ba323012a4b4ea4f186321bc3ae9bbaa7990b5773d95cc9a242
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\pl\messages.json
html
MD5: 0bd6d31a53f196364e23f00f1f5b0768
SHA256: 4ea7d131167712c8756062d7b6e8f8ae6de7eb2be91c440d3b8b260b7c7d494e
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\ms\messages.json
html
MD5: 9c3779e6e9f6f10e232ee7ad03d75921
SHA256: 6d7e1a3b52ea61d53cf44e770c89b4a370075b786dfa64174fa8b4565d0fadf3
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\pt\messages.json
html
MD5: 816dc05089e3ec573f5d4341a748fefb
SHA256: d610e5f9fae2d429ca1ba5c41bb52b93d2551222ceb751f335b0d43695544351
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\nl\messages.json
html
MD5: 8e38c515a274c55a4b003c47a23ddb4e
SHA256: ed0c2304a02cc8c49d5f4b055b73412b31505ce290a5af73858761c50f2000ef
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\ml\messages.json
text
MD5: 90f5f8ccfc9001b7845e2437d5b83740
SHA256: a0d6831c4dcb9492ceb7d8b1ff0426bf6bc7f6a9ceec7b26dafacde8ae06a3c3
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\mr\messages.json
text
MD5: df8ae4588605c10278c88d94e9c1dbbc
SHA256: b783440d2b13c18b97b02f24e953aa7a0c778817162ac91c9afbfead2d0bc8ff
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\lt\messages.json
html
MD5: a4e08cf83276578f0444c5c0a5b5196d
SHA256: c8a5d07ff98a92409aadcacd7ae99809e5f6e3be634ded7626dad8c00ec663e1
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\lv\messages.json
html
MD5: 0cfd87cf25cd27b7928925f136978097
SHA256: a6dbd930c083e2e5dfb665131d9f1e6e6bd8896753cdb79cf059e21488a920da
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\it\messages.json
html
MD5: c248ee6105ae77036fbb4c4e3e9d66e7
SHA256: c7451e207005197a225a3e43b479643c4dbe03865c2fff052acb9facc1025980
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\ja\messages.json
html
MD5: d38392c4246c105fe2f394c7ef41d0a8
SHA256: d61644907520d8a808aed9fb1532ec0f5ef12461e66a5acc7327c9ed6c2a2681
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\ko\messages.json
html
MD5: 46060399fc358c0c0620463fbfd3f325
SHA256: 139c7f78ca0f385cfaf9f08066d3347eeeba8705f746bee8eae4e15c82ba40cc
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\iw\messages.json
html
MD5: 4b3a7915595b1f5a74027909bce968dd
SHA256: f95692a9717639fb9d3886efa9de71808cb5c6b0f4354e9b99816a996298fa8f
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\kn\messages.json
text
MD5: b79cb28daffc5af94b6ecd39a3aa4032
SHA256: 27e2c6d453cd3398f8cb64fb9d4a8776be0d80eb608088804bb23ac985a3aae7
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\id\messages.json
html
MD5: 7b9a0847c6faa8402eab61c096024d33
SHA256: 5e50b077a10a977de39a8a99dbe25ee4c022e88f34d009a665ebf4b7cff688dc
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\hu\messages.json
html
MD5: 2d794e2754e5c80f54bff8ed635184d0
SHA256: c83ec71e1b3b7f14910d05e962ecfc61dad91b034a6fa8abe6afaa5b968689e9
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\gu\messages.json
html
MD5: 18bd0fa4585a840991bbe01ea1d6bff9
SHA256: 5537157a0078c9485699fc8b103ffbbd069532e29245430c60cac08d6fc50e6e
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\hi\messages.json
html
MD5: 46fca60f4c16afd5b68738750a16057e
SHA256: 61c146d44f9c4c054c9dbe79d565463496aae7fa95f784164649026eb852dee6
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\hr\messages.json
html
MD5: 444cd89a9aab432251330292216f8dae
SHA256: 2defd1bcbd8d822f07a9c79e13e10bba7e61f49aa4d395b1315321dee6df6503
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\fi\messages.json
html
MD5: 9ad4a516864a35f4225410d0f353fb58
SHA256: 0ee5e9fd9615920fa51e50667f19e8ae4399f591de1d702516779f20d62e75f4
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\fil\messages.json
html
MD5: ec51f209a7be042e832b851430ff75c6
SHA256: c137bd71c5266addf08cac46a606285e1be10e555eef8f0dbe804effe1d94d57
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\fa\messages.json
html
MD5: edb2ec2c7f482909a814b903024ac672
SHA256: 60ce4f04acfba61db4c54f7e5e990a06535b205a12d53b62d36075b84bb5cbd8
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\fr\messages.json
html
MD5: 4d3875bef5c65792c16abe203fde1f16
SHA256: a34353385db3b07a96bb1c2da7a8e623ee296618845858a239834f7371685144
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\et\messages.json
html
MD5: 2e75cee7712c279bf151d93c40757e81
SHA256: 953cad518d95ade3150c43eb753ae24057164d3c2a2bd31109e45b9e0b42bf1b
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\de\messages.json
html
MD5: fc9bd60c101f41758269170812356cea
SHA256: 0bc5972106aa310219404ba5b9518b4d2f0f5780624ca7dd40321c4adce804ba
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\el\messages.json
text
MD5: 9463fd9c6e74bc71fd662b25719d2429
SHA256: 59a2e6a9682f367c81f381cdf0633b3217cc538604faa53f04116407f5d15608
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\en\messages.json
html
MD5: 54536c1afc37045fc1e67404d3247775
SHA256: 525f6693856ec39183a2713b1f79decd65c82c7bde0ce426200fb288f791e5ad
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\es\messages.json
html
MD5: f76e1dec23c5b058be8d85ecf814ab45
SHA256: 1eda00d6c22c88a6bdec3fd9926f842ab845555096be68a492b92a983beab199
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\da\messages.json
html
MD5: d7a7b55a20e71db0c5924ba061362bdf
SHA256: 270ad3210aa587ee077b0762e0f38aa694f06f298a2f0a8531dda812843421d1
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\ca\messages.json
html
MD5: e3cbb47ad514c8679a9681fcd22a19b7
SHA256: c0e35c1d23b8c5cf553772434d96a10e5ecf1f70170a81deca882b3f705d65d8
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\cs\messages.json
html
MD5: 6c2f7dd3e5d63d41d463fb53d890f17d
SHA256: 7891476c3333a760037df7f9f319b1e47cc19058b66a208fa0127c9d7eb962ba
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\bn\messages.json
text
MD5: 98c0e976877ae91edc3dabdcea30b227
SHA256: e74817f1f5868faece3bbe1aefb3f7967969f0ad26b7c507b04787106d22ef0e
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\bg\messages.json
text
MD5: c7d7597209588826f1612285261af898
SHA256: 31aac8506daa5f302f6c4167b923788df4aab7cdf4f0673e712ad823b63536c0
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\ar\messages.json
html
MD5: cdfef1cc3d9b1a7f8295f469e5d7cce1
SHA256: 1fd3e52e3082ada8fad1f2f2ce654edaf7e99177b43f468016e8e09f11d061a9
1372
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\_locales\am\messages.json
html
MD5: 544acece47a9653d8908af804aa24c4f
SHA256: 4b1bdceed72e74dc5a64ef305c8dc476f5e2a56e00eb6884d09b0e82e59a69f5
3444
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\CRX_INSTALL\manifest.json
text
MD5: aa820edca2a1d86c3b0a259f28cd4b6c
SHA256: 0cb121b2c53dee18adedc1fa004ca640c88644fd75c5f062ce749401f96ebf49
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\scoped_dir2652_32479\59688793-a1aa-46d7-b843-dd6c99e2209d.tmp
crx
MD5: c9f1737667f13e06aa8cfb26416cd7f9
SHA256: d9a59c97ed4b1dc1c15ce3136afc93fc45d7a2253f7e9e26100f35499f3e94bf
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\59688793-a1aa-46d7-b843-dd6c99e2209d.tmp
crx
MD5: c9f1737667f13e06aa8cfb26416cd7f9
SHA256: d9a59c97ed4b1dc1c15ce3136afc93fc45d7a2253f7e9e26100f35499f3e94bf
2652
chrome.exe
C:\Users\admin\AppData\Local\Temp\16011b2d-43c7-4751-9512-338f6d00cff9.tmp
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extension State\CURRENT
text
MD5: 46295cac801e5d4857d09837238a6394
SHA256: 0f1bad70c7bd1e0a69562853ec529355462fcd0423263a3d39d6d0d70b780443
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extension State\MANIFEST-000001
binary
MD5: 5af87dfd673ba2115e2fcf5cfdb727ab
SHA256: f9d31b278e215eb0d0e9cd709edfa037e828f36214ab7906f612160fead4b2b4
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extension State\000001.dbtmp
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\3955322a5755d8d3_0
binary
MD5: 5599fa2d75a1f2f80db3570de6060b43
SHA256: 04bd74aeb7598a922dbee4c40ac00603db50f3a4b7e0e36ac06ec42d564d9e50
1528
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000006
compressed
MD5: add5bb80416c26f7c28719e958358b3f
SHA256: a306c0648ad5677440b32ea320034994f934eb02df8bdd75c27f6bf785fefc20
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\aa3abbe71413e7c4_0
binary
MD5: 9b4e7f8e12b3b86c1c5f1b8f7e1a4432
SHA256: 79e36aafc5fe49f4235f89e727c445c4687c60b2eea410bc618cf54595f46ca2
1528
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000005
compressed
MD5: 48c4122ac24d3c0c953d9ac1c6dc5184
SHA256: 3e8670ecfba8bab1d76360c14604dec69552c444bba055269aed30d973587892
1528
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000004
image
MD5: 7941e62d27d42b5960029cffb4fada3b
SHA256: 7ca40d7689200cec17f9c2c2f64e9a76590fe894a760545dcdde0a27820e7e2f
1528
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000003
ppn
MD5: 70a228b6fe7f9e5415ac8772b7414d8f
SHA256: 0ff583cbb74be1ce8a51d90b510fc00e6248230c65eae2f5b2a3ca8cf4b69914
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\9cbb2d28459bc049_0
binary
MD5: 46806ea65e0e14d63644aaf3ebf587ba
SHA256: 547252ec4985da46d15711f35e7a49e7596c424a27de06d9bfca71e300e3d1cb
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\IndexedDB\https_www.google.com_0.indexeddb.leveldb\CURRENT
text
MD5: 46295cac801e5d4857d09837238a6394
SHA256: 0f1bad70c7bd1e0a69562853ec529355462fcd0423263a3d39d6d0d70b780443
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\IndexedDB\https_www.google.com_0.indexeddb.leveldb\000001.dbtmp
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\IndexedDB\https_www.google.com_0.indexeddb.leveldb\MANIFEST-000001
binary
MD5: 3fd11ff447c1ee23538dc4d9724427a3
SHA256: 720a78803b84cbcc8eb204d5cf8ea6ee2f693be0ab2124ddf2b81455de02a3ed
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\94854a4d2cc11b03_0
binary
MD5: 255376fc0a9effb0eb962a028351cc47
SHA256: 9e955fbbe6f74198a8ee48425f5a2e9744b214779d340700d43a6b4d79b52b1b
1528
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000002
compressed
MD5: 4f0f603a74d03043125376621159870e
SHA256: e72868e36a01ddf3394e2026eb1bdef44e11d0d8c996c0c7211b3d4ea6bd053c
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG.old
text
MD5: 1c2c4bb805e49e0719deef84894dbb1f
SHA256: 1afb26b8e579f076590e61bb63648bb0230fee4516c08ebe588dfc31efd616da
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\LOG.old~RF11ab31.TMP
text
MD5: 1c2c4bb805e49e0719deef84894dbb1f
SHA256: 1afb26b8e579f076590e61bb63648bb0230fee4516c08ebe588dfc31efd616da
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\8a292ed2628c7128_0
binary
MD5: ef49612318096db91a5c20973d4addce
SHA256: 89327211ed876d7d3c0aca51f54e8f48ebeb15269731573b92b95c790b1fe55d
1528
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000001
binary
MD5: aab3f123640292a64da9cb76efc2740d
SHA256: 3fd50f8464a8d44394274903481e3fa3000c7d73284fcb8eff2d31848bfbda82
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old
text
MD5: 1b8036252b09dda7ad0963a5a40e4aba
SHA256: 89e90f5dc88f667b89afa57d04c939a3c7397bb98b9d259766fa452ec297ec06
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.old~RF11aaf3.TMP
text
MD5: 1b8036252b09dda7ad0963a5a40e4aba
SHA256: 89e90f5dc88f667b89afa57d04c939a3c7397bb98b9d259766fa452ec297ec06
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\GPUCache\data_1
binary
MD5: f50f89a0a91564d0b8a211f8921aa7de
SHA256: b1e963d702392fb7224786e7d56d43973e9b9efd1b89c17814d7c558ffc0cdec
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_1
––
MD5:  ––
SHA256:  ––
1528
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\data_3
––
MD5:  ––
SHA256:  ––
1528
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\data_2
––
MD5:  ––
SHA256:  ––
1528
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\data_1
––
MD5:  ––
SHA256:  ––
1528
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\data_0
––
MD5:  ––
SHA256:  ––
1528
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Cache\index
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\CURRENT
text
MD5: 904754a73eb4f8a75410a92b2b7a920c
SHA256: c3225bb8babf9823a2daf2bccae0cafc5d3e0857c5f24187dc004f1b2560b4db
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\CURRENT~RF11a739.TMP
text
MD5: 904754a73eb4f8a75410a92b2b7a920c
SHA256: c3225bb8babf9823a2daf2bccae0cafc5d3e0857c5f24187dc004f1b2560b4db
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\GPUCache\data_2
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\GPUCache\data_3
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\GPUCache\data_1
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000018.dbtmp
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\GPUCache\index
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\GPUCache\data_0
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old~RF11a6ad.TMP
text
MD5: c5a804a5780cfc948a8db73979de968b
SHA256: 2c6f183b3e9dfa1bdf791091ad09cdcb079307d23864dbc07c81f280aa7d9227
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.old
text
MD5: c5a804a5780cfc948a8db73979de968b
SHA256: 2c6f183b3e9dfa1bdf791091ad09cdcb079307d23864dbc07c81f280aa7d9227
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\eacc0151-8bbb-4dd8-9b2d-942cfb616e1d.tmp
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old
text
MD5: 768258eee3510091c97ade3bca3dc828
SHA256: 1f00cceba22a3fa7d0fffdebb99b95f0dfe19d2cda162abc09fc0d8a6e8ff21d
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\LOG.old~RF11a67e.TMP
text
MD5: 768258eee3510091c97ade3bca3dc828
SHA256: 1f00cceba22a3fa7d0fffdebb99b95f0dfe19d2cda162abc09fc0d8a6e8ff21d
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.old
text
MD5: 70f27bb5ff84782e8065f81ee64e6008
SHA256: fd5dd0c6f1056c6ee6c2d29bd31653abb589e7d528957942e65b3972b7ecb4e9
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Site Characteristics Database\LOG.old
text
MD5: 007e2c8f160468cc5a8b6c225f0ac40c
SHA256: 7f09cf7ac785c12f0062eb23854505c4ed396c6522eca7109b43ad5cc1a5f74b
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_3
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_2
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\data_0
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\ShaderCache\GPUCache\index
––
MD5:  ––
SHA256:  ––
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Last Version
text
MD5: f679598350690f14a2479935d826682b
SHA256: 4e7e1987eaf5ec751eb16b9f7cbae1c55873f1afe8e2b52416ed454f4efbf239
2652
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat
binary
MD5: 9c016064a1f864c8140915d77cf3389a
SHA256: 0e7265d4a8c16223538edd8cd620b8820611c74538e420a88e333be7f62ac787
1892
chrome.exe
C:\Users\admin\AppData\Local\Google\Chrome\User Data\CrashpadMetrics.pma
binary
MD5: 9543068b6751e1f3e11f91d72ee78d95
SHA256: d060ad21ae6e04cb58668caa52adfca573e018102cc07554d2ed3eae11ab7785
3600
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{EAD82261-5F44-11E9-A370-5254004A04AF}.dat
––
MD5:  ––
SHA256:  ––
3600
iexplore.exe
C:\Users\admin\AppData\Local\Temp\~DF2C6051B542E5D14E.TMP
––
MD5:  ––
SHA256:  ––
2168
iexplore.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\IETldCache\Low\index.dat
dat
MD5: d7a950fefd60dbaa01df2d85fefb3862
SHA256: 75d0b1743f61b76a35b1fedd32378837805de58d79fa950cb6e8164bfa72073a
2168
iexplore.exe
C:\Users\admin\AppData\Local\Temp\Low\JavaDeployReg.log
text
MD5: fc94eb0a4a3f3e12ac73177bc61ff922
SHA256: fad18a17550dd3060c4c978d37daef91bd30df26280dcd26a284745c4853e244
3600
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{EAD82262-5F44-11E9-A370-5254004A04AF}.dat
binary
MD5: 8dd2718b55589669205610d3ea81f502
SHA256: bf0e6ac4406c259bfdc4b54fd5d0f5c612d40d2e30ba749a315018a74e157cf5
3600
iexplore.exe
C:\Users\admin\AppData\Local\Temp\~DF29908835C4AC6FD8.TMP
––
MD5:  ––
SHA256:  ––
3600
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Last Active\{EAD82264-5F44-11E9-A370-5254004A04AF}.dat
binary
MD5: ef60de16de6c8bc57af13ac134b08cf2
SHA256: 13cdc76cdffc5f5fea9d4301fce539b10577290490a81a3c154f02e6e088d77d
3600
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Last Active\RecoveryStore.{EAD82263-5F44-11E9-A370-5254004A04AF}.dat
binary
MD5: 94a5fbb6060e0e27f843f43489491ef6
SHA256: 21ddf3d9d327198711a9725778bba702a50eadf6f118c89ad98afc3e3061603f
3600
iexplore.exe
C:\Users\admin\AppData\Local\Temp\~DFF7996F48D9FC448C.TMP
––
MD5:  ––
SHA256:  ––
3600
iexplore.exe
C:\Users\admin\AppData\Local\Temp\~DF33FDE0956A70E0F6.TMP
––
MD5:  ––
SHA256:  ––
3600
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\favicon[1].ico
image
MD5: 4c7c7f9099100812d40f0b7cb9bc2a4d
SHA256: a613edad052cdfd11102725c5d32693d9b23b4b16f1c53e0d7180e48b7a5afdf
3600
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019041520190416\index.dat
dat
MD5: 630d6c5b5c0c119259673094bdffe447
SHA256: 5e02e536653c517bc8bc353f12bb9b13939892aa315d685ef1bff4f5faf2fddf
2168
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012019041520190416\index.dat
dat
MD5: 4009d38e0a93d9136544def0974796bc
SHA256: b371f5a6962eb4f51d3f298592472a2b2e9ad52cd88c8282983a5ff37bf27943
2168
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S1IA5T2T\google[1].js
text
MD5: e9e807476facf3fee2ae42060cd5ffee
SHA256: 0859a5b924376eb8b293bf0fec8a3330e20bbbf08662c851a63fe47ac7172aeb
2168
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.dat
dat
MD5: f488542fd4ff4c3405255b8c689f41ba
SHA256: 6f7333edc87b3ba223063fbb2d5c036cb818be717c5d841d7e78474b904e68a6
2168
iexplore.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
text
MD5: d1aaa555a98762e1c8a735e18964d66c
SHA256: 76654a8085a32d189c2907764d4ab6d97092a27b1f33c102293f5e8d65d6a066
2168
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\KQ320FYB\pixel[1].gif
image
MD5: df3e567d6f16d040326c7a0ea29a4f41
SHA256: 548f2d6f4d0d820c6c5ffbeffcbd7f0e73193e2932eefe542accc84762deec87
2168
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\C8OZ2T5Z\webvarall[1].js
html
MD5: f0fea1bd998f263bf5dee7064e1fe0e3
SHA256: 08407b8d6d32a528684430e1c84b5a3bb012dfa071894540aa3580cc0dfddedb
2168
iexplore.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
binary
MD5: 14cfdfd9ea2e741856db8ded38d49d68
SHA256: 79e03bc9e20cca73f3f579d864e08c9a89265b10d791380e61a58bebf2fb0bb5
2168
iexplore.exe
C:\Users\admin\AppData\Local\Temp\Low\Tar7FC1.tmp
––
MD5:  ––
SHA256:  ––
2168
iexplore.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
compressed
MD5: 04d79a0dc77a8f449cbff6252862d398
SHA256: 4c9c4d831d61c8c38b2513f9b431ef4f4cf6af9fb18a2317cd2178d6e0997822
2168
iexplore.exe
C:\Users\admin\AppData\Local\Temp\Low\Cab7FC0.tmp
––
MD5:  ––
SHA256:  ––
2168
iexplore.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
text
MD5: fecc9d4de17349954011ac8887ef7cf9
SHA256: 8c01f71603434354afb859066dafca1d562babd44e1f9899a230ca2f45e3bfa9
2168
iexplore.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
––
MD5:  ––
SHA256:  ––
2168
iexplore.exe
C:\Users\admin\AppData\Local\Temp\Low\Tar7F42.tmp
––
MD5:  ––
SHA256:  ––
2168
iexplore.exe
C:\Users\admin\AppData\Local\Temp\Low\Cab7F41.tmp
––
MD5:  ––
SHA256:  ––
2168
iexplore.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\070E0202839D9D67350CD2613E78E416
der
MD5: 55540a230bdab55187a841cfe1aa1545
SHA256: d73494e3446b02167573b3cde3ae1c8584ac26e15e45ac3ec0326708425d90fb
2168
iexplore.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\070E0202839D9D67350CD2613E78E416
binary
MD5: 70e40c03b932b77bc605c630e6331fb9
SHA256: a51832ea0888088188dc4588d24eb881f04aaacfe96777d31eabf27961e36448
2168
iexplore.exe
C:\Users\admin\AppData\Local\Temp\Low\Tar7F30.tmp
––
MD5:  ––
SHA256:  ––
2168
iexplore.exe
C:\Users\admin\AppData\Local\Temp\Low\Cab7F2F.tmp
––
MD5:  ––
SHA256:  ––
2168
iexplore.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
text
MD5: 59a921eac5c639d85a4fb1212d119356
SHA256: d56fdb7551a5cb84a84d227cd1c39b0dab7d21faf8593e87206b392bfba99af3
2168
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IG3FJSAF\widgets[1].js
text
MD5: 4cf9f34505e9344b9a7e4d00e67b6c88
SHA256: 460c112ca18e517ef1a6c6abb2ba5ae55187138503a10177bf1908d9261c3a19
2168
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IG3FJSAF\OqOE21UvWe3[1].png
image
MD5: b85d112f813e876dc294b4263ce4d333
SHA256: ed91fbb0cd9308f91f8e1fd93942c94ee850fc4161ed788b16f801b743c70b9b
2168
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IG3FJSAF\like[1].htm
html
MD5: 1ca30d056106e0aa49f2ad4f373e745e
SHA256: be06bcada83f825ee427f757e71b8c3ae3ec902da4cad47e511b27a6542c1757
2168
iexplore.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
text
MD5: 5e11e6f413204d3e8cb1ddfab7257c12
SHA256: 309519a7af060302713a6d5562f6ca720415d815c840300dc0cce1af2bab3d9f
2168
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\C8OZ2T5Z\like[1].php
––
MD5:  ––
SHA256:  ––
2168
iexplore.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
––
MD5:  ––
SHA256:  ––
3680
FlashUtil32_26_0_0_131_ActiveX.exe
C:\Users\admin\AppData\Roaming\Adobe\Flash Player\NativeCache\NativeCache.directory:Zone.Identifier
text
MD5: fbccf14d504b7b2dbcb5a5bda75bd93b
SHA256: eacd09517ce90d34ba562171d15ac40d302f0e691b439f91be1b6406e25f5913
2168
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\C8OZ2T5Z\signupbtn_a[1].gif
image
MD5: 61da73f3c3442505acf9f4d568df2bf3
SHA256: de08cecc1c4965638d258611622ec72ee11292ff2c76e11c6ab98a483e2fd12c
2168
iexplore.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
text
MD5: 8ed026a5dff171f604382d42c8722d39
SHA256: fb420508eb82f538af77ebef9c5be4023ee664479e88210d66a3ff44bd446c6f
2168
iexplore.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\index.dat
dat
MD5: ff2f23c384973b21d0b2400c53f9924d
SHA256: 5d124a5613a062770d9d852cc9f14a69a9fda31135ab11369ac2dba4b3dbd1f0
2168
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IG3FJSAF\urchin[1].js
text
MD5: 1f36e699091daed40331072860cce88a
SHA256: 65b488811bd504ecd9037c0aee94c56a7bcd0870c2ae8818f6cf60cb3ba51621
2168
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S1IA5T2T\webvar[1].js
text
MD5: c04343a0e863ef895b4792005e52d76c
SHA256: 8e94ca52f0ebb196efef0e33d5537b575803c418cd8e1f17a46af7628d600b65
2168
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\S1IA5T2T\rss_16[1].png
image
MD5: 0cc42effa60724945e21db95c50a409e
SHA256: 301aaa485ee45a6e3c93ebbc2d1cb9e5187086626dc4f149ba16ed884a48d146
2168
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\C8OZ2T5Z\youtube_16[1].png
image
MD5: 401814665e0ddc9c5b3114c22a23b2e8
SHA256: d571a4ccfb009a0d483717ae7e441441903a85c0ffe51822bd966a2e54dc22e4
2168
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\C8OZ2T5Z\pinterest_16[1].png
image
MD5: 72cad8a8b5f8126dd5ac28122a5099d4
SHA256: b1e76785bd19f94a7c4decb227837bf5c84f66f7c7d98529bb1cb58b562fa4f4
2168
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IG3FJSAF\link_16[1].png
image
MD5: ba373183e957cd05fecda8be83d33a6e
SHA256: d81d0a5706d7d98f66cf120a2139c874a7111097744150395f80ab5080c6923c
2412
thhjgjk.exe
C:\Users\admin\AppData\Local\Temp\n1s\nchsetup.cab
––
MD5:  ––
SHA256:  ––
2168
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT
smt
MD5: 60272cba5ad84466b761ccb17bc51037
SHA256: ed2a144c57ac894