General Info

File name

PhotoViewer_1567336589_chenbin_004.exe

Full analysis
https://app.any.run/tasks/d67ae70b-b757-43c1-a90c-4d769e4bfeff
Verdict
Malicious activity
Analysis date
11/8/2018, 07:56:26
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

3f56d321fe1c641c8332330048da9585

SHA1

269c4c5b8f362ee10d1b07634091e54ae2dfbde3

SHA256

94f8da554badde07262daa78bf2103866ec42202b56b98c2930444177c40bb8e

SSDEEP

196608:ySf1WDFtd844trHSijias2g1FKmVCaQnCVhvHYv/9+:ySf1ktdj4tuJaveKGbQnCVJHYv/M

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads dropped or rewritten executable
  • PhotoViewer.exe (PID: 2392)
  • svchost.exe (PID: 2404)
  • svchost.exe (PID: 836)
  • regsvr32.exe (PID: 3048)
  • regsvr32.exe (PID: 2348)
  • PhotoViewer.exe (PID: 3260)
  • PdfReader.exe (PID: 3276)
Application was dropped or rewritten from another process
  • PdfReader.exe (PID: 3276)
  • Report.exe (PID: 3240)
  • PhotoViewer.exe (PID: 2392)
  • PhotoViewer.exe (PID: 3260)
Loads the Task Scheduler COM API
  • PhotoViewer_1567336589_chenbin_004.exe (PID: 2852)
Registers / Runs the DLL via REGSVR32.EXE
  • PhotoViewer_1567336589_chenbin_004.exe (PID: 2852)
Modifies the open verb of a shell class
  • PdfReader.exe (PID: 3276)
  • PhotoViewer.exe (PID: 2392)
Creates files in the Windows directory
  • svchost.exe (PID: 836)
Executable content was dropped or overwritten
  • PhotoViewer_1567336589_chenbin_004.exe (PID: 2852)
Creates a software uninstall entry
  • PhotoViewer_1567336589_chenbin_004.exe (PID: 2852)
Creates or modifies windows services
  • regsvr32.exe (PID: 3048)
Creates files in the user directory
  • PhotoViewer_1567336589_chenbin_004.exe (PID: 2852)
Creates COM task schedule object
  • regsvr32.exe (PID: 2348)
Uses TASKKILL.EXE to kill process
  • PhotoViewer_1567336589_chenbin_004.exe (PID: 2852)

No info indicators.

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable (generic) (3.6%)
.exe
|   Generic Win/DOS Executable (1.6%)
.exe
|   DOS Executable Generic (1.5%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2018:07:12 11:11:16+02:00
PEType:
PE32
LinkerVersion:
14
CodeSize:
1135616
InitializedDataSize:
8582144
UninitializedDataSize:
null
EntryPoint:
0xa52ee
OSVersion:
5.1
ImageVersion:
null
SubsystemVersion:
5.1
Subsystem:
Windows GUI
FileVersionNumber:
1.4.0.6
ProductVersionNumber:
1.4.0.6
FileFlagsMask:
0x003f
FileFlags:
(none)
FileOS:
Windows NT 32-bit
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
Chinese (Simplified)
CharacterSet:
Unicode
CompanyName:
上海展盟网络科技有限公司
FileDescription:
ABC看图安装包
FileVersion:
1.4.0.6
InternalName:
install.exe
LegalCopyright:
Copyright © 2016 上海展盟网络科技有限公司 All Rights Reserved
OriginalFileName:
install.exe
ProductName:
ABC看图
ProductVersion:
1.4.0.6
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
12-Jul-2018 09:11:16
Detected languages
Chinese - PRC
Debug artifacts
E:\svn\photoviewer\bin\Release\Install.pdb
CompanyName:
上海展盟网络科技有限公司
FileDescription:
ABC看图安装包
FileVersion:
1.4.0.6
InternalName:
install.exe
LegalCopyright:
Copyright © 2016 上海展盟网络科技有限公司 All Rights Reserved
OriginalFilename:
install.exe
ProductName:
ABC看图
ProductVersion:
1.4.0.6
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x00000130
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
7
Time date stamp:
12-Jul-2018 09:11:16
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x00115269 0x00115400 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.51654
.rdata 0x00117000 0x0003A3A0 0x0003A400 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 5.25712
.data 0x00152000 0x00006764 0x00002C00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 4.36545
.gfids 0x00159000 0x000001D4 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 3.60591
.tls 0x0015A000 0x00000009 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0.0203931
.rsrc 0x0015B000 0x007DFA60 0x007DFC00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 7.99632
.reloc 0x0093B000 0x0000E794 0x0000E800 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_DISCARDABLE,IMAGE_SCN_MEM_READ 6.58008
Resources
1

2

3

4

5

6

7

103

109

128

7ZDATA

7ZDATAMD5

SKINDATA

Imports
    KERNEL32.dll

    USER32.dll

    ADVAPI32.dll

    SHELL32.dll

    ole32.dll

    OLEAUT32.dll

    SHLWAPI.dll

    WS2_32.dll

    VERSION.dll

    IPHLPAPI.DLL

    urlmon.dll

    WININET.dll

    imagehlp.dll

    GDI32.dll

    IMM32.dll

    COMCTL32.dll

    gdiplus.dll

    WLDAP32.dll

Exports

    No exports.

Screenshots

Processes

Total processes
57
Monitored processes
17
Malicious processes
6
Suspicious processes
1

Behavior graph

+
drop and start drop and start drop and start start photoviewer_1567336589_chenbin_004.exe no specs photoviewer_1567336589_chenbin_004.exe taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs photoviewer.exe no specs svchost.exe no specs pdfreader.exe no specs report.exe photoviewer.exe svchost.exe
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
836
CMD
C:\Windows\system32\svchost.exe -k netsvcs
Path
C:\Windows\System32\svchost.exe
Indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Host Process for Windows Services
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\gpsvc.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\nsi.dll
c:\windows\system32\sysntfy.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\themeservice.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\profsvc.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\atl.dll
c:\windows\system32\winsta.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\slc.dll
c:\windows\system32\sens.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\shsvcs.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\schedsvc.dll
c:\windows\system32\pcwum.dll
c:\windows\system32\shell32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\authz.dll
c:\windows\system32\ubpm.dll
c:\windows\system32\ktmw32.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\credssp.dll
c:\windows\system32\fveapi.dll
c:\windows\system32\tbs.dll
c:\windows\system32\fvecerts.dll
c:\windows\system32\logoncli.dll
c:\windows\system32\wiarpc.dll
c:\windows\system32\samlib.dll
c:\windows\system32\taskcomp.dll
c:\windows\system32\version.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\netjoin.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\ikeext.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\wbem\wmisvc.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\iphlpsvc.dll
c:\windows\system32\firewallapi.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sqmapi.dll
c:\windows\system32\wdscore.dll
c:\windows\system32\srvsvc.dll
c:\windows\system32\browser.dll
c:\windows\system32\vssapi.dll
c:\windows\system32\vsstrace.dll
c:\windows\system32\samcli.dll
c:\windows\system32\sscore.dll
c:\windows\system32\clusapi.dll
c:\windows\system32\cryptdll.dll
c:\windows\system32\resutils.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\nci.dll
c:\windows\system32\propsys.dll
c:\windows\system32\sxs.dll
c:\windows\system32\netprofm.dll
c:\windows\system32\spinf.dll
c:\windows\system32\wbem\wbemcore.dll
c:\windows\system32\wbem\esscli.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\wmiutils.dll
c:\windows\system32\wbem\repdrvfs.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\npmproxy.dll
c:\windows\system32\wbem\wmiprvsd.dll
c:\windows\system32\ncobjapi.dll
c:\windows\system32\wbem\wbemess.dll
c:\windows\system32\appinfo.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\wbem\ncprov.dll
c:\windows\system32\qmgr.dll
c:\windows\system32\bitsperf.dll
c:\windows\system32\bitsigd.dll
c:\windows\system32\upnp.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\ssdpapi.dll
c:\windows\system32\wuaueng.dll
c:\windows\system32\esent.dll
c:\windows\system32\winspool.drv
c:\windows\system32\cabinet.dll
c:\windows\system32\mspatcha.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wmsgapi.dll
c:\windows\system32\wer.dll
c:\windows\system32\hnetcfg.dll
c:\windows\system32\netcfgx.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\ndiscapcfg.dll
c:\windows\system32\rascfg.dll
c:\windows\system32\mprapi.dll
c:\windows\system32\tcpipcfg.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\es.dll
c:\windows\system32\aelupsvc.dll
c:\windows\system32\windanr.exe
c:\users\admin\appdata\local\temp\photoviewer_1567336589_chenbin_004.exe
c:\users\admin\appdata\roaming\photoviewer\photoviewer.exe
c:\users\admin\appdata\roaming\photoviewer\pdfreader.exe
c:\users\admin\appdata\roaming\photoviewer\report.exe
c:\users\admin\appdata\roaming\photoviewer\shellext.dll

PID
2312
CMD
"C:\Users\admin\AppData\Local\Temp\PhotoViewer_1567336589_chenbin_004.exe"
Path
C:\Users\admin\AppData\Local\Temp\PhotoViewer_1567336589_chenbin_004.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
上海展盟网络科技有限公司
Description
ABC看图安装包
Version
1.4.0.6
Modules
Image
c:\users\admin\appdata\local\temp\photoviewer_1567336589_chenbin_004.exe
c:\systemroot\system32\ntdll.dll

PID
2852
CMD
"C:\Users\admin\AppData\Local\Temp\PhotoViewer_1567336589_chenbin_004.exe"
Path
C:\Users\admin\AppData\Local\Temp\PhotoViewer_1567336589_chenbin_004.exe
Indicators
Parent process
––
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
上海展盟网络科技有限公司
Description
ABC看图安装包
Version
1.4.0.6
Modules
Image
c:\users\admin\appdata\local\temp\photoviewer_1567336589_chenbin_004.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\propsys.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\profapi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\regsvr32.exe
c:\windows\system32\shdocvw.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\users\admin\appdata\roaming\photoviewer\photoviewer.exe
c:\users\admin\appdata\roaming\photoviewer\uninst.exe
c:\users\admin\appdata\roaming\photoviewer\photomanager.exe
c:\users\admin\appdata\roaming\photoviewer\pdfreader.exe
c:\windows\system32\taskschd.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\winmm.dll
c:\users\admin\appdata\roaming\photoviewer\report.exe
c:\windows\system32\netutils.dll

PID
2092
CMD
"C:\Windows\System32\taskkill.exe" /f /im PhotoViewer.exe
Path
C:\Windows\System32\taskkill.exe
Indicators
No indicators
Parent process
PhotoViewer_1567336589_chenbin_004.exe
User
admin
Integrity Level
HIGH
Exit code
128
Version:
Company
Microsoft Corporation
Description
Terminates Processes
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\taskkill.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\winsta.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll

PID
2644
CMD
"C:\Windows\System32\taskkill.exe" /f /im Photomanager.exe
Path
C:\Windows\System32\taskkill.exe
Indicators
No indicators
Parent process
PhotoViewer_1567336589_chenbin_004.exe
User
admin
Integrity Level
HIGH
Exit code
128
Version:
Company
Microsoft Corporation
Description
Terminates Processes
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\taskkill.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\winsta.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll

PID
548
CMD
"C:\Windows\System32\taskkill.exe" /f /im PdfReader.exe
Path
C:\Windows\System32\taskkill.exe
Indicators
No indicators
Parent process
PhotoViewer_1567336589_chenbin_004.exe
User
admin
Integrity Level
HIGH
Exit code
128
Version:
Company
Microsoft Corporation
Description
Terminates Processes
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\taskkill.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\winsta.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll

PID
2744
CMD
"C:\Windows\System32\taskkill.exe" /f /im Update.exe
Path
C:\Windows\System32\taskkill.exe
Indicators
No indicators
Parent process
PhotoViewer_1567336589_chenbin_004.exe
User
admin
Integrity Level
HIGH
Exit code
128
Version:
Company
Microsoft Corporation
Description
Terminates Processes
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\taskkill.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\winsta.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll

PID
2820
CMD
"C:\Windows\System32\taskkill.exe" /f /im Report.exe
Path
C:\Windows\System32\taskkill.exe
Indicators
No indicators
Parent process
PhotoViewer_1567336589_chenbin_004.exe
User
admin
Integrity Level
HIGH
Exit code
128
Version:
Company
Microsoft Corporation
Description
Terminates Processes
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\taskkill.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\mpr.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\winsta.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll

PID
3000
CMD
"C:\Windows\system32\regsvr32.exe" /s /u C:\Users\admin\AppData\Roaming\PhotoViewer\ShellExt.dll
Path
C:\Windows\system32\regsvr32.exe
Indicators
No indicators
Parent process
PhotoViewer_1567336589_chenbin_004.exe
User
admin
Integrity Level
HIGH
Exit code
3
Version:
Company
Microsoft Corporation
Description
Microsoft(C) Register Server
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll

PID
128
CMD
"C:\Windows\system32\regsvr32.exe" /s /u C:\Users\admin\AppData\Roaming\PhotoViewer\Checker.dll
Path
C:\Windows\system32\regsvr32.exe
Indicators
No indicators
Parent process
PhotoViewer_1567336589_chenbin_004.exe
User
admin
Integrity Level
HIGH
Exit code
3
Version:
Company
Microsoft Corporation
Description
Microsoft(C) Register Server
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll

PID
2348
CMD
"C:\Windows\system32\regsvr32.exe" /s C:\Users\admin\AppData\Roaming\PhotoViewer\ShellExt.dll
Path
C:\Windows\system32\regsvr32.exe
Indicators
No indicators
Parent process
PhotoViewer_1567336589_chenbin_004.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft(C) Register Server
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\users\admin\appdata\roaming\photoviewer\shellext.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll

PID
3048
CMD
"C:\Windows\system32\regsvr32.exe" /s C:\Users\admin\AppData\Roaming\PhotoViewer\Checker.dll
Path
C:\Windows\system32\regsvr32.exe
Indicators
No indicators
Parent process
PhotoViewer_1567336589_chenbin_004.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft(C) Register Server
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\users\admin\appdata\roaming\photoviewer\checker.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll

PID
2404
CMD
C:\Windows\System32\svchost.exe -k PhotoviewerChecker
Path
C:\Windows\System32\svchost.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Host Process for Windows Services
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\svchost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\users\admin\appdata\roaming\photoviewer\checker.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll

PID
2392
CMD
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" -regnoui
Path
C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe
Indicators
No indicators
Parent process
PhotoViewer_1567336589_chenbin_004.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
上海展盟网络科技有限公司
Description
ABC看图
Version
1.4.0.6
Modules
Image
c:\users\admin\appdata\roaming\photoviewer\photoviewer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\roaming\photoviewer\utilities.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\users\admin\appdata\roaming\photoviewer\soui.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\users\admin\appdata\roaming\photoviewer\freeimage.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\users\admin\appdata\roaming\photoviewer\sqlite3.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\version.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\users\admin\appdata\roaming\photoviewer\render-gdi.dll
c:\windows\system32\msimg32.dll
c:\users\admin\appdata\roaming\photoviewer\imgdecoder-gdip.dll
c:\windows\system32\riched20.dll
c:\windows\system32\windowscodecs.dll
c:\users\admin\appdata\roaming\photoviewer\translator.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntmarta.dll

PID
3276
CMD
"C:\Users\admin\AppData\Roaming\PhotoViewer\PdfReader.exe" -regall
Path
C:\Users\admin\AppData\Roaming\PhotoViewer\PdfReader.exe
Indicators
No indicators
Parent process
PhotoViewer_1567336589_chenbin_004.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
上海展盟网络科技有限公司
Description
PDF阅读 - ABC看图
Version
1.4.0.6
Modules
Image
c:\users\admin\appdata\roaming\photoviewer\pdfreader.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\roaming\photoviewer\utilities.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\users\admin\appdata\roaming\photoviewer\soui.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\users\admin\appdata\roaming\photoviewer\pdfium.dll
c:\users\admin\appdata\roaming\photoviewer\sqlite3.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\version.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\cscapi.dll

PID
3240
CMD
"C:\Users\admin\AppData\Roaming\PhotoViewer\Report.exe"
Path
C:\Users\admin\AppData\Roaming\PhotoViewer\Report.exe
Indicators
Parent process
PhotoViewer_1567336589_chenbin_004.exe
User
admin
Integrity Level
HIGH
Version:
Company
上海展盟网络科技有限公司
Description
看图上报程序
Version
1.4.0.6
Modules
Image
c:\users\admin\appdata\roaming\photoviewer\report.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\version.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshtcpip.dll

PID
3260
CMD
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe"
Path
C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
上海展盟网络科技有限公司
Description
ABC看图
Version
1.4.0.6
Modules
Image
c:\users\admin\appdata\roaming\photoviewer\photoviewer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\roaming\photoviewer\utilities.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\users\admin\appdata\roaming\photoviewer\soui.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\users\admin\appdata\roaming\photoviewer\freeimage.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\users\admin\appdata\roaming\photoviewer\sqlite3.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\version.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\users\admin\appdata\roaming\photoviewer\render-gdi.dll
c:\windows\system32\msimg32.dll
c:\users\admin\appdata\roaming\photoviewer\imgdecoder-gdip.dll
c:\windows\system32\riched20.dll
c:\windows\system32\windowscodecs.dll
c:\users\admin\appdata\roaming\photoviewer\translator.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\mlang.dll
c:\windows\system32\wship6.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\propsys.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\uxtheme.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\users\admin\appdata\roaming\photoviewer\shellext.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\msftedit.dll
c:\windows\system32\msls31.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\searchfolder.dll
c:\windows\system32\structuredquery.dll
c:\windows\system32\secur32.dll
c:\windows\system32\thumbcache.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\mssvp.dll
c:\windows\system32\mapi32.dll
c:\windows\system32\networkexplorer.dll
c:\windows\system32\actxprxy.dll
c:\windows\system32\mpr.dll
c:\windows\system32\drprov.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\winmm.dll
c:\windows\system32\portabledeviceapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\audiodev.dll
c:\windows\system32\wmvcore.dll
c:\windows\system32\wmasf.dll
c:\windows\system32\ehstorapi.dll

Registry activity

Total events
1962
Read events
1223
Write events
738
Delete events
1

Modification events

PID
Process
Operation
Key
Name
Value
3260
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3260
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3260
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\PhotoViewer_RASAPI32
EnableFileTracing
0
3260
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\PhotoViewer_RASAPI32
EnableConsoleTracing
0
3260
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\PhotoViewer_RASAPI32
FileTracingMask
4294901760
3260
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\PhotoViewer_RASAPI32
ConsoleTracingMask
4294901760
3260
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\PhotoViewer_RASAPI32
MaxFileSize
1048576
3260
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\PhotoViewer_RASAPI32
FileDirectory
%windir%\tracing
3260
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\PhotoViewer_RASMANCS
EnableFileTracing
0
3260
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\PhotoViewer_RASMANCS
EnableConsoleTracing
0
3260
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\PhotoViewer_RASMANCS
FileTracingMask
4294901760
3260
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\PhotoViewer_RASMANCS
ConsoleTracingMask
4294901760
3260
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\PhotoViewer_RASMANCS
MaxFileSize
1048576
3260
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\PhotoViewer_RASMANCS
FileDirectory
%windir%\tracing
3260
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3260
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3260
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\PhotoViewer\Report\offline\MainProcess.Run96C063BF-2E6D-4107-BBC7-04E488B35B9F
code
7A190F5FBD560566367623A7EF775C5422966399B01CF475B7EBE2F9B0F97A
3260
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\PhotoViewer\Report\offline\MainProcess.Run96C063BF-2E6D-4107-BBC7-04E488B35B9F
path
5991DF6460B0A5D25AA3D5EB20CE1B1425A31AAE151BCF
3260
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
{EF30B71A-4E28-40B6-88F4-789E9629838E} {0C6C4200-C589-11D0-999A-00C04FD655E1} 0xFFFF
0100000000000000A2880C503077D401
3260
PhotoViewer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
NodeSlots
0202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
3260
PhotoViewer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
MRUListEx
0200000000000000010000000700000006000000030000000500000004000000FFFFFFFF
3260
PhotoViewer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\50\ComDlg
TV_FolderType
{FBB3477E-C9E4-4B3B-A2BA-D3F5D3CD46F9}
3260
PhotoViewer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\50\ComDlg
TV_TopViewID
{82BA0782-5B7A-4569-B5D7-EC83085F08CC}
3260
PhotoViewer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\50\ComDlg
TV_TopViewVersion
0
3260
PhotoViewer.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
3260
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU
2
500068006F0074006F005600690065007700650072002E00650078006500000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000DC000000560000005C03000036020000000000000000000000000000000000000100000000000000
3260
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU
2
500068006F0074006F005600690065007700650072002E0065007800650000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000DC00000056000000250400005E02000000000000000000000000000000000000DC000000560000005C03000036020000000000000000000000000000000000000100000000000000
3260
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU
MRUListEx
020000000100000000000000FFFFFFFF
3260
PhotoViewer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\ComDlg\{FBB3477E-C9E4-4B3B-A2BA-D3F5D3CD46F9}\{82BA0782-5B7A-4569-B5D7-EC83085F08CC}
Mode
4
3260
PhotoViewer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\ComDlg\{FBB3477E-C9E4-4B3B-A2BA-D3F5D3CD46F9}\{82BA0782-5B7A-4569-B5D7-EC83085F08CC}
LogicalViewMode
1
3260
PhotoViewer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\ComDlg\{FBB3477E-C9E4-4B3B-A2BA-D3F5D3CD46F9}\{82BA0782-5B7A-4569-B5D7-EC83085F08CC}
FFlags
1092616193
3260
PhotoViewer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\ComDlg\{FBB3477E-C9E4-4B3B-A2BA-D3F5D3CD46F9}\{82BA0782-5B7A-4569-B5D7-EC83085F08CC}
IconSize
16
3260
PhotoViewer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\ComDlg\{FBB3477E-C9E4-4B3B-A2BA-D3F5D3CD46F9}\{82BA0782-5B7A-4569-B5D7-EC83085F08CC}
ColInfo
00000000000000000000000000000000FDDFDFFD100000000000000000000000040000001800000030F125B7EF471A10A5F102608C9EEBAC0A0000001001000030F125B7EF471A10A5F102608C9EEBAC0E0000007800000030F125B7EF471A10A5F102608C9EEBAC040000007800000030F125B7EF471A10A5F102608C9EEBAC0C00000050000000
3260
PhotoViewer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\ComDlg\{FBB3477E-C9E4-4B3B-A2BA-D3F5D3CD46F9}\{82BA0782-5B7A-4569-B5D7-EC83085F08CC}
Sort
000000000000000000000000000000000200000030F125B7EF471A10A5F102608C9EEBAC0A0000000100000030F125B7EF471A10A5F102608C9EEBAC0E000000FFFFFFFF
3260
PhotoViewer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\ComDlg\{FBB3477E-C9E4-4B3B-A2BA-D3F5D3CD46F9}\{82BA0782-5B7A-4569-B5D7-EC83085F08CC}
FFlags
1
3260
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CIDOpen\Modules\GlobalSettings\ProperTreeModuleInner
ProperTreeModuleInner
9C000000980000003153505305D5CDD59C2E1B10939708002B2CF9AE3B0000002A000000004E0061007600500061006E0065005F004300460044005F0046006900720073007400520075006E0000000B000000000000004100000030000000004E0061007600500061006E0065005F00530068006F0077004C00690062007200610072007900500061006E00650000000B000000FFFF00000000000000000000
3260
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Modules\NavPane
ExpandedState
06000000160014001F8080A63C324DC29940B94D446DD2D7249E0000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000160014001F4225481E03947BC34DB131E946B44C8DD50000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000160014001F43983FFBB4EAC18D42A78AD1F5659CBA930000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D0000000000000000002000000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000160014001F580D1A2CF021BE504388B07367FC96EF3C0000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B00000000000000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000160014001F50E04FD020EA3A6910A2D808002B30309D0000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000
2852
PhotoViewer_1567336589_chenbin_004.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2852
PhotoViewer_1567336589_chenbin_004.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2852
PhotoViewer_1567336589_chenbin_004.exe
write
HKEY_CURRENT_USER\Software\PhotoViewer\Install
QID
chenbin_004
2852
PhotoViewer_1567336589_chenbin_004.exe
write
HKEY_CURRENT_USER\Software\PhotoViewer\Install
Version
1.4.0.6
2852
PhotoViewer_1567336589_chenbin_004.exe
write
HKEY_CURRENT_USER\Software\PhotoViewer\Install
Path
C:\Users\admin\AppData\Roaming\PhotoViewer\
2852
PhotoViewer_1567336589_chenbin_004.exe
write
HKEY_CURRENT_USER\Software\PhotoViewer\Install
InstallCount
1
2852
PhotoViewer_1567336589_chenbin_004.exe
write
HKEY_CURRENT_USER\Software\PhotoViewer\Install
InstallDate
181108
2852
PhotoViewer_1567336589_chenbin_004.exe
write
HKEY_CURRENT_USER\Software\PhotoViewer\Install
md5
3f56d321fe1c641c8332330048da9585
2852
PhotoViewer_1567336589_chenbin_004.exe
write
HKEY_CURRENT_USER\Software\PhotoViewer\Install
FirstInstallTime
32DEE35B00000000
2852
PhotoViewer_1567336589_chenbin_004.exe
write
HKEY_CURRENT_USER\Software\PhotoViewer\Install
c_d
73E444ABC9E6FD68722AE336B2C5C6CA12D8473F3CE9BD1F96A24D87C2121A74A0C91820A897D93A
2852
PhotoViewer_1567336589_chenbin_004.exe
write
HKEY_CURRENT_USER\Software\PhotoViewer\Install
c_u
FBFD44AC0B9D7B134992B6B13F230C77
2852
PhotoViewer_1567336589_chenbin_004.exe
write
HKEY_CURRENT_USER\Software\PhotoViewer\Install
c_m
1962D7
2852
PhotoViewer_1567336589_chenbin_004.exe
write
HKEY_CURRENT_USER\Software\PhotoViewer\Install
p_d
73E444ABC9E6FD68722AE336B2C5C6CA12D8473F3CE9BD1F96A24D87C2121A74A0C91820A897D93A
2852
PhotoViewer_1567336589_chenbin_004.exe
write
HKEY_CURRENT_USER\Software\PhotoViewer\Install
p_c
FBFD44AC0B9D7B134992B6B13F230C77
2852
PhotoViewer_1567336589_chenbin_004.exe
write
HKEY_CURRENT_USER\Software\PhotoViewer\Install
p_m
1962D7
2852
PhotoViewer_1567336589_chenbin_004.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PhotoViewer
UninstallString
C:\Users\admin\AppData\Roaming\PhotoViewer\Uninst.exe
2852
PhotoViewer_1567336589_chenbin_004.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PhotoViewer
DisplayName
ABC¿´Í¼
2852
PhotoViewer_1567336589_chenbin_004.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PhotoViewer
DisplayVersion
1.4.0.6
2852
PhotoViewer_1567336589_chenbin_004.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PhotoViewer
DisplayIcon
C:\Users\admin\AppData\Roaming\PhotoViewer\Uninst.exe
2852
PhotoViewer_1567336589_chenbin_004.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PhotoViewer
Publisher
ABC¿´Í¼
2852
PhotoViewer_1567336589_chenbin_004.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PhotoViewer
InstallDate
35DEE35B00000000
2852
PhotoViewer_1567336589_chenbin_004.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PhotoViewer
LastUpdateDate
35DEE35B00000000
2852
PhotoViewer_1567336589_chenbin_004.exe
write
HKEY_CURRENT_USER\Software\PhotoViewer\Report\offline\Install.Install
code
0A2489B3807BD1314E714171AF16E51BB90BC3BEC3B5864A88455B5EA2EFC775D5
2852
PhotoViewer_1567336589_chenbin_004.exe
write
HKEY_CURRENT_USER\Software\PhotoViewer\Report\offline\Install.Install
path
5991DF6460B0A5D25AA3D5EB20CE1B1425A31AAE151BCF
836
svchost.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EC23C978-BACA-401C-8912-D2CFC387C91C}
Path
\PV_UPDATE
836
svchost.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EC23C978-BACA-401C-8912-D2CFC387C91C}
Hash
39034DA487797F39E0A8542F37E7F3D5699FB0D5AC512A5B5C38DD5B036AD6F2
836
svchost.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PV_UPDATE
Id
{EC23C978-BACA-401C-8912-D2CFC387C91C}
836
svchost.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PV_UPDATE
Index
2
836
svchost.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EC23C978-BACA-401C-8912-D2CFC387C91C}
Triggers
1500000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF782141014848484833951A74484848480048484848484848004848484848484801000000484848481C000000484848480105000000000005150000007C3E9B4DF44C73593E88FD13E8030000484848481200000048484848500043005C00610064006D0069006E000000484848484848380000004848484858020000100E000080F40300FFFFFFFF07000000000000000000000000000000000000000000000000000000681D9A000000000000000000AAAA000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFF1E000000FFFFFFFF100E0000000000000000000000E216010100200020003C002F005300650074000148484848484848
836
svchost.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EC23C978-BACA-401C-8912-D2CFC387C91C}
DynamicInfo
0300000044BB153B3077D40100000000000000000000000000000000
2348
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ .PhotoviewerShellExt
{EF30B71A-4E28-40B6-88F4-789E9629838E}
2348
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
{EF30B71A-4E28-40B6-88F4-789E9629838E}
Photoviewer Shell externsion
2348
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF30B71A-4E28-40B6-88F4-789E9629838E}
SimpleShlExt Class
2348
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF30B71A-4E28-40B6-88F4-789E9629838E}\InprocServer32
C:\Users\admin\AppData\Roaming\PhotoViewer\ShellExt.dll
2348
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF30B71A-4E28-40B6-88F4-789E9629838E}\InprocServer32
ThreadingModel
Apartment
2348
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF30B71A-4E28-40B6-88F4-789E9629838E}\TypeLib
{3DB1402D-D75E-4FF5-9A79-A92159BA32DE}
2348
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF30B71A-4E28-40B6-88F4-789E9629838E}\Version
1.0
2348
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\ABCPhotoview
{EF30B71A-4E28-40B6-88F4-789E9629838E}
3048
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PhotoviewerChecker
Description
ABC看图更新检测服务
3048
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PhotoviewerChecker\Parameters
ServiceDll
C:\Users\admin\AppData\Roaming\PhotoViewer\Checker.dll
3048
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost
PhotoviewerChecker
PhotoviewerChecker
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.bmp
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.bmp\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.bmp\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.bmp
PhotoViewer.bmp
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.bmp\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",2
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.bmp
PreviousRegistration
Paint.Picture
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.dib
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.dib\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.dib\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.dib
PhotoViewer.dib
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.dib\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.dib
PreviousRegistration
Paint.Picture
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.cut
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.cut\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.cut\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.cut
PhotoViewer.cut
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.cut\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.dds
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.dds\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.dds\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.dds
PhotoViewer.dds
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.dds\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.exr
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.exr\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.exr\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.exr
PhotoViewer.exr
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.exr\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.g3
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.g3\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.g3\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.g3
PhotoViewer.g3
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.g3\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.gif
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.gif\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.gif\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.gif
PhotoViewer.gif
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.gif\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",3
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.gif
PreviousRegistration
giffile
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.hdr
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.hdr\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.hdr\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.hdr
PhotoViewer.hdr
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.hdr\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.ico
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.ico\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.ico\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.ico
PhotoViewer.ico
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.ico\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",4
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.ico
PreviousRegistration
icofile
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.cur
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.cur\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.cur\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.cur
PhotoViewer.cur
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.cur\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.cur
PreviousRegistration
curfile
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pgx
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pgx\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pgx\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.pgx
PhotoViewer.pgx
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pgx\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.j2k
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.j2k\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.j2k\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.j2k
PhotoViewer.j2k
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.j2k\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.jp2
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.jp2\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.jp2\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.jp2
PhotoViewer.jp2
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.jp2\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.j2c
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.j2c\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.j2c\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.j2c
PhotoViewer.j2c
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.j2c\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.jpc
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.jpc\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.jpc\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.jpc
PhotoViewer.jpc
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.jpc\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.jpg
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.jpg\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.jpg\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.jpg
PhotoViewer.jpg
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.jpg\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",5
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.jpg
PreviousRegistration
jpegfile
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.jpeg
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.jpeg\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.jpeg\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.jpeg
PhotoViewer.jpeg
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.jpeg\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.jpeg
PreviousRegistration
jpegfile
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.jpe
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.jpe\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.jpe\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.jpe
PhotoViewer.jpe
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.jpe\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.jpe
PreviousRegistration
jpegfile
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.jfif
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.jfif\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.jfif\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.jfif
PhotoViewer.jfif
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.jfif\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.jfif
PreviousRegistration
pjpegfile
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.koa
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.koa\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.koa\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.koa
PhotoViewer.koa
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.koa\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.iff
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.iff\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.iff\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.iff
PhotoViewer.iff
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.iff\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.lbm
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.lbm\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.lbm\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.lbm
PhotoViewer.lbm
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.lbm\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.mng
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.mng\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.mng\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.mng
PhotoViewer.mng
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.mng\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.jng
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.jng\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.jng\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.jng
PhotoViewer.jng
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.jng\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pcd
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pcd\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pcd\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.pcd
PhotoViewer.pcd
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pcd\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pcx
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pcx\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pcx\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.pcx
PhotoViewer.pcx
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pcx\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pfm
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pfm\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pfm\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.pfm
PhotoViewer.pfm
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pfm\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pfm
PreviousRegistration
pfmfile
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pct
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pct\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pct\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.pct
PhotoViewer.pct
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pct\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pict
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pict\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pict\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.pict
PhotoViewer.pict
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pict\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pic
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pic\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pic\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.pic
PhotoViewer.pic
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pic\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.png
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.png\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.png\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.png
PhotoViewer.png
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.png\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",6
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.png
PreviousRegistration
pngfile
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pnm
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pnm\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pnm\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.pnm
PhotoViewer.pnm
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pnm\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pgm
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pgm\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pgm\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.pgm
PhotoViewer.pgm
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pgm\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.ppm
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.ppm\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.ppm\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.ppm
PhotoViewer.ppm
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.ppm\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pbm
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pbm\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pbm\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.pbm
PhotoViewer.pbm
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pbm\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.ras
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.ras\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.ras\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.ras
PhotoViewer.ras
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.ras\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.nef
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.nef\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.nef\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.nef
PhotoViewer.nef
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.nef\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.crw
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.crw\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.crw\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.crw
PhotoViewer.crw
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.crw\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.cr2
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.cr2\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.cr2\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.cr2
PhotoViewer.cr2
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.cr2\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.mrw
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.mrw\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.mrw\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.mrw
PhotoViewer.mrw
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.mrw\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.raf
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.raf\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.raf\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.raf
PhotoViewer.raf
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.raf\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.3fr
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.3fr\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.3fr\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.3fr
PhotoViewer.3fr
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.3fr\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.dcr
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.dcr\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.dcr\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.dcr
PhotoViewer.dcr
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.dcr\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.raw
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.raw\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.raw\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.raw
PhotoViewer.raw
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.raw\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",8
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.dng
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.dng\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.dng\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.dng
PhotoViewer.dng
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.dng\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pef
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pef\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pef\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.pef
PhotoViewer.pef
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pef\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.arw
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.arw\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.arw\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.arw
PhotoViewer.arw
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.arw\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.sr2
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.sr2\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.sr2\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.sr2
PhotoViewer.sr2
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.sr2\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.mef
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.mef\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.mef\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.mef
PhotoViewer.mef
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.mef\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.orf
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.orf\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.orf\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.orf
PhotoViewer.orf
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.orf\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.x3f
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.x3f\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.x3f\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.x3f
PhotoViewer.x3f
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.x3f\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.sgi
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.sgi\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.sgi\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.sgi
PhotoViewer.sgi
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.sgi\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.ska
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.ska\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.ska\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.ska
PhotoViewer.ska
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.ska\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.tbi
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.tbi\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.tbi\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.tbi
PhotoViewer.tbi
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.tbi\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.tga
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.tga\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.tga\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.tga
PhotoViewer.tga
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.tga\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.targa
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.targa\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.targa\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.targa
PhotoViewer.targa
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.targa\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.tiff
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.tiff\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.tiff\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.tiff
PhotoViewer.tiff
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.tiff\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",9
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.tiff
PreviousRegistration
TIFImage.Document
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.tif
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.tif\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.tif\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.tif
PhotoViewer.tif
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.tif\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.tif
PreviousRegistration
TIFImage.Document
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.wbm
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.wbm\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.wbm\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.wbm
PhotoViewer.wbm
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.wbm\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.wbmp
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.wbmp\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.wbmp\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.wbmp
PhotoViewer.wbmp
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.wbmp\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.wap
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.wap\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.wap\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.wap
PhotoViewer.wap
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.wap\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.wdp
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.wdp\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.wdp\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.wdp
PhotoViewer.wdp
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.wdp\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.wdp
PreviousRegistration
wdpfile
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.webp
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.webp\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.webp\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.webp
PhotoViewer.webp
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.webp\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.wmf
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.wmf\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.wmf\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.wmf
PhotoViewer.wmf
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.wmf\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.wmf
PreviousRegistration
wmffile
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.emf
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.emf\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.emf\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.emf
PhotoViewer.emf
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.emf\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.emf
PreviousRegistration
emffile
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.xbm
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.xbm\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.xbm\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.xbm
PhotoViewer.xbm
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.xbm\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.xpm
图片格式
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.xpm\shell\open
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.xpm\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe" "%1"
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.xpm
PhotoViewer.xpm
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.xpm\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",1
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
52
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\RegisteredApplications
PhotoViewer
Software\Clients\Media\PhotoViewer\Capabilities
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities
ApplicationDescription
ABC看图是一款超好用的看图软件,秒开百兆大图,支持CMYK模式,可以打开的格式多达69种。
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities
ApplicationIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe",0
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities
ApplicationName
ABC看图
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\UserChoice
Progid
PhotoViewer.bmp
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
53
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dib\UserChoice
Progid
PhotoViewer.dib
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
54
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cut\UserChoice
Progid
PhotoViewer.cut
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
55
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dds\UserChoice
Progid
PhotoViewer.dds
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
56
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exr\UserChoice
Progid
PhotoViewer.exr
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
57
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.g3\UserChoice
Progid
PhotoViewer.g3
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
58
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif\UserChoice
Progid
PhotoViewer.gif
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
59
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hdr\UserChoice
Progid
PhotoViewer.hdr
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
60
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ico\UserChoice
Progid
PhotoViewer.ico
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
61
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cur\UserChoice
Progid
PhotoViewer.cur
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
62
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pgx\UserChoice
Progid
PhotoViewer.pgx
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
63
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2k\UserChoice
Progid
PhotoViewer.j2k
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
64
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jp2\UserChoice
Progid
PhotoViewer.jp2
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
65
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2c\UserChoice
Progid
PhotoViewer.j2c
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
66
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpc\UserChoice
Progid
PhotoViewer.jpc
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
67
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\UserChoice
Progid
PhotoViewer.jpg
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
68
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpeg\UserChoice
Progid
PhotoViewer.jpeg
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
69
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpe\UserChoice
Progid
PhotoViewer.jpe
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
70
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jfif\UserChoice
Progid
PhotoViewer.jfif
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
71
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.koa\UserChoice
Progid
PhotoViewer.koa
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
72
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iff\UserChoice
Progid
PhotoViewer.iff
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
73
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lbm\UserChoice
Progid
PhotoViewer.lbm
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
74
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mng\UserChoice
Progid
PhotoViewer.mng
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
75
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jng\UserChoice
Progid
PhotoViewer.jng
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
76
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcd\UserChoice
Progid
PhotoViewer.pcd
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
77
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcx\UserChoice
Progid
PhotoViewer.pcx
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
78
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pfm\UserChoice
Progid
PhotoViewer.pfm
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
79
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pct\UserChoice
Progid
PhotoViewer.pct
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
80
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pict\UserChoice
Progid
PhotoViewer.pict
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
81
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pic\UserChoice
Progid
PhotoViewer.pic
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
82
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\UserChoice
Progid
PhotoViewer.png
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
83
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pnm\UserChoice
Progid
PhotoViewer.pnm
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
84
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pgm\UserChoice
Progid
PhotoViewer.pgm
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
85
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppm\UserChoice
Progid
PhotoViewer.ppm
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
86
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbm\UserChoice
Progid
PhotoViewer.pbm
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
87
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ras\UserChoice
Progid
PhotoViewer.ras
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
88
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nef\UserChoice
Progid
PhotoViewer.nef
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
89
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.crw\UserChoice
Progid
PhotoViewer.crw
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
90
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cr2\UserChoice
Progid
PhotoViewer.cr2
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
91
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mrw\UserChoice
Progid
PhotoViewer.mrw
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
92
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raf\UserChoice
Progid
PhotoViewer.raf
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
93
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3fr\UserChoice
Progid
PhotoViewer.3fr
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
94
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcr\UserChoice
Progid
PhotoViewer.dcr
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
95
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raw\UserChoice
Progid
PhotoViewer.raw
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
96
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dng\UserChoice
Progid
PhotoViewer.dng
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
97
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pef\UserChoice
Progid
PhotoViewer.pef
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
98
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.arw\UserChoice
Progid
PhotoViewer.arw
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
99
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sr2\UserChoice
Progid
PhotoViewer.sr2
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
100
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mef\UserChoice
Progid
PhotoViewer.mef
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
101
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.orf\UserChoice
Progid
PhotoViewer.orf
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
102
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.x3f\UserChoice
Progid
PhotoViewer.x3f
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
103
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sgi\UserChoice
Progid
PhotoViewer.sgi
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
104
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ska\UserChoice
Progid
PhotoViewer.ska
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
105
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tbi\UserChoice
Progid
PhotoViewer.tbi
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
106
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tga\UserChoice
Progid
PhotoViewer.tga
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
107
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.targa\UserChoice
Progid
PhotoViewer.targa
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
108
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tiff\UserChoice
Progid
PhotoViewer.tiff
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
109
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tif\UserChoice
Progid
PhotoViewer.tif
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
110
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbm\UserChoice
Progid
PhotoViewer.wbm
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
111
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbmp\UserChoice
Progid
PhotoViewer.wbmp
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
112
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wap\UserChoice
Progid
PhotoViewer.wap
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
113
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wdp\UserChoice
Progid
PhotoViewer.wdp
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
114
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.webp\UserChoice
Progid
PhotoViewer.webp
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
115
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmf\UserChoice
Progid
PhotoViewer.wmf
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
116
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.emf\UserChoice
Progid
PhotoViewer.emf
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
117
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xbm\UserChoice
Progid
PhotoViewer.xbm
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
118
2392
PhotoViewer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xpm\UserChoice
Progid
PhotoViewer.xpm
2392
PhotoViewer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
119
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pdf
PDF(便携式文档)格式
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pdf\shell\open
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pdf\shell\open\command
"C:\Users\admin\AppData\Roaming\PhotoViewer\PdfReader.exe" "%1"
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities\FileAssociations
.pdf
PhotoViewer.pdf
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pdf\DefaultIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PdfReader.exe",1
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PhotoViewer.pdf
PreviousRegistration
AcroExch.Document.DC
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pdf\UserChoice
Progid
PhotoViewer.pdf
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
120
3276
PdfReader.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pdf\UserChoice
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
121
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\RegisteredApplications
PhotoViewer
Software\Clients\Media\PhotoViewer\Capabilities
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities
ApplicationDescription
ABC看图是一款超好用的看图软件,秒开百兆大图,支持CMYK模式,可以打开的格式多达69种。
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities
ApplicationIcon
"C:\Users\admin\AppData\Roaming\PhotoViewer\PdfReader.exe",0
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Media\PhotoViewer\Capabilities
ApplicationName
ABC看图
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\UserChoice
Progid
PhotoViewer.bmp
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
122
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dib\UserChoice
Progid
PhotoViewer.dib
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
123
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cut\UserChoice
Progid
PhotoViewer.cut
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
124
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dds\UserChoice
Progid
PhotoViewer.dds
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
125
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exr\UserChoice
Progid
PhotoViewer.exr
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
126
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.g3\UserChoice
Progid
PhotoViewer.g3
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
127
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif\UserChoice
Progid
PhotoViewer.gif
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
128
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.hdr\UserChoice
Progid
PhotoViewer.hdr
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
129
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ico\UserChoice
Progid
PhotoViewer.ico
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
130
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cur\UserChoice
Progid
PhotoViewer.cur
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
131
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pgx\UserChoice
Progid
PhotoViewer.pgx
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
132
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2k\UserChoice
Progid
PhotoViewer.j2k
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
133
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jp2\UserChoice
Progid
PhotoViewer.jp2
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
134
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.j2c\UserChoice
Progid
PhotoViewer.j2c
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
135
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpc\UserChoice
Progid
PhotoViewer.jpc
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
136
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\UserChoice
Progid
PhotoViewer.jpg
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
137
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpeg\UserChoice
Progid
PhotoViewer.jpeg
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
138
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpe\UserChoice
Progid
PhotoViewer.jpe
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
139
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jfif\UserChoice
Progid
PhotoViewer.jfif
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
140
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.koa\UserChoice
Progid
PhotoViewer.koa
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
141
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.iff\UserChoice
Progid
PhotoViewer.iff
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
142
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.lbm\UserChoice
Progid
PhotoViewer.lbm
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
143
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mng\UserChoice
Progid
PhotoViewer.mng
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
144
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jng\UserChoice
Progid
PhotoViewer.jng
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
145
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcd\UserChoice
Progid
PhotoViewer.pcd
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
146
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pcx\UserChoice
Progid
PhotoViewer.pcx
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
147
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pfm\UserChoice
Progid
PhotoViewer.pfm
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
148
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pct\UserChoice
Progid
PhotoViewer.pct
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
149
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pict\UserChoice
Progid
PhotoViewer.pict
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
150
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pic\UserChoice
Progid
PhotoViewer.pic
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
151
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\UserChoice
Progid
PhotoViewer.png
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
152
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pnm\UserChoice
Progid
PhotoViewer.pnm
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
153
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pgm\UserChoice
Progid
PhotoViewer.pgm
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
154
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ppm\UserChoice
Progid
PhotoViewer.ppm
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
155
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pbm\UserChoice
Progid
PhotoViewer.pbm
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
156
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ras\UserChoice
Progid
PhotoViewer.ras
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
157
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nef\UserChoice
Progid
PhotoViewer.nef
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
158
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.crw\UserChoice
Progid
PhotoViewer.crw
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
159
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cr2\UserChoice
Progid
PhotoViewer.cr2
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
160
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mrw\UserChoice
Progid
PhotoViewer.mrw
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
161
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raf\UserChoice
Progid
PhotoViewer.raf
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
162
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3fr\UserChoice
Progid
PhotoViewer.3fr
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
163
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcr\UserChoice
Progid
PhotoViewer.dcr
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
164
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raw\UserChoice
Progid
PhotoViewer.raw
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
165
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dng\UserChoice
Progid
PhotoViewer.dng
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
166
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pef\UserChoice
Progid
PhotoViewer.pef
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
167
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.arw\UserChoice
Progid
PhotoViewer.arw
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
168
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sr2\UserChoice
Progid
PhotoViewer.sr2
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
169
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mef\UserChoice
Progid
PhotoViewer.mef
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
170
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.orf\UserChoice
Progid
PhotoViewer.orf
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
171
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.x3f\UserChoice
Progid
PhotoViewer.x3f
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
172
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sgi\UserChoice
Progid
PhotoViewer.sgi
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
173
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ska\UserChoice
Progid
PhotoViewer.ska
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
174
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tbi\UserChoice
Progid
PhotoViewer.tbi
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
175
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tga\UserChoice
Progid
PhotoViewer.tga
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
176
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.targa\UserChoice
Progid
PhotoViewer.targa
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
177
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tiff\UserChoice
Progid
PhotoViewer.tiff
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
178
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tif\UserChoice
Progid
PhotoViewer.tif
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
179
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbm\UserChoice
Progid
PhotoViewer.wbm
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
180
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wbmp\UserChoice
Progid
PhotoViewer.wbmp
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
181
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wap\UserChoice
Progid
PhotoViewer.wap
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
182
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wdp\UserChoice
Progid
PhotoViewer.wdp
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
183
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.webp\UserChoice
Progid
PhotoViewer.webp
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
184
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmf\UserChoice
Progid
PhotoViewer.wmf
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
185
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.emf\UserChoice
Progid
PhotoViewer.emf
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
186
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xbm\UserChoice
Progid
PhotoViewer.xbm
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
187
3276
PdfReader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xpm\UserChoice
Progid
PhotoViewer.xpm
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
188
3276
PdfReader.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
189
3240
Report.exe
write
HKEY_CURRENT_USER\Software\PhotoViewer\Install
c_d
73E444ABC9E6FD68722AE336B2C5C6CA12D8473F3CE9BD1F96A24D87C2121A74A0C91820A897D93A
3240
Report.exe
write
HKEY_CURRENT_USER\Software\PhotoViewer\Install
c_u
FBFD44AC0B9D7B134992B6B13F230C77
3240
Report.exe
write
HKEY_CURRENT_USER\Software\PhotoViewer\Install
c_m
4672B4901CE861C3E7DD7DE07F02D051A5

Files activity

Executable files
21
Suspicious files
0
Text files
1
Unknown types
10

Dropped files

PID
Process
Filename
Type
2852
PhotoViewer_1567336589_chenbin_004.exe
C:\Users\admin\AppData\Roaming\PhotoViewer\ShellExt64.dll
executable
MD5: a9e31de9ac85cd479621a7b01d8130c7
SHA256: 9dce1ea0737b7700a7229ecb49964319c4e0f1effdee5cdc0898d3d2dd383818
2852
PhotoViewer_1567336589_chenbin_004.exe
C:\Users\admin\AppData\Roaming\PhotoViewer\UpdateCheck.exe
executable
MD5: affbb9ee8a2b4934517aad1451ca62f8
SHA256: c1c1c5b69a6460d648fc8d2bef60fb7b9db4ed81a5bc44a970c471971e74ae5c
2852
PhotoViewer_1567336589_chenbin_004.exe
C:\Users\admin\AppData\Roaming\PhotoViewer\Checker.dll
executable
MD5: 7de7c2c223af22cf305c06b11cb94432
SHA256: 2926ebc0d9b1948fff2abeaae0fc4ff6a92a2cd57a48c12907fd09a6a47963a3
2852
PhotoViewer_1567336589_chenbin_004.exe
C:\Users\admin\AppData\Roaming\PhotoViewer\Uninst.exe
executable
MD5: 1d71b3b59c88ccf19fcea9214d4866d3
SHA256: 653a7b08cd449407f970bdd8255f0b5af49128d9ab95e664f9a616006cee1871
2852
PhotoViewer_1567336589_chenbin_004.exe
C:\Users\admin\AppData\Roaming\PhotoViewer\soui-sys-resource.dll
executable
MD5: e37660a67ea0cfd9349da2fa0c9a78b9
SHA256: f133b035a87c49bfcc0844a00c949daab8ccd13a44272877baa60ec6b61c8d4b
2852
PhotoViewer_1567336589_chenbin_004.exe
C:\Users\admin\AppData\Roaming\PhotoViewer\Update.exe
executable
MD5: 2dee0ee5c0a7ff338d9e2f086ff2bfe9
SHA256: 824a2a84bc4755c3db90f718fdb1d2db90b2cb64dfc1fe35f4466dd5315d6568
2852
PhotoViewer_1567336589_chenbin_004.exe
C:\Users\admin\AppData\Roaming\PhotoViewer\translator.dll
executable
MD5: 088a161c78f3b61b165b09b437cabae7
SHA256: d37d32022a833b218cbf85b1ec1ff7cdc9a27a264d05b5057d2dd3c9d30cdcb3
2852
PhotoViewer_1567336589_chenbin_004.exe
C:\Users\admin\AppData\Roaming\PhotoViewer\Report.exe
executable
MD5: 0a90936a39cd85d0c1802fbab21ac636
SHA256: 4d078e3b3e17d6c775274862c92d29dccdf5757593f2877dd9e9018e5edca0d5
2852
PhotoViewer_1567336589_chenbin_004.exe
C:\Users\admin\AppData\Roaming\PhotoViewer\sqlite3.dll
executable
MD5: 7e32a0a6055959ef06328d8b348307e8
SHA256: a60c776c40e9e9a3a30c3ccac433a7d915b15af32ad273224fc4f5c7613c7dbe
2852
PhotoViewer_1567336589_chenbin_004.exe
C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoManager.exe
executable
MD5: 7f31c4247aac6d5ef7a57ad85639818c
SHA256: 2730651ffbb9d04f25d6794be54b58c196aaf5f43cb26c66b066238c8bd30396
2852
PhotoViewer_1567336589_chenbin_004.exe
C:\Users\admin\AppData\Roaming\PhotoViewer\utilities.dll
executable
MD5: 96469baffff00cc8ab95ae3eb681e09a
SHA256: 7e1b7ac33c91b1ed35d76b564f38f6be9543c20c7b14a38c0483b5a956f83d15
2852
PhotoViewer_1567336589_chenbin_004.exe
C:\Users\admin\AppData\Roaming\PhotoViewer\FreeImage.dll
executable
MD5: 186dd7c87e621960298719fb6f867c17
SHA256: 28901bc0efe8a3ddb15ae6756127e3b5b1af18b4d919f064d4da2a63b3d0f95d
2852
PhotoViewer_1567336589_chenbin_004.exe
C:\Users\admin\AppData\Roaming\PhotoViewer\PdfReader.exe
executable
MD5: c14884cea81cc1b9982e70d1258c2f81
SHA256: 616ee40b0fa843442afb44d9ee62c9cd186003c3fc504a2aeb940c21dd82b715
2852
PhotoViewer_1567336589_chenbin_004.exe
C:\Users\admin\AppData\Roaming\PhotoViewer\ShellExt.dll
executable
MD5: a5fa380c2edc87d16144162556e78f11
SHA256: 117c89423657fe95c13dcb110fe3d4c09355ac9e7e1d6f39e1fa136492074e21
2852
PhotoViewer_1567336589_chenbin_004.exe
C:\Users\admin\AppData\Roaming\PhotoViewer\render-gdi.dll
executable
MD5: bffa7a4cbb54202db1516add31fcdf0c
SHA256: 84bbf80b39739308e8cb7f6806e082dec0492cb27542bd669d3ab68ad67f2514
2852
PhotoViewer_1567336589_chenbin_004.exe
C:\Users\admin\AppData\Roaming\PhotoViewer\imgdecoder-gdip.dll
executable
MD5: e7792d2b17939d6d80a5794eba388412
SHA256: 7566429f97d19e0710f9e4fd273b22c39867a9d812c9dc3e8e193aa314090f55
2852
PhotoViewer_1567336589_chenbin_004.exe
C:\Users\admin\AppData\Roaming\PhotoViewer\CaptureScreen.exe
executable
MD5: 752f14202faa332ba41915883440e0ec
SHA256: 76aa62bda4f44d283f745a8cc28a42fb4cff736d2b0e4dcd5c4e3a4394b44152
2852
PhotoViewer_1567336589_chenbin_004.exe
C:\Users\admin\AppData\Roaming\PhotoViewer\pdfium.dll
executable
MD5: 34dd4f28f701cb4dadddaa695d55df34
SHA256: 5ae8ebbfffcf975caa73f3be633d78f8d6880c64e3b5c3ddb10c5677cfa402ee
2852
PhotoViewer_1567336589_chenbin_004.exe
C:\Users\admin\AppData\Roaming\PhotoViewer\FreeImage64.dll
executable
MD5: 62b0705f0183751e7a513fd28170e9d7
SHA256: 690b65122cb94b960fcd3d3d8d921adc4394d627c15da650f256ca41e552d50a
2852
PhotoViewer_1567336589_chenbin_004.exe
C:\Users\admin\AppData\Roaming\PhotoViewer\PhotoViewer.exe
executable
MD5: f8a29b35878e683ce6fdb2f35a26b0ac
SHA256: 6cf0766c589a6dadbb2fe2ac1cfcf6a98ca7b8281946ae6746bdc137c79a15b2
2852
PhotoViewer_1567336589_chenbin_004.exe
C:\Users\admin\AppData\Roaming\PhotoViewer\soui.dll
executable
MD5: a5bedb05ef32126708ebe84d09079687
SHA256: 3b04365252ca5320f9eac1168a7cedb20bd93bfa185ff8b2080f960e625fdfe0
836
svchost.exe
C:\Windows\appcompat\programs\RecentFileCache.bcf
txt
MD5: e4321361b6f82f6b375cc49c7a6d6f75
SHA256: 12380d81eb5ed497e7fe12a84165df073f52f1fb73220b607330d7ed4a8b2631
2852
PhotoViewer_1567336589_chenbin_004.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\ABC看图\启动ABC看图.lnk
lnk
MD5: 0ac92cc42acb14763f0ff28de2509318
SHA256: b8ef95444a161d629cd14c06b8a562b91009a05c67d0fffd306ef72a1e03b687
2852
PhotoViewer_1567336589_chenbin_004.exe
C:\Users\admin\Desktop\ABC看图.lnk
lnk
MD5: 686ba06e1ae9617bfe473fe908993721
SHA256: f5aca74e00f697429600c6fa2612f8871ae13c885770baa080a90304feb59e22
3260
PhotoViewer.exe
C:\Users\admin\Documents\ABCPhoto\PhotoViewer\cache.db-journal
––
MD5:  ––
SHA256:  ––
836
svchost.exe
C:\Windows\appcompat\programs\RecentFileCache.bcf
txt
MD5: acd239c4dee01d3f9fcf38e64767a661
SHA256: ea2647598d59721dfbffb6b92c4fc5f4c636a4f7688e7b9b8b646144105a61ba
2392
PhotoViewer.exe
C:\Users\admin\Documents\ABCPhoto\PhotoViewer\cache.db
sqlite
MD5: 69ffe3f95cb96a52e712953ae03a337b
SHA256: 7d053125c6402dc73aedb938b225058a376891809b0fb8e9c0295c810a726600
2392
PhotoViewer.exe
C:\Users\admin\Documents\ABCPhoto\PhotoViewer\cache.db-journal
––
MD5:  ––
SHA256:  ––
2852
PhotoViewer_1567336589_chenbin_004.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\ABC看图\卸载ABC看图.lnk
lnk
MD5: 9fa08c99281734b6259edfb323da0841
SHA256: b261569ae548c020a517a43642d516af62c7bcf8aa781a7b05e0c986e2a6b37b
836
svchost.exe
C:\Windows\System32\Tasks\PV_UPDATE
––
MD5:  ––
SHA256:  ––
836
svchost.exe
C:\Windows\appcompat\programs\RecentFileCache.bcf
txt
MD5: 0796bccc32868f1bf844a2beca36ff70
SHA256: b10ac101b536a98dae7cf0a9de897d20e25277963c94d684bfcf6356c3cff761
2852
PhotoViewer_1567336589_chenbin_004.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\ABC看图\启动PDF阅读.lnk
lnk
MD5: c813107a0418be5a5494b6a1cfe4fd45
SHA256: 20cb05f9b28058bdc5710736099bf31d9420d67ac7d90d97c0bf24d24e9b1700
2852
PhotoViewer_1567336589_chenbin_004.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\ABC看图\启动图集管理.lnk
lnk
MD5: 4c5183db90551290584501e882c05ddc
SHA256: f808458102c211b394743a4d5d8cfb77e812227c40a2162b4e4d68ba5e59b735
2852
PhotoViewer_1567336589_chenbin_004.exe
C:\Users\admin\AppData\Local\Temp\ABCPhotoView.7z
––
MD5:  ––
SHA256:  ––
2852
PhotoViewer_1567336589_chenbin_004.exe
C:\Users\admin\AppData\Local\Temp\CheckABCPhotoView.7z.md5
text
MD5: 0d1044734ab2ece1ef358078f22bcb4f
SHA256: f5c6bcd4dd597bae2a7fca045b733a89587d5d3b8376ea9904b1cd75d873a993
836
svchost.exe
C:\Windows\appcompat\programs\RecentFileCache.bcf
txt
MD5: 9a24b65fcbc1386b75bef6d800f00467
SHA256: ca84d551051c7feeeb2e618c1ed21ef3a5511c3f4937eb969629f58aeadf58e6

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
3
TCP/UDP connections
3
DNS requests
3
Threats
0

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
3240 Report.exe GET –– 117.50.8.146:80 http://kantu.shzhanmeng.com/2.gif?proj=kantu&food=D5CmfUa6EOoz/uWnaEtDZXgwy658l4b/w/zm2qlL2w9iFbjGTa205QLCT+2L5NHuQcW2ISZX5QI/fCSxuKnH8YkfLJhyb7/8KWBXghSrdscUaoND97CcdjOpxuJrRnCaWP3lZz6bi7NeqMhJtbZUipLbozzBQcILbZtlJwsL/3zQBeUk3TDS/P2SMYaghrImTFrj9DyOh1Pu3Uh7eAm6IJVQxk1k CN
––
––
malicious
3260 PhotoViewer.exe GET –– 119.167.216.173:80 http://ktnews.7654.com/ CN
––
––
malicious
3260 PhotoViewer.exe GET –– 113.215.232.5:80 http://down2.abckantu.com/n/kantu/parameter.xml CN
––
––
malicious

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
3240 Report.exe 117.50.8.146:80 China Unicom Beijing Province Network CN unknown
3260 PhotoViewer.exe 119.167.216.173:80 CHINA UNICOM China169 Backbone CN unknown
–– –– 113.215.232.5:80 Huashu media&Network Limited CN suspicious

DNS requests

Domain IP Reputation
kantu.shzhanmeng.com 117.50.8.146
malicious
ktnews.7654.com 119.167.216.173
221.204.60.123
113.200.16.31
27.221.54.19
221.204.58.110
121.29.54.65
113.200.16.30
221.204.60.63
113.200.16.27
211.91.160.204
139.215.203.208
113.200.16.32
112.132.32.105
218.11.8.104
139.215.203.199
malicious
down2.abckantu.com 113.215.232.5
113.215.232.8
113.215.232.9
113.215.232.10
113.215.232.11
113.215.232.7
113.215.232.6
malicious

Threats

No threats detected.

Debug output strings

No debug info.