General Info

File name

pdfelement6-pro_setup_full2990.exe

Full analysis
https://app.any.run/tasks/04940d33-9bd2-478f-b8f9-6513b899a444
Verdict
Malicious activity
Analysis date
3/14/2019, 19:48:49
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:

loader

Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

22bfe0db8cb700048b1cab4af1e6834b

SHA1

c5df3e6f41957b117503ac8811a687732b1884eb

SHA256

8eaaf2df6df0b310a2f613b921f93c02da49b4849b30a937e85e9f62c104ce58

SSDEEP

12288:jmksnrb46qwBpJEVwPQXXXgp5fmWlWYwU0fClaLM/UtfvHB1+jKB:k3XCZXXXgpxm9Yw0WuUFvv++B

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
180 seconds
Additional time used
120 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Changes settings of System certificates
  • PDFelement.exe (PID: 2996)
Loads dropped or rewritten executable
  • Setup.exe (PID: 3652)
  • PrinterRepaireTool.exe (PID: 968)
  • spoolsv.exe (PID: 1192)
  • WSHelper.exe (PID: 3928)
  • spoolsv.exe (PID: 2192)
  • spoolsv.exe (PID: 3616)
  • FileAssociation.exe (PID: 2272)
  • WSHelper.exe (PID: 1092)
  • PDFelement.exe (PID: 2996)
  • install.exe (PID: 3164)
Application was dropped or rewritten from another process
  • WSPrtSetup.exe (PID: 2972)
  • WSHelper.exe (PID: 1092)
  • FileAssociation.exe (PID: 2272)
  • WSPrtSetup.exe (PID: 2220)
  • Wondershare Helper Compact.exe (PID: 3800)
  • PrinterRepaireTool.exe (PID: 968)
  • install.exe (PID: 3164)
  • WSPrtSetup.exe (PID: 3000)
  • PDFelement.exe (PID: 2996)
  • PEOfficeAddInInstall.exe (PID: 2716)
  • Setup.exe (PID: 3652)
  • WSHelper.exe (PID: 3928)
Changes the autorun value in the registry
  • Wondershare Helper Compact.tmp (PID: 2472)
  • pdfelement6-pro_full2990.tmp (PID: 3640)
Downloads executable files from the Internet
  • pdfelement6-pro_setup_full2990.exe (PID: 3796)
Adds / modifies Windows certificates
  • PDFelement.exe (PID: 2996)
Creates files in the program directory
  • WSHelper.exe (PID: 3928)
  • WSPrtSetup.exe (PID: 2972)
  • WSPrtSetup.exe (PID: 2220)
  • WSPrtSetup.exe (PID: 3000)
Reads Environment values
  • PDFelement.exe (PID: 2996)
Executable content was dropped or overwritten
  • Wondershare Helper Compact.tmp (PID: 2472)
  • WSPrtSetup.exe (PID: 3000)
  • spoolsv.exe (PID: 1192)
  • Wondershare Helper Compact.exe (PID: 3800)
  • vcredist_x86_vc2015.exe (PID: 4068)
  • vcredist_x86_vc2008sp1.exe (PID: 3976)
  • vcredist_x86_vc2010sp1.exe (PID: 2348)
  • msiexec.exe (PID: 2212)
  • pdfelement6-pro_full2990.exe (PID: 2572)
  • pdfelement6-pro_full2990.tmp (PID: 3640)
Removes files from Windows directory
  • spoolsv.exe (PID: 1192)
  • WSPrtSetup.exe (PID: 3000)
  • msiexec.exe (PID: 2212)
Creates files in the Windows directory
  • spoolsv.exe (PID: 1192)
  • WSPrtSetup.exe (PID: 3000)
  • msiexec.exe (PID: 2212)
  • pdfelement6-pro_full2990.tmp (PID: 3640)
Modifies the open verb of a shell class
  • FileAssociation.exe (PID: 2272)
  • pdfelement6-pro_full2990.tmp (PID: 3640)
Creates files in the user directory
  • PDFelement.exe (PID: 2996)
  • pdfelement6-pro_full2990.tmp (PID: 3640)
Starts Internet Explorer
  • pdfelement6-pro_setup_full2990.exe (PID: 3796)
Searches for installed software
  • vcredist_x86_vc2015.exe (PID: 4068)
Executes scripts
  • pdfelement6-pro_full2990.tmp (PID: 3640)
Creates COM task schedule object
  • PEOfficeAddInInstall.exe (PID: 2716)
Reads Windows owner or organization settings
  • pdfelement6-pro_full2990.tmp (PID: 3640)
Reads internet explorer settings
  • pdfelement6-pro_setup_full2990.exe (PID: 3796)
Reads the Windows organization settings
  • pdfelement6-pro_full2990.tmp (PID: 3640)
Low-level read access rights to disk partition
  • pdfelement6-pro_setup_full2990.exe (PID: 3796)
Uses TASKKILL.EXE to kill process
  • pdfelement6-pro_full2990.tmp (PID: 3640)
Dropped object may contain Bitcoin addresses
  • PDFelement.exe (PID: 2996)
  • pdfelement6-pro_full2990.tmp (PID: 3640)
Reads settings of System Certificates
  • PDFelement.exe (PID: 2996)
  • pdfelement6-pro_full2990.tmp (PID: 3640)
Application was dropped or rewritten from another process
  • vcredist_x86_vc2008sp1.exe (PID: 3976)
  • vcredist_x86_vc2015.exe (PID: 560)
  • vcredist_x86_vc2015.exe (PID: 4068)
  • Wondershare Helper Compact.tmp (PID: 2472)
  • pdfelement6-pro_full2990.tmp (PID: 3640)
  • vcredist_x86_vc2010sp1.exe (PID: 2348)
Creates files in the program directory
  • Wondershare Helper Compact.tmp (PID: 2472)
  • pdfelement6-pro_full2990.tmp (PID: 3640)
Application launched itself
  • iexplore.exe (PID: 708)
Loads dropped or rewritten executable
  • vcredist_x86_vc2015.exe (PID: 4068)
  • Wondershare Helper Compact.tmp (PID: 2472)
  • pdfelement6-pro_full2990.tmp (PID: 3640)
Changes internet zones settings
  • iexplore.exe (PID: 708)
Creates a software uninstall entry
  • Wondershare Helper Compact.tmp (PID: 2472)
  • msiexec.exe (PID: 2212)
  • pdfelement6-pro_full2990.tmp (PID: 3640)
Creates files in the user directory
  • iexplore.exe (PID: 3676)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable MS Visual C++ (generic) (16.3%)
.exe
|   Win64 Executable (generic) (14.5%)
.dll
|   Win32 Dynamic Link Library (generic) (3.4%)
.exe
|   Win32 Executable (generic) (2.3%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2019:01:18 03:07:35+01:00
PEType:
PE32
LinkerVersion:
9
CodeSize:
451584
InitializedDataSize:
521728
UninitializedDataSize:
null
EntryPoint:
0x513f5
OSVersion:
5
ImageVersion:
null
SubsystemVersion:
5
Subsystem:
Windows GUI
FileVersionNumber:
2.0.13.2
ProductVersionNumber:
2.0.13.2
FileFlagsMask:
0x0017
FileFlags:
(none)
FileOS:
Win32
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
English (U.S.)
CharacterSet:
Unicode
FileDescription:
pdfelement-6-professional_setup_full2990.exe
FileVersion:
2.0.13.2
LegalCopyright:
Copyright©2017 Wondershare. All rights reserved.
ProductName:
PDFelement 6 Professional
ProductVersion:
6.8.7

Screenshots

Processes

Total processes
68
Monitored processes
30
Malicious processes
9
Suspicious processes
6

Behavior graph

+
start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start pdfelement6-pro_setup_full2990.exe no specs pdfelement6-pro_setup_full2990.exe pdfelement6-pro_full2990.exe pdfelement6-pro_full2990.tmp taskkill.exe no specs vcredist_x86_vc2008sp1.exe install.exe no specs msiexec.exe vcredist_x86_vc2010sp1.exe setup.exe vcredist_x86_vc2015.exe no specs vcredist_x86_vc2015.exe wondershare helper compact.exe wondershare helper compact.tmp wshelper.exe no specs cscript.exe no specs wsprtsetup.exe spoolsv.exe printerrepairetool.exe no specs rundll32.exe no specs spoolsv.exe wsprtsetup.exe no specs spoolsv.exe wsprtsetup.exe no specs peofficeaddininstall.exe no specs fileassociation.exe no specs pdfelement.exe iexplore.exe iexplore.exe wshelper.exe
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
1192
CMD
C:\Windows\System32\spoolsv.exe
Path
C:\Windows\System32\spoolsv.exe
Indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Spooler SubSystem App
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\spoolsv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\slc.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\credssp.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\winsta.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\umb.dll
c:\windows\system32\atl.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\localspl.dll
c:\windows\system32\spoolss.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\winspool.drv
c:\windows\system32\printisolationproxy.dll
c:\windows\system32\fxsmon.dll
c:\windows\system32\tcpmon.dll
c:\windows\system32\snmpapi.dll
c:\windows\system32\wsnmp32.dll
c:\windows\system32\msxml6.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\usbmon.dll
c:\windows\system32\wls0wndh.dll
c:\windows\system32\wsdmon.dll
c:\windows\system32\wsdapi.dll
c:\windows\system32\webservices.dll
c:\windows\system32\firewallapi.dll
c:\windows\system32\version.dll
c:\windows\system32\fundisc.dll
c:\windows\system32\fdpnp.dll
c:\windows\system32\spool\prtprocs\w32x86\winprint.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\spinf.dll
c:\windows\system32\win32spl.dll
c:\windows\system32\inetpp.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\netutils.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\wspdfelementmonitor.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\spool\drivers\w32x86\pscript5.dll
c:\windows\system32\spool\drivers\w32x86\ps5ui.dll
c:\windows\system32\ntprint.dll
c:\windows\system32\mscms.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\spool\drivers\w32x86\3\pscript5.dll
c:\windows\system32\spool\drivers\w32x86\3\ps5ui.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll

PID
2968
CMD
"C:\Users\admin\AppData\Local\Temp\pdfelement6-pro_setup_full2990.exe"
Path
C:\Users\admin\AppData\Local\Temp\pdfelement6-pro_setup_full2990.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
Description
pdfelement-6-professional_setup_full2990.exe
Version
2.0.13.2
Modules
Image
c:\users\admin\appdata\local\temp\pdfelement6-pro_setup_full2990.exe
c:\systemroot\system32\ntdll.dll

PID
3796
CMD
"C:\Users\admin\AppData\Local\Temp\pdfelement6-pro_setup_full2990.exe"
Path
C:\Users\admin\AppData\Local\Temp\pdfelement6-pro_setup_full2990.exe
Indicators
Parent process
––
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
pdfelement-6-professional_setup_full2990.exe
Version
2.0.13.2
Modules
Image
c:\users\admin\appdata\local\temp\pdfelement6-pro_setup_full2990.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\mlang.dll
c:\windows\system32\profapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\wship6.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\jscript.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\imgutil.dll
c:\windows\system32\pngfilt.dll
c:\windows\system32\dxtrans.dll
c:\windows\system32\atl.dll
c:\windows\system32\ddrawex.dll
c:\windows\system32\ddraw.dll
c:\windows\system32\dciman32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\dxtmsft.dll
c:\windows\system32\sxs.dll
c:\windows\system32\propsys.dll
c:\users\public\documents\wondershare\pdfelement6-pro_full2990.exe
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\mpr.dll
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\mssprxy.dll

PID
2572
CMD
"C:\Users\Public\Documents\Wondershare\pdfelement6-pro_full2990.exe" /VERYSILENT /NOPAGE /LANG=ENG /LOG="C:\Users\admin\AppData\Local\Temp\WAE-PDFelement 6 Professional.log" /installpath: "C:\Program Files\Wondershare\PDFelement 6 Professional\" /DIR="C:\Program Files\Wondershare\PDFelement 6 Professional\"
Path
C:\Users\Public\Documents\Wondershare\pdfelement6-pro_full2990.exe
Indicators
Parent process
pdfelement6-pro_setup_full2990.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Wondershare Software Co.,Ltd.
Description
Wondershare PDFelement 6 Pro Setup
Version
6.8.8.4159
Modules
Image
c:\users\public\documents\wondershare\pdfelement6-pro_full2990.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\shell32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\is-cmfgs.tmp\pdfelement6-pro_full2990.tmp

PID
3640
CMD
"C:\Users\admin\AppData\Local\Temp\is-CMFGS.tmp\pdfelement6-pro_full2990.tmp" /SL5="$30110,74609247,548864,C:\Users\Public\Documents\Wondershare\pdfelement6-pro_full2990.exe" /VERYSILENT /NOPAGE /LANG=ENG /LOG="C:\Users\admin\AppData\Local\Temp\WAE-PDFelement 6 Professional.log" /installpath: "C:\Program Files\Wondershare\PDFelement 6 Professional\" /DIR="C:\Program Files\Wondershare\PDFelement 6 Professional\"
Path
C:\Users\admin\AppData\Local\Temp\is-CMFGS.tmp\pdfelement6-pro_full2990.tmp
Indicators
Parent process
pdfelement6-pro_full2990.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\users\admin\appdata\local\temp\is-cmfgs.tmp\pdfelement6-pro_full2990.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\uxtheme.dll
c:\users\admin\appdata\local\temp\is-qnv5s.tmp\_isetup\_shfoldr.dll
c:\windows\system32\shfolder.dll
c:\users\admin\appdata\local\temp\is-qnv5s.tmp\wsoverlay.dll
c:\windows\system32\propsys.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\imageres.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\msftedit.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\program files\wondershare\pdfelement 6 professional\pdfelement.exe
c:\program files\wondershare\pdfelement 6 professional\unins000.exe
c:\windows\system32\shdocvw.dll
c:\users\admin\appdata\local\temp\is-qnv5s.tmp\vcredist_x86_vc2008sp1.exe
c:\users\admin\appdata\local\temp\is-qnv5s.tmp\vcredist_x86_vc2010sp1.exe
c:\users\admin\appdata\local\temp\is-qnv5s.tmp\vcredist_x86_vc2015.exe
c:\users\admin\appdata\roaming\wondershare\wondershare helper compact\wondershare helper compact.exe
c:\windows\system32\cscript.exe
c:\program files\wondershare\pdfelement 6 professional\creatorforpdfeditor\wsprtsetup.exe
c:\program files\wondershare\pdfelement 6 professional\printerrepairetool.exe
c:\windows\system32\wpdshext.dll
c:\windows\system32\winmm.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\program files\wondershare\pdfelement 6 professional\peofficeaddininstall.exe
c:\users\admin\appdata\local\temp\is-qnv5s.tmp\wsutilities.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\msxml6.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\program files\common files\microsoft shared\office14\msoxmlmf.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\schannel.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\p2pcollab.dll
c:\windows\system32\qagentrt.dll
c:\windows\system32\fveui.dll
c:\windows\system32\userenv.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\rsaenh.dll
c:\program files\wondershare\pdfelement 6 professional\fileassociation.exe
c:\windows\system32\netutils.dll

PID
3832
CMD
"C:\Windows\System32\taskkill.exe" /F /T /IM BsSndRpt.exe /IM PDFSaveAsPrinter.exe
Path
C:\Windows\System32\taskkill.exe
Indicators
No indicators
Parent process
pdfelement6-pro_full2990.tmp
User
admin
Integrity Level
HIGH
Exit code
128
Version:
Company
Microsoft Corporation
Description
Terminates Processes
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\taskkill.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\winsta.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\wbem\wmiutils.dll

PID
3976
CMD
"C:\Users\admin\AppData\Local\Temp\is-QNV5S.tmp\vcredist_x86_vc2008sp1.exe" /q /norestart
Path
C:\Users\admin\AppData\Local\Temp\is-QNV5S.tmp\vcredist_x86_vc2008sp1.exe
Indicators
Parent process
pdfelement6-pro_full2990.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft Visual C++ 2008 Redistributable Setup
Version
9.0.30729.17
Modules
Image
c:\users\admin\appdata\local\temp\is-qnv5s.tmp\vcredist_x86_vc2008sp1.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clusapi.dll
c:\windows\system32\cryptdll.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\feclient.dll
c:\windows\system32\apphelp.dll
c:\391853386070633bdd11\install.exe

PID
3164
CMD
c:\391853386070633bdd11\.\install.exe /q /norestart
Path
c:\391853386070633bdd11\install.exe
Indicators
No indicators
Parent process
vcredist_x86_vc2008sp1.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
External Installer
Version
9.0.30729.1 built by: SP
Modules
Image
c:\391853386070633bdd11\install.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\devobj.dll
c:\391853386070633bdd11\install.res.1033.dll
c:\windows\system32\secur32.dll
c:\windows\system32\msi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\msimsg.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\rpcrtremote.dll

PID
2212
CMD
C:\Windows\system32\msiexec.exe /V
Path
C:\Windows\system32\msiexec.exe
Indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\msimsg.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msisip.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\winsta.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\microsoft.net\framework\v4.0.30319\fusion.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\devrtl.dll
c:\program files\common files\microsoft shared\vc\msdia90.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\sxsstore.dll

PID
2348
CMD
"C:\Users\admin\AppData\Local\Temp\is-QNV5S.tmp\vcredist_x86_vc2010sp1.exe" /q /norestart
Path
C:\Users\admin\AppData\Local\Temp\is-QNV5S.tmp\vcredist_x86_vc2010sp1.exe
Indicators
Parent process
pdfelement6-pro_full2990.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft Visual C++ 2010 x86 Redistributable Setup
Version
10.0.40219.01
Modules
Image
c:\users\admin\appdata\local\temp\is-qnv5s.tmp\vcredist_x86_vc2010sp1.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\clusapi.dll
c:\windows\system32\cryptdll.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\feclient.dll
c:\windows\system32\apphelp.dll
c:\ad572f4ba1b1074aa62525852e90\setup.exe
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll

PID
3652
CMD
c:\ad572f4ba1b1074aa62525852e90\Setup.exe /q /norestart
Path
c:\ad572f4ba1b1074aa62525852e90\Setup.exe
Indicators
Parent process
vcredist_x86_vc2010sp1.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Setup Installer
Version
10.0.40219.1 built by: SP1Rel
Modules
Image
c:\ad572f4ba1b1074aa62525852e90\setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\ad572f4ba1b1074aa62525852e90\setupengine.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\version.dll
c:\windows\system32\msi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\secur32.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\ad572f4ba1b1074aa62525852e90\sqmapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\p2pcollab.dll
c:\windows\system32\qagentrt.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\fveui.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\msisip.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msimsg.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\rpcrtremote.dll

PID
560
CMD
"C:\Users\admin\AppData\Local\Temp\is-QNV5S.tmp\vcredist_x86_vc2015.exe" /q /norestart
Path
C:\Users\admin\AppData\Local\Temp\is-QNV5S.tmp\vcredist_x86_vc2015.exe
Indicators
No indicators
Parent process
pdfelement6-pro_full2990.tmp
User
admin
Integrity Level
HIGH
Exit code
1638
Version:
Company
Microsoft Corporation
Description
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215
Version
14.0.24215.1
Modules
Image
c:\users\admin\appdata\local\temp\is-qnv5s.tmp\vcredist_x86_vc2015.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\msi.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\profapi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\srclient.dll
c:\windows\system32\spp.dll
c:\windows\system32\vssapi.dll
c:\windows\system32\atl.dll
c:\windows\system32\vsstrace.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll

PID
4068
CMD
"C:\Users\admin\AppData\Local\Temp\is-QNV5S.tmp\vcredist_x86_vc2015.exe" /q /norestart -burn.unelevated BurnPipe.{5324286E-4F85-4360-BAA1-65FBBA620E2B} {1C373720-5695-4156-B2A0-291ACB5397EB} 560
Path
C:\Users\admin\AppData\Local\Temp\is-QNV5S.tmp\vcredist_x86_vc2015.exe
Indicators
Parent process
vcredist_x86_vc2015.exe
User
admin
Integrity Level
HIGH
Exit code
1638
Version:
Company
Microsoft Corporation
Description
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215
Version
14.0.24215.1
Modules
Image
c:\users\admin\appdata\local\temp\is-qnv5s.tmp\vcredist_x86_vc2015.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\msi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\profapi.dll
c:\windows\system32\feclient.dll
c:\users\admin\appdata\local\temp\{e2803110-78b3-4664-a479-3611a381656a}\.ba1\wixstdba.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\riched20.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\msls31.dll
c:\windows\system32\ucrtbase.dll

PID
3800
CMD
"C:\Users\admin\AppData\Roaming\Wondershare\Wondershare Helper Compact\Wondershare Helper Compact.exe" /VERYSILENT
Path
C:\Users\admin\AppData\Roaming\Wondershare\Wondershare Helper Compact\Wondershare Helper Compact.exe
Indicators
Parent process
pdfelement6-pro_full2990.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Wondershare
Description
Wondershare Helper Compact
Version
2.5.2.3
Modules
Image
c:\users\admin\appdata\roaming\wondershare\wondershare helper compact\wondershare helper compact.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\shell32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\is-g8jho.tmp\wondershare helper compact.tmp

PID
2472
CMD
"C:\Users\admin\AppData\Local\Temp\is-G8JHO.tmp\Wondershare Helper Compact.tmp" /SL5="$4018A,2104196,54272,C:\Users\admin\AppData\Roaming\Wondershare\Wondershare Helper Compact\Wondershare Helper Compact.exe" /VERYSILENT
Path
C:\Users\admin\AppData\Local\Temp\is-G8JHO.tmp\Wondershare Helper Compact.tmp
Indicators
Parent process
Wondershare Helper Compact.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Setup/Uninstall
Version
51.52.0.0
Modules
Image
c:\users\admin\appdata\local\temp\is-g8jho.tmp\wondershare helper compact.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\mpr.dll
c:\windows\system32\version.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\uxtheme.dll
c:\users\admin\appdata\local\temp\is-sr7kt.tmp\_isetup\_shfoldr.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\psapi.dll
c:\users\admin\appdata\local\temp\is-sr7kt.tmp\tempkillprocess.dll
c:\users\admin\appdata\local\temp\is-sr7kt.tmp\kpbyname.dll
c:\windows\system32\imageres.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\apphelp.dll
c:\program files\common files\wondershare\wondershare helper compact\wshelper.exe

PID
1092
CMD
"C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe" /regserver
Path
C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
Indicators
No indicators
Parent process
Wondershare Helper Compact.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Wondershare
Description
Wondershare Studio
Version
2.5.2.3
Modules
Image
c:\program files\common files\wondershare\wondershare helper compact\wshelper.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\common files\wondershare\wondershare helper compact\daqexp.dll
c:\program files\common files\wondershare\wondershare helper compact\cbscreatevc.dll
c:\program files\common files\wondershare\wondershare helper compact\cbsproducstinfo.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\olepro32.dll
c:\windows\system32\sxs.dll

PID
2708
CMD
"cscript" C:\Users\admin\AppData\Local\Temp\is-QNV5S.tmp\FixServiceModel30Reg.js
Path
C:\Windows\system32\cscript.exe
Indicators
No indicators
Parent process
pdfelement6-pro_full2990.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft ® Console Based Script Host
Version
5.8.7600.16385
Modules
Image
c:\windows\system32\cscript.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sxs.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\jscript.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\msisip.dll
c:\windows\system32\wshext.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\scrobj.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wshom.ocx
c:\windows\system32\mpr.dll
c:\windows\system32\scrrun.dll
c:\windows\system32\msxml3.dll

PID
3000
CMD
"C:\Program Files\Wondershare\PDFelement 6 Professional\CreatorForPDFEditor\WSPrtSetup.exe" /log "C:\Program Files\Wondershare\PDFelement 6 Professional/CreatorForPDFEditor/WSPrtInstall.log" /dvrname "Wondershare PDFelement" /prtname "Wondershare PDFelement" /monname "Wondershare PDFelement Monitor" /monport "Wondershare PDFelement Port" /monfile "WSPDFelementMonitor.dll"
Path
C:\Program Files\Wondershare\PDFelement 6 Professional\CreatorForPDFEditor\WSPrtSetup.exe
Indicators
Parent process
pdfelement6-pro_full2990.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Wondershare Software
Description
Version
1.0.0.1
Modules
Image
c:\program files\wondershare\pdfelement 6 professional\creatorforpdfeditor\wsprtsetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winspool.drv
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll

PID
968
CMD
"C:\Program Files\Wondershare\PDFelement 6 Professional\PrinterRepaireTool.exe"
Path
C:\Program Files\Wondershare\PDFelement 6 Professional\PrinterRepaireTool.exe
Indicators
No indicators
Parent process
pdfelement6-pro_full2990.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Wondershare Software Co.,Ltd.
Description
Wondershare PDFelement
Version
6.0.4.0
Modules
Image
c:\program files\wondershare\pdfelement 6 professional\printerrepairetool.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\mscorlib\225759bb87c854c0fff27b1d84858c21\mscorlib.ni.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll
c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll
c:\windows\system32\oleaut32.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system\52cca48930e580e3189eac47158c20be\system.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.drawing\646b4b01cb29986f8e076aa65c9e9753\system.drawing.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.windows.forms\5aac750b35b27770dccb1a43f83cced7\system.windows.forms.ni.dll
c:\windows\microsoft.net\framework\v4.0.30319\nlssorting.dll
c:\program files\wondershare\pdfelement 6 professional\pestudio.pdfelement.customizations.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\wondershare\pdfelement 6 professional\resources.dll
c:\program files\wondershare\pdfelement 6 professional\pestudio.frameworks.compacts.dll
c:\program files\wondershare\pdfelement 6 professional\wul.core.dll
c:\windows\system32\shell32.dll
c:\program files\wondershare\pdfelement 6 professional\wsutilities.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\msxml6.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\crypt32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\program files\common files\microsoft shared\office14\msoxmlmf.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\winspool.drv
c:\windows\assembly\nativeimages_v4.0.30319_32\system.serv759bfb78#\86909e4c4c7deb51e42b8f335c7aaa77\system.serviceprocess.ni.dll
c:\program files\wondershare\pdfelement 6 professional\creatorforpdfeditor\wsprtsetup.exe
c:\windows\system32\apphelp.dll

PID
3540
CMD
C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding
Path
C:\Windows\System32\rundll32.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows host process (Rundll32)
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
3616
CMD
C:\Windows\System32\spoolsv.exe
Path
C:\Windows\System32\spoolsv.exe
Indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Spooler SubSystem App
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\spoolsv.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\slc.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\umb.dll
c:\windows\system32\atl.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\localspl.dll
c:\windows\system32\spoolss.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\winspool.drv
c:\windows\system32\printisolationproxy.dll
c:\windows\system32\fxsmon.dll
c:\windows\system32\tcpmon.dll
c:\windows\system32\snmpapi.dll
c:\windows\system32\wsnmp32.dll
c:\windows\system32\msxml6.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\usbmon.dll
c:\windows\system32\wls0wndh.dll
c:\windows\system32\wspdfelementmonitor.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\wsdmon.dll
c:\windows\system32\wsdapi.dll
c:\windows\system32\webservices.dll
c:\windows\system32\firewallapi.dll
c:\windows\system32\version.dll
c:\windows\system32\fundisc.dll
c:\windows\system32\fdpnp.dll
c:\windows\system32\spool\prtprocs\w32x86\winprint.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\win32spl.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\spinf.dll
c:\windows\system32\inetpp.dll
c:\windows\system32\winsta.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\netutils.dll
c:\windows\system32\rsaenh.dll

PID
2972
CMD
"C:\Program Files\Wondershare\PDFelement 6 Professional\CreatorForPDFEditor\WSPrtSetup.exe" /log "C:\Program Files\Wondershare\PDFelement 6 Professional\CreatorForPDFEditor\UnInstall1.log" /dvrname "Wondershare PDFelement Xiamenair" /prtname "Wondershare PDFelement Xiamenair" /monname "Wondershare PDFelement Xiamenair Monitor" /monport "Wondershare PDFelement Monitor Xiamenair Port Port" /monfile "WSPDFelementMonitorXiamenair.dll" /u
Path
C:\Program Files\Wondershare\PDFelement 6 Professional\CreatorForPDFEditor\WSPrtSetup.exe
Indicators
No indicators
Parent process
PrinterRepaireTool.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Wondershare Software
Description
Version
1.0.0.1
Modules
Image
c:\program files\wondershare\pdfelement 6 professional\creatorforpdfeditor\wsprtsetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\winspool.drv
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll

PID
2192
CMD
C:\Windows\System32\spoolsv.exe
Path
C:\Windows\System32\spoolsv.exe
Indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Spooler SubSystem App
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\spoolsv.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\slc.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\umb.dll
c:\windows\system32\atl.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\localspl.dll
c:\windows\system32\spoolss.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\winspool.drv
c:\windows\system32\printisolationproxy.dll
c:\windows\system32\fxsmon.dll
c:\windows\system32\tcpmon.dll
c:\windows\system32\snmpapi.dll
c:\windows\system32\wsnmp32.dll
c:\windows\system32\msxml6.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\usbmon.dll
c:\windows\system32\wls0wndh.dll
c:\windows\system32\wspdfelementmonitor.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\wsdmon.dll
c:\windows\system32\wsdapi.dll
c:\windows\system32\webservices.dll
c:\windows\system32\firewallapi.dll
c:\windows\system32\version.dll
c:\windows\system32\fundisc.dll
c:\windows\system32\fdpnp.dll
c:\windows\system32\spool\prtprocs\w32x86\winprint.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\spinf.dll
c:\windows\system32\win32spl.dll
c:\windows\system32\inetpp.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\netutils.dll
c:\windows\system32\winsta.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\spool\drivers\w32x86\3\mxdwdrv.dll

PID
2220
CMD
"C:\Program Files\Wondershare\PDFelement 6 Professional\CreatorForPDFEditor\WSPrtSetup.exe" /log "C:\Program Files\Wondershare\PDFelement 6 Professional\CreatorForPDFEditor\Install.log" /dvrname "Wondershare PDFelement Xiamenair" /prtname "Wondershare PDFelement Xiamenair" /monname "Wondershare PDFelement Monitor Xiamenair" /monport "Wondershare PDFelement Monitor Xiamenair Port" /monfile "WSPDFelementMonitorXiamenair.dll"
Path
C:\Program Files\Wondershare\PDFelement 6 Professional\CreatorForPDFEditor\WSPrtSetup.exe
Indicators
No indicators
Parent process
PrinterRepaireTool.exe
User
admin
Integrity Level
HIGH
Exit code
2
Version:
Company
Wondershare Software
Description
Version
1.0.0.1
Modules
Image
c:\program files\wondershare\pdfelement 6 professional\creatorforpdfeditor\wsprtsetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winspool.drv
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll

PID
2716
CMD
"C:\Program Files\Wondershare\PDFelement 6 Professional\PEOfficeAddInInstall.exe"
Path
C:\Program Files\Wondershare\PDFelement 6 Professional\PEOfficeAddInInstall.exe
Indicators
No indicators
Parent process
pdfelement6-pro_full2990.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft
Description
PEOfficeAddInInstall
Version
1.0.0.0
Modules
Image
c:\program files\wondershare\pdfelement 6 professional\peofficeaddininstall.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\mscorlib\225759bb87c854c0fff27b1d84858c21\mscorlib.ni.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll
c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll
c:\windows\system32\oleaut32.dll
c:\windows\microsoft.net\framework\v4.0.30319\nlssorting.dll
c:\windows\system32\shell32.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system\52cca48930e580e3189eac47158c20be\system.ni.dll

PID
2272
CMD
"C:\Program Files\Wondershare\PDFelement 6 Professional\FileAssociation.exe" /InstallFileAssociate
Path
C:\Program Files\Wondershare\PDFelement 6 Professional\FileAssociation.exe
Indicators
No indicators
Parent process
pdfelement6-pro_full2990.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Wondershare Software Co.,Ltd.
Description
Wondershare PDFelement
Version
6.0.4.0
Modules
Image
c:\program files\wondershare\pdfelement 6 professional\fileassociation.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\mscorlib\225759bb87c854c0fff27b1d84858c21\mscorlib.ni.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll
c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll
c:\windows\system32\oleaut32.dll
c:\program files\wondershare\pdfelement 6 professional\pestudio.pdfelement.customizations.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system\52cca48930e580e3189eac47158c20be\system.ni.dll
c:\program files\wondershare\pdfelement 6 professional\resources.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.drawing\646b4b01cb29986f8e076aa65c9e9753\system.drawing.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.windows.forms\5aac750b35b27770dccb1a43f83cced7\system.windows.forms.ni.dll
c:\windows\microsoft.net\framework\v4.0.30319\nlssorting.dll
c:\program files\wondershare\pdfelement 6 professional\pestudio.frameworks.compacts.dll
c:\program files\wondershare\pdfelement 6 professional\wul.core.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\shell32.dll
c:\program files\wondershare\pdfelement 6 professional\wsutilities.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\msxml6.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\common files\microsoft shared\office14\msoxmlmf.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll

PID
2996
CMD
"C:\Program Files\Wondershare\PDFelement 6 Professional\PDFelement.exe"
Path
C:\Program Files\Wondershare\PDFelement 6 Professional\PDFelement.exe
Indicators
Parent process
pdfelement6-pro_setup_full2990.exe
User
admin
Integrity Level
HIGH
Version:
Company
Wondershare Software Co.,Ltd.
Description
Wondershare PDFelement
Version
6.8.8.4159
Modules
Image
c:\program files\wondershare\pdfelement 6 professional\pdfelement.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\mscorlib\225759bb87c854c0fff27b1d84858c21\mscorlib.ni.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll
c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll
c:\windows\system32\oleaut32.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system\52cca48930e580e3189eac47158c20be\system.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.drawing\646b4b01cb29986f8e076aa65c9e9753\system.drawing.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.windows.forms\5aac750b35b27770dccb1a43f83cced7\system.windows.forms.ni.dll
c:\program files\wondershare\pdfelement 6 professional\pestudio.frameworks.compacts.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\uxtheme.dll
c:\windows\microsoft.net\assembly\gac_msil\system.windows.forms\v4.0_4.0.0.0__b77a5c561934e089\system.windows.forms.dll
c:\program files\wondershare\pdfelement 6 professional\pestudio.pdfelement.customizations.dll
c:\program files\wondershare\pdfelement 6 professional\resources.dll
c:\windows\microsoft.net\framework\v4.0.30319\nlssorting.dll
c:\program files\wondershare\pdfelement 6 professional\wul.core.dll
c:\windows\system32\shell32.dll
c:\program files\wondershare\pdfelement 6 professional\wsutilities.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\msxml6.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\program files\common files\microsoft shared\office14\msoxmlmf.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\program files\wondershare\pdfelement 6 professional\pestudio.pdfelement.base.dll
c:\program files\wondershare\pdfelement 6 professional\pestudio.pdfelement.ui.dll
c:\program files\wondershare\pdfelement 6 professional\pestudio.pdfelement.api.dll
c:\program files\wondershare\pdfelement 6 professional\wul.localization.dll
c:\program files\wondershare\pdfelement 6 professional\wul.ctrls.dll
c:\program files\wondershare\pdfelement 6 professional\wul.zip.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xml\d86b080a37c60a872c82b912a2a63dac\system.xml.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.management\4dfa27fdd6a4cce26f99585e1c744f9b\system.management.ni.dll
c:\windows\system32\wbem\wmiutils.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\microsoft.net\framework\v4.0.30319\wminet_utils.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\program files\wondershare\pdfelement 6 professional\bugsplatdotnet2.0.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\program files\wondershare\pdfelement 6 professional\productauthor.dll
c:\program files\wondershare\pdfelement 6 professional\pestudio.pdfelement.business.dll
c:\program files\wondershare\pdfelement 6 professional\libpdfcore.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\api-ms-win-core-timezone-l1-1-0.dll
c:\windows\system32\api-ms-win-core-file-l2-1-0.dll
c:\windows\system32\api-ms-win-core-localization-l1-2-0.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
c:\windows\system32\api-ms-win-core-file-l1-2-0.dll
c:\windows\system32\api-ms-win-crt-string-l1-1-0.dll
c:\windows\system32\api-ms-win-crt-heap-l1-1-0.dll
c:\windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
c:\windows\system32\api-ms-win-crt-convert-l1-1-0.dll
c:\windows\system32\api-ms-win-crt-locale-l1-1-0.dll
c:\windows\system32\api-ms-win-crt-math-l1-1-0.dll
c:\windows\system32\api-ms-win-crt-time-l1-1-0.dll
c:\windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
c:\windows\system32\api-ms-win-crt-environment-l1-1-0.dll
c:\windows\system32\api-ms-win-crt-utility-l1-1-0.dll
c:\program files\wondershare\pdfelement 6 professional\icudt.dll
c:\program files\wondershare\pdfelement 6 professional\castle.core.dll
c:\windows\microsoft.net\framework\v4.0.30319\clrcompression.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\bcrypt.dll
c:\program files\wondershare\pdfelement 6 professional\cbsproductclient.dll
c:\windows\system32\sxs.dll
c:\program files\wondershare\pdfelement 6 professional\netcomms.dll
c:\program files\wondershare\pdfelement 6 professional\wul.ribbonctrls.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.core\55560c2014611e9119f99923c9ebdeef\system.core.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.configuration\46957030830964165644b52b0696c5d9\system.configuration.ni.dll
c:\windows\microsoft.net\framework\v4.0.30319\diasymreader.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\program files\wondershare\pdfelement 6 professional\data_api.dll
c:\windows\system32\msftedit.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\winspool.drv
c:\windows\system32\comdlg32.dll
c:\windows\system32\spool\drivers\w32x86\3\unidrvui.dll
c:\windows\system32\spool\drivers\w32x86\3\sendtoonenoteui.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\credssp.dll
c:\windows\system32\secur32.dll
c:\windows\system32\schannel.dll
c:\program files\wondershare\pdfelement 6 professional\wspdfelementmonitor.dll
c:\windows\system32\userenv.dll
c:\windows\system32\msls31.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\program files\wondershare\pdfelement 6 professional\smartupdateclient.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\structuredquery.dll
c:\windows\system32\actxprxy.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\thumbcache.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\mpr.dll
c:\windows\system32\drprov.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\portabledeviceapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\audiodev.dll
c:\windows\system32\wmvcore.dll
c:\windows\system32\wmasf.dll
c:\windows\system32\ehstorapi.dll
c:\windows\system32\networkexplorer.dll
c:\windows\system32\searchfolder.dll
c:\windows\system32\linkinfo.dll

PID
708
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" -nohome
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
pdfelement6-pro_setup_full2990.exe
User
admin
Integrity Level
HIGH
Exit code
1
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\cryptbase.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\ieui.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\clbcatq.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\url.dll
c:\windows\system32\version.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\propsys.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\msfeeds.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\userenv.dll
c:\windows\system32\linkinfo.dll

PID
3676
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:708 CREDAT:79873
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
iexplore.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\comdlg32.dll
c:\program files\internet explorer\ieshims.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rsaenh.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mlang.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\apphelp.dll
c:\program files\java\jre1.8.0_92\bin\ssv.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\version.dll
c:\progra~1\micros~1\office14\urlredir.dll
c:\windows\system32\secur32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\progra~1\micros~1\office14\msohev.dll
c:\program files\java\jre1.8.0_92\bin\jp2ssv.dll
c:\program files\java\jre1.8.0_92\bin\msvcr100.dll
c:\program files\java\jre1.8.0_92\bin\deploy.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\sxs.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\credssp.dll

PID
3928
CMD
C:\PROGRA~1\COMMON~1\WONDER~1\WONDER~1\WSHelper.exe -Embedding
Path
C:\PROGRA~1\COMMON~1\WONDER~1\WONDER~1\WSHelper.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Wondershare
Description
Wondershare Studio
Version
2.5.2.3
Modules
Image
c:\program files\common files\wondershare\wondershare helper compact\wshelper.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\common files\wondershare\wondershare helper compact\daqexp.dll
c:\program files\common files\wondershare\wondershare helper compact\cbscreatevc.dll
c:\program files\common files\wondershare\wondershare helper compact\cbsproducstinfo.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\olepro32.dll
c:\windows\system32\sxs.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\profapi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll

Registry activity

Total events
3668
Read events
2270
Write events
1380
Delete events
18

Modification events

PID
Process
Operation
Key
Name
Value
1192
spoolsv.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement\DsDriver
1192
spoolsv.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement\DsSpooler
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Monitors\Wondershare PDFelement Monitor
Driver
WSPDFelementMonitor.dll
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\Wondershare PDFelement
Dependent Files
PSCRIPT.NTF
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\Wondershare PDFelement
Configuration File
PS5UI.DLL
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\Wondershare PDFelement
Data File
PDFCREAT.PPD
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\Wondershare PDFelement
Driver
PSCRIPT5.DLL
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\Wondershare PDFelement
Help File
PSCRIPT.HLP
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\Wondershare PDFelement
Monitor
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\Wondershare PDFelement
Datatype
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\Wondershare PDFelement
Previous Names
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\Wondershare PDFelement
Version
3
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\Wondershare PDFelement
TempDir
0
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\Wondershare PDFelement
Attributes
2
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\Wondershare PDFelement
Manufacturer
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\Wondershare PDFelement
OEM URL
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\Wondershare PDFelement
HardwareID
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\Wondershare PDFelement
Provider
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\Wondershare PDFelement
Print Processor
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\Wondershare PDFelement
VendorSetup
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\Wondershare PDFelement
ColorProfiles
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\Wondershare PDFelement
InfPath
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\Wondershare PDFelement
PrinterDriverAttributes
0
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\Wondershare PDFelement
CoreDependencies
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\Wondershare PDFelement
DriverDate
01/01/1601
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\Wondershare PDFelement
DriverVersion
0.0.0.0
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\Wondershare PDFelement
MinInboxDriverVerDate
01/01/1601
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\Wondershare PDFelement
MinInboxDriverVerVersion
0.0.0.0
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
1778046
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
1778046
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
1778062
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Ports
Ne02:
1192
spoolsv.exe
write
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Devices
Wondershare PDFelement
winspool,Ne02:
1192
spoolsv.exe
write
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\PrinterPorts
Wondershare PDFelement
winspool,Ne02:,15,45
1192
spoolsv.exe
write
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Devices
Wondershare PDFelement
winspool,Ne02:
1192
spoolsv.exe
write
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\PrinterPorts
Wondershare PDFelement
winspool,Ne02:,15,45
1192
spoolsv.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Windows NT\CurrentVersion\Devices
Wondershare PDFelement
winspool,Ne02:
1192
spoolsv.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Windows NT\CurrentVersion\PrinterPorts
Wondershare PDFelement
winspool,Ne02:,15,45
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
ChangeID
1778093
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
StatusExt
0
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
Status
64
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
Name
Wondershare PDFelement
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
Share Name
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
Print Processor
winprint
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
Datatype
RAW
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
Parameters
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
Action
0
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
ObjectGUID
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
DsKeyUpdate
0
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
DsKeyUpdateForeground
0
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
Description
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
Printer Driver
Wondershare PDFelement
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
Default DevMode
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
Priority
1
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
Default Priority
0
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
StartTime
0
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
UntilTime
0
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
Separator File
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
Location
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
Attributes
0
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
txTimeout
45000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
dnsTimeout
15000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
Security
01000C80D0000000DC00000000000000140000000200BC0007000000000024000C000F000105000000000005150000007C3E9B4DF44C73593E88FD13E80300000009240030000F000105000000000005150000007C3E9B4DF44C73593E88FD13E803000000091400000000100101000000000003000000000000140008000200010100000000000100000000000A140000000020010100000000000100000000000018000C000F0001020000000000052000000020020000000B18000000001001020000000000052000000020020000010100000000000512000000010100000000000512000000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
CreatorSid
0105000000000005150000007C3E9B4DF44C73593E88FD13E8030000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
SpoolDirectory
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
Port
Wondershare PDFelement Port
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
Status
0
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement\PrinterDriverData
InitDriverVersion
1282
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
ChangeID
1778125
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement\PrinterDriverData
FreeMem
9765
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
ChangeID
1778140
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement\PrinterDriverData
JobTimeOut
0
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
ChangeID
1778141
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement\PrinterDriverData
Protocol
0
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement\PrinterDriverData
PrinterDataSize
560
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
ChangeID
1778156
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement\PrinterDriverData
PrinterData
02053002800B000080969800000000002C0100006400580200000000000000000000000000000000E7B14B4C000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
ChangeID
1778157
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement\PrinterDriverData
FeatureKeywordSize
2
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement\PrinterDriverData
FeatureKeyword
0000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
ChangeID
1778171
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
LetterSmall
5C4B03006843040000000000000000005C4B0300684304000100000002000000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\LetterSmall
FormKeyword
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
ChangeID
1778172
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
1778171
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
1778171
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
1778171
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
A0
3ED50C00FD23120000000000000000003ED50C00FD2312000200000002000000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\A0
FormKeyword
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
ChangeID
1778187
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
1778187
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
1778187
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
1778187
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
A1
9E1009003ED50C0000000000000000009E1009003ED50C000300000002000000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\A1
FormKeyword
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
ChangeID
1778188
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
1778203
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
1778203
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
1778203
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
A7
6321010047990100000000000000000063210100479901000400000002000000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\A7
FormKeyword
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
ChangeID
1778218
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
1778218
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
1778218
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
1778234
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
A8
F3CB0000632101000000000000000000F3CB0000632101000500000002000000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\A8
FormKeyword
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
ChangeID
1778234
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
1778250
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
1778250
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
1778250
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
A9
B2900000F3CB00000000000000000000B2900000F3CB00000600000002000000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\A9
FormKeyword
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
ChangeID
1778265
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
1778265
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
1778265
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
1778281
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
A10
99640000B2900000000000000000000099640000B29000000700000002000000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\A10
FormKeyword
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
ChangeID
1778296
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
1778296
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
1778312
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
1778328
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
ISO B0
BD420F002D9315000000000000000000BD420F002D9315000800000002000000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\ISO B0
FormKeyword
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
ChangeID
1778328
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
1778328
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
1778343
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
1778343
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
ISO B1
97C90A00BD420F00000000000000000097C90A00BD420F000900000002000000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\ISO B1
FormKeyword
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
ChangeID
1778359
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
1778359
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
1778359
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
1778359
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
ISO B2
AEA0070097C90A000000000000000000AEA0070097C90A000A00000002000000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\ISO B2
FormKeyword
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
ChangeID
1778375
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
1778375
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
1778375
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
1778390
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
ISO B3
6B630500AEA0070000000000000000006B630500AEA007000B00000002000000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\ISO B3
FormKeyword
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
ChangeID
1778390
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
1778390
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
1778406
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
1778406
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
ISO B4
07D103006B630500000000000000000007D103006B6305000C00000002000000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\ISO B4
FormKeyword
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
ChangeID
1778421
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
1778421
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
1778421
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
1778421
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
ISO B5
A4AF020007D103000000000000000000A4AF020007D103000D00000002000000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\ISO B5
FormKeyword
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
ChangeID
1778437
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
1778437
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
1778437
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
1778437
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
ISO B6
D3E70100A4AF02000000000000000000D3E70100A4AF02000E00000002000000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\ISO B6
FormKeyword
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
ChangeID
1778453
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
1778453
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
1778453
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
1778453
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
JIS B0
DFB70F002A3716000000000000000000DFB70F002A3716000F00000002000000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\JIS B0
FormKeyword
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
ChangeID
1778468
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
1778468
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
1778468
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
1778468
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
JIS B1
451C0B00DFB70F000000000000000000451C0B00DFB70F001000000002000000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\JIS B1
FormKeyword
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
ChangeID
1778484
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
1778484
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
1778484
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
1778484
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
JIS B2
F0DB0700451C0B000000000000000000F0DB0700451C0B001100000002000000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\JIS B2
FormKeyword
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
ChangeID
1778485
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
1778485
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
1778500
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
1778500
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
JIS B3
238E0500F0DB07000000000000000000238E0500F0DB07001200000002000000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\JIS B3
FormKeyword
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
ChangeID
1778500
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
1778500
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
1778515
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
1778515
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
JIS B4
97EC0300238E0500000000000000000097EC0300238E05001300000002000000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\JIS B4
FormKeyword
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
ChangeID
1778515
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
1778515
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
1778516
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
1778516
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
JIS B5
11C7020097EC0300000000000000000011C7020097EC03001400000002000000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\JIS B5
FormKeyword
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
ChangeID
1778516
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
1778531
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
1778531
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
1778531
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
JIS B6
3AF4010011C7020000000000000000003AF4010011C702001500000002000000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\JIS B6
FormKeyword
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
ChangeID
1778531
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
1778532
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
1778532
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
1778532
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
C0
85FD0D000CCB1300000000000000000085FD0D000CCB13001600000002000000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\C0
FormKeyword
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
ChangeID
1778546
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
1778546
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
1778546
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
1778546
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
C1
75E3090085FD0D00000000000000000075E3090085FD0D001700000002000000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\C1
FormKeyword
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
ChangeID
1778562
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
1778562
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
1778562
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
1778562
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
C2
B2FC060075E309000000000000000000B2FC060075E309001800000002000000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\C2
FormKeyword
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
ChangeID
1778563
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
1778563
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
1778563
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
1778578
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
C3
0AF10400B2FC060000000000000000000AF10400B2FC06001900000002000000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\C3
FormKeyword
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
ChangeID
1778578
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
1778578
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
1778578
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
1778579
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
C4
597E03000AF104000000000000000000597E03000AF104001A00000002000000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\C4
FormKeyword
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
ChangeID
1778593
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
1778593
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
1778593
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
1779000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
TV HDTV 1920x1080
D5550A0048D005000000000000000000D5550A0048D005003B00000002000000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\TV HDTV 1920x1080
FormKeyword
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
ChangeID
1779000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
1779000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
1779000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
1779001
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement\PrinterDriverData
Forms?
1280029159
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
ChangeID
1779001
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement\PrinterDriverData
DependentFiles
PSCRIPT.NTF
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
ChangeID
1779015
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
Status
128
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
DsKeyUpdateForeground
1
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement\DsSpooler
driverName
Wondershare PDFelement
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement\DsSpooler
portName
Wondershare PDFelement Port
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement\DsSpooler
printStartTime
0
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement\DsSpooler
printEndTime
0
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement\DsSpooler
printerName
Wondershare PDFelement
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement\DsSpooler
printKeepPrintedJobs
00
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement\DsSpooler
printSpooling
PrintWhileSpooling
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement\DsSpooler
priority
1
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement\DsSpooler
uNCName
\\User-PC\Wondershare PDFelement
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
1778593
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
C5
85780200597E0300000000000000000085780200597E03001B00000002000000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\C5
FormKeyword
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Wondershare PDFelement
ChangeID
1778594
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
1778609
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
1778609
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
1778609
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
C6
1BBD01008578020000000000000000001BBD0100857802001C00000002000000
1192
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\C6
FormKeyword
1192
spoolsv.exe