General Info

File name

bbfbex5.exe

Full analysis
https://app.any.run/tasks/6a6b3d3e-6cb1-4a4f-9030-7f43d7692a7f
Verdict
Malicious activity
Analysis date
8/13/2019, 16:25:56
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

ed7722aa48e43e5635e76b8e172b7412

SHA1

8362b9b2bce0bbb24492ab8cddd767436438c05b

SHA256

950b9e0df279ef8207e036a23148295b0fe72365a07a9c88b31c5c9552060e13

SSDEEP

393216:l78lTxGKwU4uSVTd2Qxpd6o0PJb7GWrWhFW0SHDhrtt70VQYR6xqoKbRrPH7/2MB:lYrwjuMTdlxpd2BT6h7+Dh5J0KVTKtjP

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
120 seconds
Additional time used
60 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (75.0.3770.100)
  • Google Update Helper (1.3.34.7)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.7.2 (4.7.03062)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (14.21.27702.2)
  • Microsoft Visual C++ 2019 X86 Additional Runtime - 14.21.27702 (14.21.27702)
  • Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.21.27702 (14.21.27702)
  • Mozilla Firefox 68.0.1 (x86 en-US) (68.0.1)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • Update for Microsoft .NET Framework 4.7.2 (KB4087364) (1)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB4019990
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads dropped or rewritten executable
  • explorer.exe (PID: 128)
  • bbfbex5.exe (PID: 4004)
  • DefConfig.exe (PID: 724)
  • FTSUploadAgent.exe (PID: 1040)
  • LogSysServer.exe (PID: 2156)
  • FlashBack Recorder.exe (PID: 3184)
  • DefConfig.exe (PID: 2884)
  • DefConfig.exe (PID: 2664)
  • RunNonElevated.exe (PID: 2092)
Application was dropped or rewritten from another process
  • DefConfig.exe (PID: 724)
  • LogSysServer.exe (PID: 2156)
  • LogSysServer.exe (PID: 3272)
  • FTSUploadAgent.exe (PID: 1040)
  • RunNonElevated.exe (PID: 2092)
  • nsA4A7.tmp (PID: 2204)
  • DefConfig.exe (PID: 2664)
  • DefConfig.exe (PID: 2884)
  • ns67F9.tmp (PID: 1928)
  • ns65B6.tmp (PID: 3444)
  • ns6A3C.tmp (PID: 2716)
  • FlashBack Recorder.exe (PID: 3184)
  • RecorderChecker.exe (PID: 2292)
Changes settings of System certificates
  • FTSUploadAgent.exe (PID: 1040)
Creates files in the user directory
  • FlashBack Recorder.exe (PID: 3184)
  • DefConfig.exe (PID: 2664)
  • LogSysServer.exe (PID: 2156)
  • bbfbex5.exe (PID: 4004)
  • DefConfig.exe (PID: 2884)
  • DefConfig.exe (PID: 724)
Reads CPU info
  • LogSysServer.exe (PID: 2156)
Creates files in the program directory
  • FlashBack Recorder.exe (PID: 3184)
  • bbfbex5.exe (PID: 4004)
Modifies the open verb of a shell class
  • bbfbex5.exe (PID: 4004)
Starts application with an unusual extension
  • bbfbex5.exe (PID: 4004)
Creates a software uninstall entry
  • bbfbex5.exe (PID: 4004)
Creates COM task schedule object
  • bbfbex5.exe (PID: 4004)
Executable content was dropped or overwritten
  • bbfbex5.exe (PID: 4004)
Manual execution by user
  • FlashBack Recorder.exe (PID: 3184)
Dropped object may contain Bitcoin addresses
  • bbfbex5.exe (PID: 4004)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win64 Executable (generic) (76.4%)
.exe
|   Win32 Executable (generic) (12.4%)
.exe
|   Generic Win/DOS Executable (5.5%)
.exe
|   DOS Executable Generic (5.5%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2012:02:24 20:19:59+01:00
PEType:
PE32
LinkerVersion:
10
CodeSize:
28672
InitializedDataSize:
445952
UninitializedDataSize:
16896
EntryPoint:
0x39e3
OSVersion:
5
ImageVersion:
6
SubsystemVersion:
5
Subsystem:
Windows GUI
FileVersionNumber:
5.36.0.4417
ProductVersionNumber:
5.36.0.4417
FileFlagsMask:
0x0000
FileFlags:
(none)
FileOS:
Win32
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
Neutral
CharacterSet:
ASCII
CompanyName:
Blueberry Software (UK) Ltd.
CompanyWebsite:
http://www.bbflashback.com/
FileDescription:
null
FileVersion:
5.36.0.4417
LegalCopyright:
null
ProductName:
FlashBack Express 5
ProductVersion:
5.36.0.4417
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
24-Feb-2012 19:19:59
Detected languages
English - United States
CompanyName:
Blueberry Software (UK) Ltd.
CompanyWebsite:
http://www.bbflashback.com/
FileDescription:
null
FileVersion:
5.36.0.4417
LegalCopyright:
null
ProductName:
FlashBack Express 5
ProductVersion:
5.36.0.4417
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x000000D0
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
6
Time date stamp:
24-Feb-2012 19:19:59
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x00006F10 0x00007000 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.49788
.rdata 0x00008000 0x00002A92 0x00002C00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 4.39389
.data 0x0000B000 0x00067EBC 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 1.47278
.ndata 0x00073000 0x001CD000 0x00000000 IMAGE_SCN_CNT_UNINITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.rsrc 0x00240000 0x00008DC0 0x00008E00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 6.50454
.reloc 0x00249000 0x00000F8A 0x00001000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_DISCARDABLE,IMAGE_SCN_MEM_READ 7.85423
Resources
1

2

3

4

5

6

103

105

106

107

109

111

Imports
    KERNEL32.dll

    USER32.dll

    GDI32.dll

    SHELL32.dll

    ADVAPI32.dll

    COMCTL32.dll

    ole32.dll

    VERSION.dll

Exports

    No exports.

Screenshots

Processes

Total processes
56
Monitored processes
16
Malicious processes
5
Suspicious processes
7

Behavior graph

+
drop and start drop and start drop and start drop and start start bbfbex5.exe no specs bbfbex5.exe ns65b6.tmp no specs defconfig.exe no specs ns67f9.tmp no specs defconfig.exe no specs ns6a3c.tmp no specs defconfig.exe no specs nsa4a7.tmp no specs runnonelevated.exe no specs explorer.exe no specs flashback recorder.exe logsysserver.exe logsysserver.exe no specs ftsuploadagent.exe recorderchecker.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
128
CMD
C:\Windows\Explorer.EXE
Path
C:\Windows\explorer.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Windows Explorer
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\slc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\profapi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\iconcodecservice.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sndvolsso.dll
c:\windows\system32\hid.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\timedate.cpl
c:\windows\system32\atl.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\actxprxy.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\userenv.dll
c:\windows\system32\samlib.dll
c:\windows\system32\samcli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\msls31.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\authui.dll
c:\windows\system32\cryptui.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\gameux.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\wer.dll
c:\windows\system32\msiltcfg.dll
c:\windows\system32\version.dll
c:\windows\system32\msi.dll
c:\windows\system32\winsta.dll
c:\windows\system32\psapi.dll
c:\windows\system32\networkexplorer.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wdmaud.drv
c:\windows\system32\ksuser.dll
c:\windows\system32\avrt.dll
c:\windows\system32\audioses.dll
c:\windows\system32\msacm32.drv
c:\windows\system32\msacm32.dll
c:\windows\system32\midimap.dll
c:\windows\system32\msutb.dll
c:\windows\system32\stobject.dll
c:\windows\system32\batmeter.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\es.dll
c:\windows\system32\prnfldr.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dxp.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\syncreg.dll
c:\windows\ehome\ehsso.dll
c:\windows\system32\netshell.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\alttab.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
c:\program files\filezilla ftp client\fzshellext.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\pnidui.dll
c:\windows\system32\qutil.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\npmproxy.dll
c:\windows\system32\wlanapi.dll
c:\windows\system32\wlanutil.dll
c:\windows\system32\wwanapi.dll
c:\windows\system32\wwapi.dll
c:\windows\system32\qagent.dll
c:\windows\system32\srchadmin.dll
c:\windows\system32\sxs.dll
c:\windows\system32\bthprops.cpl
c:\windows\system32\ieframe.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\synccenter.dll
c:\windows\system32\actioncenter.dll
c:\windows\system32\imapi2.dll
c:\windows\system32\hgcpl.dll
c:\windows\system32\provsvc.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\fxsst.dll
c:\windows\system32\fxsapi.dll
c:\windows\system32\fxsresm.dll
c:\windows\system32\wscinterop.dll
c:\windows\system32\wscapi.dll
c:\windows\system32\wscui.cpl
c:\windows\system32\werconcpl.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\wercplsupport.dll
c:\windows\system32\msxml6.dll
c:\windows\system32\hcproviders.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\thumbcache.dll
c:\windows\system32\mpr.dll
c:\windows\system32\structuredquery.dll
c:\windows\system32\searchfolder.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\naturallanguage6.dll
c:\windows\system32\nlsdata0009.dll
c:\windows\system32\nlslexicons0009.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\van.dll
c:\windows\system32\rasmm.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\wwanmm.dll
c:\windows\system32\wlanmm.dll
c:\windows\system32\wlanhlp.dll
c:\windows\system32\onex.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\eappcfg.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\netprofm.dll
c:\windows\system32\rasdlg.dll
c:\windows\system32\mprapi.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\hnetcfg.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\netcfgx.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\comsvcs.dll
c:\windows\system32\shacct.dll
c:\windows\system32\msftedit.dll
c:\windows\system32\twext.dll
c:\program files\winrar\rarext.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\syncui.dll
c:\windows\system32\synceng.dll
c:\program files\notepad++\nppshell_06.dll
c:\windows\system32\acppage.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\ehstorapi.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\audiodev.dll
c:\windows\system32\wmvcore.dll
c:\windows\system32\wmasf.dll
c:\program files\common files\microsoft shared\office14\msoxev.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\program files\windows sidebar\sbdrop.dll
c:\windows\system32\winanr.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\users\admin\appdata\local\temp\bbfbex5.exe
c:\program files\blueberry software\flashback express 5\flashback recorder.exe
c:\program files\blueberry software\flashback express 5\flashback player.exe
c:\program files\blueberry software\flashback express 5\ve32.dll

PID
3356
CMD
"C:\Users\admin\AppData\Local\Temp\bbfbex5.exe"
Path
C:\Users\admin\AppData\Local\Temp\bbfbex5.exe
Indicators
No indicators
Parent process
explorer.exe
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
Blueberry Software (UK) Ltd.
Description
Version
5.36.0.4417
Modules
Image
c:\users\admin\appdata\local\temp\bbfbex5.exe
c:\systemroot\system32\ntdll.dll

PID
4004
CMD
"C:\Users\admin\AppData\Local\Temp\bbfbex5.exe"
Path
C:\Users\admin\AppData\Local\Temp\bbfbex5.exe
Indicators
Parent process
explorer.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Blueberry Software (UK) Ltd.
Description
Version
5.36.0.4417
Modules
Image
c:\users\admin\appdata\local\temp\bbfbex5.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\uxtheme.dll
c:\users\admin\appdata\local\temp\nscf8d2.tmp\advsplash.dll
c:\windows\system32\winmm.dll
c:\users\admin\appdata\local\temp\nscf8d2.tmp\userinfo.dll
c:\windows\system32\sspicli.dll
c:\users\admin\appdata\local\temp\nscf8d2.tmp\system.dll
c:\users\admin\appdata\local\temp\nscf8d2.tmp\rempendingfileop.dll
c:\windows\system32\riched20.dll
c:\users\admin\appdata\local\temp\nscf8d2.tmp\nsdialogs.dll
c:\windows\system32\comdlg32.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\users\admin\appdata\local\temp\nscf8d2.tmp\startmenu.dll
c:\users\admin\appdata\local\temp\nscf8d2.tmp\installoptions.dll
c:\users\admin\appdata\local\temp\nscf8d2.tmp\version.dll
c:\users\admin\appdata\local\temp\nscf8d2.tmp\processes.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\psapi.dll
c:\program files\blueberry software\flashback express 5\fbplayerapi.dll
c:\program files\common files\blueberry software\bandloader.dll
c:\program files\common files\blueberry software\bbfiletransfer.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\program files\common files\blueberry software\bbmemdumpflt.ax
c:\windows\system32\quartz.dll
c:\windows\system32\devenum.dll
c:\program files\common files\blueberry software\fbexploreraddon.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\program files\blueberry software\flashback express 5\flashback player.exe
c:\program files\blueberry software\flashback express 5\flashback recorder.exe
c:\program files\blueberry software\flashback express 5\flashback batch export.exe
c:\program files\blueberry software\flashback express 5\logsysserver.exe
c:\windows\hh.exe
c:\program files\blueberry software\flashback express 5\uninstall.exe
c:\program files\blueberry software\flashback express 5\flashbackinstall.dll
c:\program files\blueberry software\flashback express 5\borlndmm.dll
c:\windows\system32\winspool.drv
c:\program files\blueberry software\flashback express 5\cc32120mt.dll
c:\program files\blueberry software\flashback express 5\logsysinstaller.dll
c:\users\admin\appdata\local\temp\nscf8d2.tmp\nsexec.dll
c:\users\admin\appdata\local\temp\nscf8d2.tmp\ns65b6.tmp
c:\users\admin\appdata\local\temp\nscf8d2.tmp\ns67f9.tmp
c:\users\admin\appdata\local\temp\nscf8d2.tmp\ns6a3c.tmp
c:\users\admin\appdata\local\temp\nscf8d2.tmp\statplugindll.dll
c:\users\admin\appdata\local\temp\nscf8d2.tmp\nsa4a7.tmp
c:\windows\system32\netutils.dll

PID
3444
CMD
"C:\Users\admin\AppData\Local\Temp\nscF8D2.tmp\ns65B6.tmp" C:\Program Files\Blueberry Software\FlashBack Express 5\UploadProfiles\DefConfig.exe -add "File Copy" "C:\Program Files\Blueberry Software\FlashBack Express 5\UploadProfiles\FileCopyPublisher.dll" "FBExpress5"
Path
C:\Users\admin\AppData\Local\Temp\nscF8D2.tmp\ns65B6.tmp
Indicators
No indicators
Parent process
bbfbex5.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\nscf8d2.tmp\ns65b6.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\apphelp.dll
c:\program files\blueberry software\flashback express 5\uploadprofiles\defconfig.exe

PID
724
CMD
"C:\Program Files\Blueberry Software\FlashBack Express 5\UploadProfiles\DefConfig.exe" -add "File Copy" "C:\Program Files\Blueberry Software\FlashBack Express 5\UploadProfiles\FileCopyPublisher.dll" "FBExpress5"
Path
C:\Program Files\Blueberry Software\FlashBack Express 5\UploadProfiles\DefConfig.exe
Indicators
No indicators
Parent process
ns65B6.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\program files\blueberry software\flashback express 5\uploadprofiles\defconfig.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\profapi.dll
c:\program files\blueberry software\flashback express 5\uploadprofiles\publishconfigurator.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\oleaut32.dll
c:\program files\blueberry software\flashback express 5\uploadprofiles\filecopypublisher.dll

PID
1928
CMD
"C:\Users\admin\AppData\Local\Temp\nscF8D2.tmp\ns67F9.tmp" C:\Program Files\Blueberry Software\FlashBack Express 5\UploadProfiles\DefConfig.exe -add "FTP" "C:\Program Files\Blueberry Software\FlashBack Express 5\UploadProfiles\FtpPublisher.dll" "FBExpress5"
Path
C:\Users\admin\AppData\Local\Temp\nscF8D2.tmp\ns67F9.tmp
Indicators
No indicators
Parent process
bbfbex5.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\nscf8d2.tmp\ns67f9.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\blueberry software\flashback express 5\uploadprofiles\defconfig.exe
c:\windows\system32\apphelp.dll

PID
2884
CMD
"C:\Program Files\Blueberry Software\FlashBack Express 5\UploadProfiles\DefConfig.exe" -add "FTP" "C:\Program Files\Blueberry Software\FlashBack Express 5\UploadProfiles\FtpPublisher.dll" "FBExpress5"
Path
C:\Program Files\Blueberry Software\FlashBack Express 5\UploadProfiles\DefConfig.exe
Indicators
No indicators
Parent process
ns67F9.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\program files\blueberry software\flashback express 5\uploadprofiles\defconfig.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\profapi.dll
c:\program files\blueberry software\flashback express 5\uploadprofiles\publishconfigurator.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\oleaut32.dll
c:\program files\blueberry software\flashback express 5\uploadprofiles\ftppublisher.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll

PID
2716
CMD
"C:\Users\admin\AppData\Local\Temp\nscF8D2.tmp\ns6A3C.tmp" C:\Program Files\Blueberry Software\FlashBack Express 5\UploadProfiles\DefConfig.exe -add "YouTube" "C:\Program Files\Blueberry Software\FlashBack Express 5\UploadProfiles\YouTubePublisher.dll" "FBExpress5"
Path
C:\Users\admin\AppData\Local\Temp\nscF8D2.tmp\ns6A3C.tmp
Indicators
No indicators
Parent process
bbfbex5.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\nscf8d2.tmp\ns6a3c.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\blueberry software\flashback express 5\uploadprofiles\defconfig.exe
c:\windows\system32\apphelp.dll

PID
2664
CMD
"C:\Program Files\Blueberry Software\FlashBack Express 5\UploadProfiles\DefConfig.exe" -add "YouTube" "C:\Program Files\Blueberry Software\FlashBack Express 5\UploadProfiles\YouTubePublisher.dll" "FBExpress5"
Path
C:\Program Files\Blueberry Software\FlashBack Express 5\UploadProfiles\DefConfig.exe
Indicators
No indicators
Parent process
ns6A3C.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\program files\blueberry software\flashback express 5\uploadprofiles\defconfig.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\profapi.dll
c:\program files\blueberry software\flashback express 5\uploadprofiles\publishconfigurator.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\oleaut32.dll
c:\program files\blueberry software\flashback express 5\uploadprofiles\youtubepublisher.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\version.dll

PID
2204
CMD
"C:\Users\admin\AppData\Local\Temp\nscF8D2.tmp\nsA4A7.tmp" C:\Program Files\Blueberry Software\FlashBack Express 5\RunNonElevated.exe FlashBack Recorder.exe
Path
C:\Users\admin\AppData\Local\Temp\nscF8D2.tmp\nsA4A7.tmp
Indicators
No indicators
Parent process
bbfbex5.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\nscf8d2.tmp\nsa4a7.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\apphelp.dll
c:\program files\blueberry software\flashback express 5\runnonelevated.exe

PID
2092
CMD
"C:\Program Files\Blueberry Software\FlashBack Express 5\RunNonElevated.exe" FlashBack Recorder.exe
Path
C:\Program Files\Blueberry Software\FlashBack Express 5\RunNonElevated.exe
Indicators
No indicators
Parent process
nsA4A7.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\program files\blueberry software\flashback express 5\runnonelevated.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\program files\blueberry software\flashback express 5\ve32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
3184
CMD
"C:\Program Files\Blueberry Software\FlashBack Express 5\FlashBack Recorder.exe"
Path
C:\Program Files\Blueberry Software\FlashBack Express 5\FlashBack Recorder.exe
Indicators
Parent process
explorer.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Blueberry Consultants Ltd.
Description
FlashBack Express 5 Recorder
Version
5.36.0.4417
Modules
Image
c:\program files\blueberry software\flashback express 5\flashback recorder.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\blueberry software\flashback express 5\rtl170.bpl
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\oleacc.dll
c:\program files\blueberry software\flashback express 5\vcl170.bpl
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\winspool.drv
c:\windows\system32\oledlg.dll
c:\program files\blueberry software\flashback express 5\vclx170.bpl
c:\windows\system32\winmm.dll
c:\program files\blueberry software\flashback express 5\xecompat.bpl
c:\program files\blueberry software\flashback express 5\bcbie170.bpl
c:\program files\blueberry software\flashback express 5\borlndmm.dll
c:\program files\blueberry software\flashback express 5\cc32120mt.dll
c:\program files\blueberry software\flashback express 5\soaprtl170.bpl
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\program files\blueberry software\flashback express 5\xmlrtl170.bpl
c:\program files\blueberry software\flashback express 5\dbrtl170.bpl
c:\program files\blueberry software\flashback express 5\inet170.bpl
c:\program files\blueberry software\flashback express 5\dsnap170.bpl
c:\program files\blueberry software\flashback express 5\vclimg170.bpl
c:\program files\blueberry software\flashback express 5\vclie170.bpl
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\pdh.dll
c:\windows\system32\psapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\program files\blueberry software\flashback express 5\logsysserver.exe
c:\windows\system32\apphelp.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\winsta.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\olepro32.dll
c:\windows\system32\hhctrl.ocx
c:\windows\system32\riched20.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\msxml6.dll
c:\program files\blueberry software\flashback express 5\checkforupdate.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\system32\perfos.dll
c:\windows\system32\msimg32.dll
c:\program files\blueberry software\flashback express 5\flashbackinstall.dll
c:\program files\blueberry software\flashback express 5\lame_enc.dll
c:\program files\blueberry software\flashback express 5\twolame.dll
c:\program files\blueberry software\flashback express 5\vistacoresoundapiwrap.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\program files\blueberry software\flashback express 5\dbghelp.dll
c:\windows\system32\wdmaud.drv
c:\windows\system32\ksuser.dll
c:\windows\system32\avrt.dll
c:\windows\system32\audioses.dll
c:\windows\system32\msacm32.drv
c:\windows\system32\msacm32.dll
c:\windows\system32\midimap.dll
c:\windows\system32\mfplat.dll
c:\program files\blueberry software\flashback express 5\libavencoder.dll
c:\program files\blueberry software\flashback express 5\avcodec-52.dll
c:\program files\blueberry software\flashback express 5\avcore-0.dll
c:\program files\blueberry software\flashback express 5\avutil-50.dll
c:\program files\blueberry software\flashback express 5\libx264-128.dll
c:\program files\blueberry software\flashback express 5\swscale-0.dll
c:\program files\blueberry software\flashback express 5\avformat-52.dll
c:\program files\blueberry software\flashback express 5\sseutils.dll
c:\windows\system32\mf.dll
c:\windows\system32\atl.dll
c:\windows\system32\devenum.dll
c:\windows\system32\msdmo.dll
c:\windows\system32\avicap32.dll
c:\windows\system32\msvfw32.dll
c:\program files\blueberry software\flashback express 5\video2flv.dll
c:\program files\blueberry software\flashback express 5\fbo\ftsuploadagent.exe
c:\program files\blueberry software\flashback express 5\recorderchecker.exe
c:\program files\blueberry software\flashback express 5\bbipp.dll
c:\program files\blueberry software\flashback express 5\libiomp5md.dll

PID
2156
CMD
"C:\Program Files\Blueberry Software\FlashBack Express 5\LogSysServer.exe" -x
Path
C:\Program Files\Blueberry Software\FlashBack Express 5\LogSysServer.exe
Indicators
Parent process
FlashBack Recorder.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Blueberry Consultants
Description
LogSysServer Application
Version
1.6.1.137
Modules
Image
c:\program files\blueberry software\flashback express 5\logsysserver.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\winmm.dll
c:\windows\system32\winspool.drv
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\rasadhlp.dll
c:\program files\blueberry software\flashback express 5\xecompat.bpl
c:\program files\blueberry software\flashback express 5\flashback recorder.exe
c:\program files\blueberry software\flashback express 5\rtl170.bpl
c:\windows\system32\mpr.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\oleacc.dll
c:\program files\blueberry software\flashback express 5\vcl170.bpl
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\oledlg.dll
c:\program files\blueberry software\flashback express 5\vclx170.bpl
c:\program files\blueberry software\flashback express 5\bcbie170.bpl
c:\program files\blueberry software\flashback express 5\borlndmm.dll
c:\program files\blueberry software\flashback express 5\cc32120mt.dll
c:\program files\blueberry software\flashback express 5\soaprtl170.bpl
c:\program files\blueberry software\flashback express 5\xmlrtl170.bpl
c:\program files\blueberry software\flashback express 5\dbrtl170.bpl
c:\program files\blueberry software\flashback express 5\inet170.bpl
c:\program files\blueberry software\flashback express 5\dsnap170.bpl
c:\program files\blueberry software\flashback express 5\vclimg170.bpl
c:\program files\blueberry software\flashback express 5\vclie170.bpl
c:\windows\system32\pdh.dll
c:\windows\system32\psapi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\winsta.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\olepro32.dll
c:\program files\blueberry software\flashback express 5\checkforupdate.dll
c:\windows\system32\hhctrl.ocx
c:\windows\system32\riched20.dll
c:\windows\system32\msxml6.dll
c:\program files\blueberry software\flashback express 5\fbo\logsys.client.net35.dll
c:\program files\blueberry software\flashback express 5\fbo\ftsuploadagent.exe
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorsec.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\userenv.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\credssp.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorjit.dll
c:\program files\blueberry software\flashback express 5\fbo\blueberry.logger.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system\9e0a3b9b9f457233a335d7fba8f95419\system.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.drawing\dbfe8642a8ed7b2b103ad28e0c96418a\system.drawing.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.windows.forms\3afcd5168c7a6cb02eab99d7fd71e102\system.windows.forms.ni.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcm90.dll

PID
3272
CMD
"C:\Program Files\Blueberry Software\FlashBack Express 5\LogSysServer.exe" -x
Path
C:\Program Files\Blueberry Software\FlashBack Express 5\LogSysServer.exe
Indicators
No indicators
Parent process
FlashBack Recorder.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Blueberry Consultants
Description
LogSysServer Application
Version
1.6.1.137
Modules
Image
c:\program files\blueberry software\flashback express 5\logsysserver.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\winmm.dll
c:\windows\system32\winspool.drv
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\sspicli.dll

PID
1040
CMD
"C:\Program Files\Blueberry Software\FlashBack Express 5\FBO\FTSUploadAgent.exe" /p:c70 /w:10396
Path
C:\Program Files\Blueberry Software\FlashBack Express 5\FBO\FTSUploadAgent.exe
Indicators
Parent process
FlashBack Recorder.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Description
FTSUploadAgent
Version
1.0.0.3
Modules
Image
c:\program files\blueberry software\flashback express 5\fbo\ftsuploadagent.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\ole32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\profapi.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorsec.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\riched20.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\userenv.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\credssp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorjit.dll
c:\program files\blueberry software\flashback express 5\fbo\blueberry.logger.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system\9e0a3b9b9f457233a335d7fba8f95419\system.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.drawing\dbfe8642a8ed7b2b103ad28e0c96418a\system.drawing.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.windows.forms\3afcd5168c7a6cb02eab99d7fd71e102\system.windows.forms.ni.dll
c:\program files\blueberry software\flashback express 5\fbo\logsys.client.net35.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcm90.dll
c:\windows\system32\ntmarta.dll
c:\program files\blueberry software\flashback express 5\fbo\blueberry.s3filetransfer.dll
c:\windows\system32\shfolder.dll
c:\program files\blueberry software\flashback express 5\fbo\blueberry.tdfhandler.dll
c:\program files\blueberry software\flashback express 5\fbo\awssdk.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.configuration\bc09ad2d49d8535371845cd7532f9271\system.configuration.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.xml\461d3b6b3f43e6fbe6c897d5936e17e4\system.xml.ni.dll
c:\windows\system32\psapi.dll

PID
2292
CMD
RecorderChecker.exe 3184 262780 "FlashBack Express 5 Recorder"
Path
C:\Program Files\Blueberry Software\FlashBack Express 5\RecorderChecker.exe
Indicators
No indicators
Parent process
FlashBack Recorder.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Blueberry Software Ltd.
Description
Recorder Checker Application
Version
1.0.0.13
Modules
Image
c:\program files\blueberry software\flashback express 5\recorderchecker.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll

Registry activity

Total events
2546
Read events
2270
Write events
275
Delete events
1

Modification events

PID
Process
Operation
Key
Name
Value
128
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\NccQngn\Ybpny\Grzc\oosork5.rkr
0000000000000000000000003D100000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
128
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000001C0000002500000081A50C00090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101
128
explorer.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
128
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Blueberry Software\FlashBack Express 5\FlashBack Express Player.lnk
1
128
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blueberry Software\FlashBack Express 5\FlashBack Express Player.lnk
1
128
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Blueberry Software\FlashBack Express 5\FlashBack Express Recorder.lnk
1
128
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blueberry Software\FlashBack Express 5\FlashBack Express Recorder.lnk
1
128
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
LanguageList
en-US
128
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\NccQngn\Ybpny\Grzc\oosork5.rkr
000000000000000000000000089B0000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
128
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000001C000000250000004C300D00090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101
128
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\Oyhroreel Fbsgjner\SynfuOnpx Rkcerff 5\SynfuOnpx Erpbeqre.rkr
00000000000000000100000000000000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
128
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000001C000000260000004C300D00090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101
128
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\Oyhroreel Fbsgjner\SynfuOnpx Rkcerff 5\SynfuOnpx Erpbeqre.rkr
00000000000000000100000003020000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
128
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000001C000000260000004F320D00090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101090000000D000000CC19050033003000380030003400360042003000410046003400410033003900430042000000460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0051007500690063006B0020004C00610075006E00630068005C0055007300650072002000500069006E006E006500000000000034FF01F832FF01D4E3E1013DA94A7600000000FBFFFF7FF8E3E101987880574F8C6244BB6371042380B1090000000001100211FFFFFFFF000000000000000000000000534275066D42750653427506000000000000000000000000080000002E006C00E72F0A77A48EF37600000000AC032E0000002E00E72F0A77B08EF37603005B019604010000002E005B148D23020000006CE4E101B07F0A7744E5E1010000000058005A0044E5E1010200000010E5E101F2700A7791830A771C8FF37611000000B8453100B045310078192F00F8FD580600E500008F148D23B0E4E10182914A7600E5E101B4E4E10127954A7600000000CC90FF01DCE4E101CD944A76CC90FF0188E5E101408CFF01E1944A7600000000408CFF0188E5E101E4E4E101
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager
PendingFileRenameOperations
\??\C:\Program Files\Mozilla Firefox\tobedeleted\mozfbe5d5f7-8112-4126-966a-cd1572113b1d
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Blueberry Software\FlashBack Express 5\Components
PreInstall
1
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{811F7815-CA60-44f0-8116-36EBEC978693}
FBPLAYERAPI
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\FBPLAYERAPI.DLL
AppID
{811F7815-CA60-44f0-8116-36EBEC978693}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FBPLAYERAPI.FBPLAYERAPI.1
CFBPLAYERAPI Object
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FBPLAYERAPI.FBPLAYERAPI.1\CLSID
{9011568A-520F-40c3-81B7-19F1755B12D2}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FBPLAYERAPI.FBPLAYERAPI
CFBPLAYERAPI Object
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FBPLAYERAPI.FBPLAYERAPI\CLSID
{9011568A-520F-40c3-81B7-19F1755B12D2}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FBPLAYERAPI.FBPLAYERAPI\CurVer
FBPLAYERAPI.FBPLAYERAPI.1
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9011568A-520F-40c3-81B7-19F1755B12D2}
CFBPLAYERAPI Object
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9011568A-520F-40c3-81B7-19F1755B12D2}\ProgID
FBPLAYERAPI.FBPLAYERAPI.1
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9011568A-520F-40c3-81B7-19F1755B12D2}\VersionIndependentProgID
FBPLAYERAPI.FBPLAYERAPI
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9011568A-520F-40c3-81B7-19F1755B12D2}\InprocServer32
C:\Program Files\Blueberry Software\FlashBack Express 5\FBPLAYERAPI.dll
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9011568A-520F-40c3-81B7-19F1755B12D2}\InprocServer32
ThreadingModel
both
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9011568A-520F-40c3-81B7-19F1755B12D2}
AppID
{811F7815-CA60-44f0-8116-36EBEC978693}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9011568A-520F-40c3-81B7-19F1755B12D2}\TypeLib
{811F7815-CA60-44F0-8116-36EBEC978693}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{811F7815-CA60-44F0-8116-36EBEC978693}\1.0
FBPLAYERAPI 1.0 Type Library
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{811F7815-CA60-44F0-8116-36EBEC978693}\1.0\FLAGS
0
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{811F7815-CA60-44F0-8116-36EBEC978693}\1.0\0\win32
C:\Program Files\Blueberry Software\FlashBack Express 5\FBPLAYERAPI.dll
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{811F7815-CA60-44F0-8116-36EBEC978693}\1.0\HELPDIR
C:\Program Files\Blueberry Software\FlashBack Express 5\
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{815FAF71-694C-48E6-B3B1-5A6541A5F7E5}
IFBPLAYERAPI
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{815FAF71-694C-48E6-B3B1-5A6541A5F7E5}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{815FAF71-694C-48E6-B3B1-5A6541A5F7E5}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{815FAF71-694C-48E6-B3B1-5A6541A5F7E5}\TypeLib
{811F7815-CA60-44F0-8116-36EBEC978693}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{815FAF71-694C-48E6-B3B1-5A6541A5F7E5}\TypeLib
Version
1.0
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Blueberry Software\FlashBack Express 5\Components
Main
1
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Program Files\Common Files\Blueberry Software\BandLoader.dll
1
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{6685D22E-4B34-4E47-B2C1-FA3307E8BF59}
BandLoader
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\BandLoader.DLL
AppID
{6685D22E-4B34-4E47-B2C1-FA3307E8BF59}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BandLoader.MyBandLoader.1
MyBandLoader Class
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BandLoader.MyBandLoader.1\CLSID
{97269FFE-DB23-4212-83B3-483BD9F64E01}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BandLoader.MyBandLoader
MyBandLoader Class
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BandLoader.MyBandLoader\CLSID
{97269FFE-DB23-4212-83B3-483BD9F64E01}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BandLoader.MyBandLoader\CurVer
BandLoader.MyBandLoader.1
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{97269FFE-DB23-4212-83B3-483BD9F64E01}
MyBandLoader Class
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{97269FFE-DB23-4212-83B3-483BD9F64E01}\ProgID
BandLoader.MyBandLoader.1
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{97269FFE-DB23-4212-83B3-483BD9F64E01}\VersionIndependentProgID
BandLoader.MyBandLoader
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{97269FFE-DB23-4212-83B3-483BD9F64E01}\InprocServer32
C:\Program Files\Common Files\Blueberry Software\BandLoader.dll
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{97269FFE-DB23-4212-83B3-483BD9F64E01}\InprocServer32
ThreadingModel
Apartment
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{97269FFE-DB23-4212-83B3-483BD9F64E01}
AppID
{6685D22E-4B34-4E47-B2C1-FA3307E8BF59}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{97269FFE-DB23-4212-83B3-483BD9F64E01}\TypeLib
{498EAE2C-8803-44D9-8461-826EF6FB55B9}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{498EAE2C-8803-44D9-8461-826EF6FB55B9}\1.0
BandLoader 1.0 Type Library
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{498EAE2C-8803-44D9-8461-826EF6FB55B9}\1.0\FLAGS
0
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{498EAE2C-8803-44D9-8461-826EF6FB55B9}\1.0\0\win32
C:\Program Files\Common Files\Blueberry Software\BandLoader.dll
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{498EAE2C-8803-44D9-8461-826EF6FB55B9}\1.0\HELPDIR
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C836D51A-04EA-4806-8B2D-A7F4A08B710C}
IMyBandLoader
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C836D51A-04EA-4806-8B2D-A7F4A08B710C}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C836D51A-04EA-4806-8B2D-A7F4A08B710C}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C836D51A-04EA-4806-8B2D-A7F4A08B710C}\TypeLib
{498EAE2C-8803-44D9-8461-826EF6FB55B9}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{C836D51A-04EA-4806-8B2D-A7F4A08B710C}\TypeLib
Version
1.0
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Program Files\Common Files\Blueberry Software\BBFileTransfer.dll
1
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{ECF1D436-2F2F-45E6-B7CA-D978ED171BDD}
BBFileTransfer
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\BBFileTransfer.DLL
AppID
{ECF1D436-2F2F-45E6-B7CA-D978ED171BDD}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BBFileTransfer.FileTransferEngine.1
CFileTransferEngine Object
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BBFileTransfer.FileTransferEngine.1\CLSID
{E04D1559-4653-4B9D-B21C-3CBED4086680}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BBFileTransfer.FileTransferEngine
CFileTransferEngine Object
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BBFileTransfer.FileTransferEngine\CLSID
{E04D1559-4653-4B9D-B21C-3CBED4086680}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BBFileTransfer.FileTransferEngine\CurVer
BBFileTransfer.FileTransferEngine.1
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E04D1559-4653-4B9D-B21C-3CBED4086680}
CFileTransferEngine Object
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E04D1559-4653-4B9D-B21C-3CBED4086680}\ProgID
BBFileTransfer.FileTransferEngine.1
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E04D1559-4653-4B9D-B21C-3CBED4086680}\VersionIndependentProgID
BBFileTransfer.FileTransferEngine
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E04D1559-4653-4B9D-B21C-3CBED4086680}\InprocServer32
C:\Program Files\Common Files\Blueberry Software\BBFileTransfer.dll
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E04D1559-4653-4B9D-B21C-3CBED4086680}\InprocServer32
ThreadingModel
apartment
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E04D1559-4653-4B9D-B21C-3CBED4086680}
AppID
{ECF1D436-2F2F-45E6-B7CA-D978ED171BDD}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E04D1559-4653-4B9D-B21C-3CBED4086680}\TypeLib
{ECF1D436-2F2F-45E6-B7CA-D978ED171BDD}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BBFileTransfer.FileTransferProcess.1
CFileTransferProcess Object
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BBFileTransfer.FileTransferProcess.1\CLSID
{9CC18C7C-797A-42C1-802E-133A8198BB91}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BBFileTransfer.FileTransferProcess
CFileTransferProcess Object
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BBFileTransfer.FileTransferProcess\CLSID
{9CC18C7C-797A-42C1-802E-133A8198BB91}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BBFileTransfer.FileTransferProcess\CurVer
BBFileTransfer.FileTransferProcess.1
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9CC18C7C-797A-42C1-802E-133A8198BB91}
CFileTransferProcess Object
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9CC18C7C-797A-42C1-802E-133A8198BB91}\ProgID
BBFileTransfer.FileTransferProcess.1
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9CC18C7C-797A-42C1-802E-133A8198BB91}\VersionIndependentProgID
BBFileTransfer.FileTransferProcess
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9CC18C7C-797A-42C1-802E-133A8198BB91}\InprocServer32
C:\Program Files\Common Files\Blueberry Software\BBFileTransfer.dll
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9CC18C7C-797A-42C1-802E-133A8198BB91}\InprocServer32
ThreadingModel
apartment
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9CC18C7C-797A-42C1-802E-133A8198BB91}
AppID
{ECF1D436-2F2F-45E6-B7CA-D978ED171BDD}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9CC18C7C-797A-42C1-802E-133A8198BB91}\TypeLib
{ECF1D436-2F2F-45E6-B7CA-D978ED171BDD}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{ECF1D436-2F2F-45E6-B7CA-D978ED171BDD}\1.0
BBFileTransfer 1.0 Type Library
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{ECF1D436-2F2F-45E6-B7CA-D978ED171BDD}\1.0\FLAGS
0
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{ECF1D436-2F2F-45E6-B7CA-D978ED171BDD}\1.0\0\win32
C:\Program Files\Common Files\Blueberry Software\BBFileTransfer.dll
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{ECF1D436-2F2F-45E6-B7CA-D978ED171BDD}\1.0\HELPDIR
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BD7FED92-0896-4405-AB95-31B74150DEEF}
_IFileTransferEngineEvents
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BD7FED92-0896-4405-AB95-31B74150DEEF}\ProxyStubClsid
{00020420-0000-0000-C000-000000000046}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BD7FED92-0896-4405-AB95-31B74150DEEF}\ProxyStubClsid32
{00020420-0000-0000-C000-000000000046}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BD7FED92-0896-4405-AB95-31B74150DEEF}\TypeLib
{ECF1D436-2F2F-45E6-B7CA-D978ED171BDD}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{BD7FED92-0896-4405-AB95-31B74150DEEF}\TypeLib
Version
1.0
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{91E51792-1732-422E-AA01-C6ADADE75738}
IFileTransferEngine
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{91E51792-1732-422E-AA01-C6ADADE75738}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{91E51792-1732-422E-AA01-C6ADADE75738}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{91E51792-1732-422E-AA01-C6ADADE75738}\TypeLib
{ECF1D436-2F2F-45E6-B7CA-D978ED171BDD}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{91E51792-1732-422E-AA01-C6ADADE75738}\TypeLib
Version
1.0
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{171251DF-AF1E-49D1-B9E7-61778948D486}
_IFileTransferProcessEvents
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{171251DF-AF1E-49D1-B9E7-61778948D486}\ProxyStubClsid
{00020420-0000-0000-C000-000000000046}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{171251DF-AF1E-49D1-B9E7-61778948D486}\ProxyStubClsid32
{00020420-0000-0000-C000-000000000046}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{171251DF-AF1E-49D1-B9E7-61778948D486}\TypeLib
{ECF1D436-2F2F-45E6-B7CA-D978ED171BDD}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{171251DF-AF1E-49D1-B9E7-61778948D486}\TypeLib
Version
1.0
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{25604B85-0CEE-4216-A886-AC8627655E42}
IFileTransferProcess
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{25604B85-0CEE-4216-A886-AC8627655E42}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{25604B85-0CEE-4216-A886-AC8627655E42}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{25604B85-0CEE-4216-A886-AC8627655E42}\TypeLib
{ECF1D436-2F2F-45E6-B7CA-D978ED171BDD}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{25604B85-0CEE-4216-A886-AC8627655E42}\TypeLib
Version
1.0
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Program Files\Common Files\Blueberry Software\bbmemdumpflt.ax
1
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1D51818F-76B7-430D-AB49-87B6EB3DE442}
BB Dump Filter
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1D51818F-76B7-430D-AB49-87B6EB3DE442}\InprocServer32
C:\Program Files\Common Files\Blueberry Software\bbmemdumpflt.ax
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1D51818F-76B7-430D-AB49-87B6EB3DE442}\InprocServer32
ThreadingModel
Both
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{083863F1-70DE-11D0-BD40-00A0C911CE86}\Instance\{1D51818F-76B7-430D-AB49-87B6EB3DE442}
FriendlyName
BBDumpFilter
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{083863F1-70DE-11D0-BD40-00A0C911CE86}\Instance\{1D51818F-76B7-430D-AB49-87B6EB3DE442}
CLSID
{1D51818F-76B7-430D-AB49-87B6EB3DE442}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{083863F1-70DE-11D0-BD40-00A0C911CE86}\Instance\{1D51818F-76B7-430D-AB49-87B6EB3DE442}
FilterData
020000000000200001000000000000003070693300000000000000000100000000000000000000003074793300000000380000003800000000000000000000000000000000000000
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Program Files\Common Files\Blueberry Software\FBExplorerAddon.dll
1
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{AC2722DE-89AA-43F0-83E0-8E9662D67A7E}
FBExplorerAddon
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\FBExplorerAddon.DLL
AppID
{AC2722DE-89AA-43F0-83E0-8E9662D67A7E}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\QuickShare
{A8065B9E-193F-4797-B62D-8F6321E7FCCB}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FBDeskBand.DeskBandImpl.1
Blueberry FlashBack Client
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FBDeskBand.DeskBandImpl.1\CLSID
{84A8D09C-3774-4815-8EDF-32D7957E130C}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FBDeskBand.DeskBandImpl
Blueberry FlashBack Client
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FBDeskBand.DeskBandImpl\CLSID
{84A8D09C-3774-4815-8EDF-32D7957E130C}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FBDeskBand.DeskBandImpl\CurVer
FBDeskBand.DeskBandImpl.1
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{84A8D09C-3774-4815-8EDF-32D7957E130C}
Blueberry FlashBack Client
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{84A8D09C-3774-4815-8EDF-32D7957E130C}\ProgID
FBDeskBand.DeskBandImpl.1
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{84A8D09C-3774-4815-8EDF-32D7957E130C}\VersionIndependentProgID
FBDeskBand.DeskBandImpl
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{84A8D09C-3774-4815-8EDF-32D7957E130C}\InprocServer32
C:\Program Files\Common Files\Blueberry Software\FBExplorerAddon.dll
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{84A8D09C-3774-4815-8EDF-32D7957E130C}\InprocServer32
ThreadingModel
apartment
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{84A8D09C-3774-4815-8EDF-32D7957E130C}
AppID
{AC2722DE-89AA-43F0-83E0-8E9662D67A7E}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{84A8D09C-3774-4815-8EDF-32D7957E130C}\TypeLib
{AC2722DE-89AA-43F0-83E0-8E9662D67A7E}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{AC2722DE-89AA-43F0-83E0-8E9662D67A7E}\1.0
FBExplorerAddon 1.0 Type Library
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{AC2722DE-89AA-43F0-83E0-8E9662D67A7E}\1.0\FLAGS
0
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{AC2722DE-89AA-43F0-83E0-8E9662D67A7E}\1.0\0\win32
C:\Program Files\Common Files\Blueberry Software\FBExplorerAddon.dll
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{AC2722DE-89AA-43F0-83E0-8E9662D67A7E}\1.0\HELPDIR
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5A0ECFF7-4E67-4D0A-B7AC-19771E5622CE}
IDeskBandImpl
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5A0ECFF7-4E67-4D0A-B7AC-19771E5622CE}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5A0ECFF7-4E67-4D0A-B7AC-19771E5622CE}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5A0ECFF7-4E67-4D0A-B7AC-19771E5622CE}\TypeLib
{AC2722DE-89AA-43F0-83E0-8E9662D67A7E}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{5A0ECFF7-4E67-4D0A-B7AC-19771E5622CE}\TypeLib
Version
1.0
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
{A8065B9E-193F-4797-B62D-8F6321E7FCCB}
Blueberry FlashBack Client
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\BB FlashBack 2
{A8065B9E-193F-4797-B62D-8F6321E7FCCB}
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Program Files\Common Files\Blueberry Software\QSTools.dll
1
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Blueberry Software\FlashBack Express 5\Components
Common Files
1
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Blueberry Software\FlashBack Express 5\Components
FB Files
1
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Blueberry Software\FlashBack Express 5\Components
Custom
1
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Blueberry Software\FlashBack Express 5\Components
DefaultTextBoxStyles
1
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Blueberry Software\FlashBack Express 5\Components
MicroPlayerLangs
1
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Blueberry Software\FlashBack Express 5\Components
SWFControlBars
1
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Blueberry Software\FlashBack Express 5\Components
UploadProfiles
1
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Blueberry Software\FlashBack Express 5\Components
TASpecificFiles
1
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Blueberry Software\FlashBack Express 5\Components
FBOFiles
1
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Blueberry Software\FlashBack Express 5
Path
C:\Program Files\Blueberry Software\FlashBack Express 5
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\LogSysServer.exe
NoStartPage
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\FlashBack Batch Export.exe
NoStartPage
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Blueberry Software\FlashBack Express 5
StartMenuGroup
Blueberry Software\FlashBack Express 5
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FlashBack Express 5
DisplayName
FlashBack Express 5
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FlashBack Express 5
DisplayVersion
5.36.0.4417
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FlashBack Express 5
Publisher
Blueberry Software (UK) Ltd.
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FlashBack Express 5
URLInfoAbout
http://www.bbflashback.com/
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FlashBack Express 5
DisplayIcon
C:\Program Files\Blueberry Software\FlashBack Express 5\uninstall.exe
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FlashBack Express 5
UninstallString
C:\Program Files\Blueberry Software\FlashBack Express 5\uninstall.exe
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FlashBack Express 5
NoModify
1
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FlashBack Express 5
NoRepair
1
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FlashBack Express 5
InstallLocation
C:\Program Files\Blueberry Software\FlashBack Express 5
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FlashBack Express 5
VersionMajor
5
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FlashBack Express 5
VersionMinor
36
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.fbr
FlashBack Movie
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FlashBack Movie
FlashBack Movie
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FlashBack Movie\shell
open
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FlashBack Movie\DefaultIcon
C:\Program Files\Blueberry Software\FlashBack Express 5\FlashBack Player.exe,0
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FlashBack Movie\shell\open\command
"C:\Program Files\Blueberry Software\FlashBack Express 5\FlashBack Player.exe" "%1"
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FlashBack Movie\shell\edit
Edit FlashBack Movie
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\FlashBack Movie\shell\edit\command
"C:\Program Files\Blueberry Software\FlashBack Express 5\FlashBack Player.exe" "%1"
4004
bbfbex5.exe
write
HKEY_CURRENT_USER\Software\LogSys
Installation Path
C:\Program Files\Blueberry Software\FlashBack Express 5\LogSysServer.exe
4004
bbfbex5.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Blueberry Software\FlashBack Express 5
InstallerLanguage
1033
3184
FlashBack Recorder.exe
write
HKEY_CURRENT_USER\Software\Blueberry Software\BB FlashBack Express
UseTestSiteURL
0
3184
FlashBack Recorder.exe
write
HKEY_CURRENT_USER\Software\Clients\RPC32\5sserpxE
NEWHDWID1
3307738450
3184
FlashBack Recorder.exe
write
HKEY_CURRENT_USER\Software\Clients\RPC32\5sserpxE
NEWHDWID2
2924233003
3184
FlashBack Recorder.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FlashBack Recorder_RASAPI32
EnableFileTracing
0
3184
FlashBack Recorder.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FlashBack Recorder_RASAPI32
EnableConsoleTracing
0
3184
FlashBack Recorder.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FlashBack Recorder_RASAPI32
FileTracingMask
4294901760
3184
FlashBack Recorder.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FlashBack Recorder_RASAPI32
ConsoleTracingMask
4294901760
3184
FlashBack Recorder.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FlashBack Recorder_RASAPI32
MaxFileSize
1048576
3184
FlashBack Recorder.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FlashBack Recorder_RASAPI32
FileDirectory
%windir%\tracing
3184
FlashBack Recorder.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FlashBack Recorder_RASMANCS
EnableFileTracing
0
3184
FlashBack Recorder.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FlashBack Recorder_RASMANCS
EnableConsoleTracing
0
3184
FlashBack Recorder.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FlashBack Recorder_RASMANCS
FileTracingMask
4294901760
3184
FlashBack Recorder.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FlashBack Recorder_RASMANCS
ConsoleTracingMask
4294901760
3184
FlashBack Recorder.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FlashBack Recorder_RASMANCS
MaxFileSize
1048576
3184
FlashBack Recorder.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\FlashBack Recorder_RASMANCS
FileDirectory
%windir%\tracing
3184
FlashBack Recorder.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3184
FlashBack Recorder.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000092000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3184
FlashBack Recorder.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3184
FlashBack Recorder.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2156
LogSysServer.exe
write
HKEY_CURRENT_USER\Software\LogSys
Installation Path
C:\Program Files\Blueberry Software\FlashBack Express 5\LogSysServer.exe
3272
LogSysServer.exe
write
HKEY_CURRENT_USER\Software\LogSys
Installation Path
C:\Program Files\Blueberry Software\FlashBack Express 5\LogSysServer.exe
1040
FTSUploadAgent.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
LanguageList
en-US
1040
FTSUploadAgent.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\Certificates\F5AD0BCC1AD56CD150725B1C866C30AD92EF21B0
Blob
030000000100000014000000F5AD0BCC1AD56CD150725B1C866C30AD92EF21B0140000000100000014000000BBAF7E023DFAA6F13C848EADEE3898ECD93232D40400000001000000100000001EDAF9AE99CE2920667D0E9A8B3F8C9C0F00000001000000300000007CE102D63C57CB48F80A65D1A5E9B350A7A618482AA5A36775323CA933DDFCB00DEF83796A6340DEC5EBF7596CFD8E5D19000000010000001000000082218FFB91733E64136BE5719F57C3A118000000010000001000000045ED9BBC5E43D3B9ECD63C060DB78E5C200000000100000078050000308205743082045CA00302010202102766EE56EB49F38EABD770A2FC84DE22300D06092A864886F70D01010C0500306F310B300906035504061302534531143012060355040A130B416464547275737420414231263024060355040B131D41646454727573742045787465726E616C20545450204E6574776F726B312230200603550403131941646454727573742045787465726E616C20434120526F6F74301E170D3030303533303130343833385A170D3230303533303130343833385A308185310B3009060355040613024742311B30190603550408131247726561746572204D616E636865737465723110300E0603550407130753616C666F7264311A3018060355040A1311434F4D4F444F204341204C696D69746564312B302906035504031322434F4D4F444F205253412043657274696669636174696F6E20417574686F7269747930820222300D06092A864886F70D01010105000382020F003082020A028202010091E85492D20A56B1AC0D24DDC5CF446774992B37A37D23700071BC53DFC4FA2A128F4B7F1056BD9F7072B7617FC94B0F17A73DE3B00461EEFF1197C7F4863E0AFA3E5CF993E6347AD9146BE79CB385A0827A76AF7190D7ECFD0DFA9C6CFADFB082F4147EF9BEC4A62F4F7F997FB5FC674372BD0C00D689EB6B2CD3ED8F981C14AB7EE5E36EFCD8A8E49224DA436B62B855FDEAC1BC6CB68BF30E8D9AE49B6C6999F878483045D5ADE10D3C4560FC32965127BC67C3CA2EB66BEA46C7C720A0B11F65DE4808BAA44EA9F283463784EBE8CC814843674E722A9B5CBD4C1B288A5C227BB4AB98D9EEE05183C309464E6D3E99FA9517DA7C3357413C8D51ED0BB65CAF2C631ADF57C83FBCE95DC49BAF4599E2A35A24B4BAA9563DCF6FAAFF4958BEF0A8FFF4B8ADE937FBBAB8F40B3AF9E843421E89D884CB13F1D9BBE18960B88C2856AC141D9C0AE771EBCF0EDD3DA996A148BD3CF7AFB50D224CC01181EC563BF6D3A2E25BB7B204225295809369E88E4C65F191032D707402EA8B671529695202BBD7DF506A5546BFA0A328617F70D0C3A2AA2C21AA47CE289C064576BF821827B4D5AEB4CB50E66BF44C867130E9A6DF1686E0D8FF40DDFBD042887FA3333A2E5C1E41118163CE18716B2BECA68AB7315C3A6A47E0C37959D6201AAFF26A98AA72BC574AD24B9DBB10FCB04C41E5ED1D3D5E289D9CCCBFB351DAA747E584530203010001A381F43081F1301F0603551D23041830168014ADBD987A34B426F7FAC42654EF03BDE024CB541A301D0603551D0E04160414BBAF7E023DFAA6F13C848EADEE3898ECD93232D4300E0603551D0F0101FF040403020186300F0603551D130101FF040530030101FF30110603551D20040A300830060604551D200030440603551D1F043D303B3039A037A0358633687474703A2F2F63726C2E7573657274727573742E636F6D2F416464547275737445787465726E616C4341526F6F742E63726C303506082B0601050507010104293027302506082B060105050730018619687474703A2F2F6F6373702E7573657274727573742E636F6D300D06092A864886F70D01010C0500038201010064BF83F15F9A85D0CDB8A129570DE85AF7D1E93EF276046EF15270BB1E3CFF4D0D746ACC818225D3C3A02A5D4CF5BA8BA16DC4540975C7E3270E5D847937401377F5B4AC1CD03BAB1712D6EF34187E2BE979D3AB57450CAF28FAD0DBE5509588BBDF8557697D92D852CA7381BF1CF3E6B86E661105B31E942D7F91959259F14CCEA391714C7C470C3B0B19F6A1B16C863E5CAAC42E82CBF90796BA484D90F294C8A973A2EB067B239DDEA2F34D559F7A6145981868C75E406B23F5797AEF8CB56B8BB76F46F47BF13D4B04D89380595AE041241DB28F15605847DBEF6E46FD15F5D95F9AB3DBD8B8E440B3CD9739AE85BB1D8EBCDC879BD1A6EFF13B6F10386F

Files activity

Executable files
85
Suspicious files
9
Text files
872
Unknown types
34

Dropped files

PID
Process
Filename
Type
4004
bbfbex5.exe
C:\Users\admin\AppData\Local\Temp\nscF8D2.tmp\AdvSplash.dll
executable
MD5: 4c2048fab3e88d65b1186de260751d1b
SHA256: b08d6797848ee8eef5393391a7318e10720d55d03c910a2127c03b074c4966af
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\XECompat.bpl
executable
MD5: c5192e00681475beece5254ce07fc51a
SHA256: 3428967791d9fc2caaa57f5a6c43585f462f04c897fde30ef0ac9f4b87bb3261
4004
bbfbex5.exe
C:\Program Files\Common Files\Blueberry Software\ActiveBand.ocx
executable
MD5: 6c8de5ca1796270b9727da17a5c75425
SHA256: 1f504b2497b9dd7c6c931b1be94e4d17242e2cdbc8255e859dc39a1cae75b4e6
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\OpenH264Lib.dll
executable
MD5: 7ca31a7e47b7c42a8cb270f1633803d8
SHA256: da4706eccd8a01e64f44e4742b3ffcefa355b76fb73804c01534ae5982741ba4
4004
bbfbex5.exe
C:\Program Files\Common Files\Blueberry Software\FBExplorerAddon.dll
executable
MD5: 768e8c7df79fa62bed0e482a1ac83b1b
SHA256: 18f4654ec937611b06c1e3e8ecdccebd4e6bb7f8ee04e5bd04453d1a9932eb7d
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\vclx170.bpl
executable
MD5: ad76581e6ce875865bce12f8eaf42854
SHA256: 7585d8f5173a10d4547e0c854d589527154e680f5040c4ea6ce9cde54dd58c37
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\FlashBack Batch Export.exe
executable
MD5: 2b9cd9db95a088ab98ffdd1b5a458f80
SHA256: 44472930cd594d7fbcff8149ecaca1442b95c0d92d0b137a144fea7a80d4cab2
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\vcl170.bpl
executable
MD5: f77ea5d7cbeb284b821b659484e7c39d
SHA256: 3cf64c2a596162d9724b0a4e4bcb7e9aabf53bc638231640abecc9bff96797a6
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\FlashBack Player.exe
executable
MD5: d1df9abbe17ad11b6bcba908ed04c734
SHA256: 1e0dc84cf9c62246638fd9871ce948e36ba510a59645fe22b5a6ac8a5308af3f
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\soaprtl170.bpl
executable
MD5: 4f7898886836dfe0578dc0548c4342f6
SHA256: ba31c6cc7641ba1e7e3d4128cac94a3ba851b8a6d18c64511d644ff22548e1ff
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\vclie170.bpl
executable
MD5: f41d66924e451cb300639a99abc1a9a4
SHA256: 0cd9899c51136a87c7c072621b1550111576fec8d39e33a448eaab29365291f5
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\FlashBack Recorder.exe
executable
MD5: 962f2c93f5fcaa96dbd58631e030bf83
SHA256: a90753134c28fc0c88dd0a5a0de2ea2aec4d63f1e5433c8e483b7c5cf21af350
4004
bbfbex5.exe
C:\Program Files\Common Files\Blueberry Software\BBFileTransfer.dll
executable
MD5: c2f996608a766d561f82c574891f9ca1
SHA256: d58846f0ad3460a3233c2e74275f63e7039cb7a1054ac04746f59a73c4a42dde
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\vclactnband170.bpl
executable
MD5: 9d66c6d5ec22e2925f7c6e40630ffe7a
SHA256: 210f3692497e35d9683f9606b57ae01dddbfa8199f6fc28be8849d6ef903ce35
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\xmlrtl170.bpl
executable
MD5: d198143922a934e2ea1c90b3f1eb0af2
SHA256: 5ae9ffd2bf2daf63aac3800183805c369ae093fd7ee6914d7cfce6472792696e
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\UploadProfiles\DefConfig.exe
executable
MD5: cb3671e5a5d89ca0da23e9416bcddb23
SHA256: 55c9219ca1f7b43313af8a89d4541621c6f4000b8577bf7235b450c31961a7c6
4004
bbfbex5.exe
C:\Program Files\Common Files\Blueberry Software\bbmemdumpflt.ax
executable
MD5: f1efaf89d3a251b8e358a1e5093f532f
SHA256: f500421d8eb9e70bbebc3984cf318af1b398dc7ef78697bc42a639e27f8c3a51
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\vclimg170.bpl
executable
MD5: f38d0a8589909f5ec79e2403752b574c
SHA256: 6d8e5273fa36b15cbb840a98d19a467093a7a007b4fae0569c1ed3651498f02b
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\avcore-0.dll
executable
MD5: 5672aee2403b564a5a5e53f5d4d3a8d0
SHA256: 8f213be55f026c728c4bec710ee3c3a8c8595964a50f3850b27f977a099b2e92
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\UploadProfiles\FileCopyPublisher.dll
executable
MD5: 7aedce982b19a7c8c06f661cfb5700e0
SHA256: a0762593bc92658be36795f3180069f31f7bb5b46e1c909a3bf4c6c45287d238
4004
bbfbex5.exe
C:\Program Files\Common Files\Blueberry Software\QSTools.dll
executable
MD5: b1c5718fddb1b9628cfb8968e688b4d5
SHA256: c409a5277690f3fe37436624125ef6aa5ccded1902dc5d0c720b56f2ce006855
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\rtl170.bpl
executable
MD5: 3af8a5000932a97fbe8dd8508384db8f
SHA256: 413f10c73e63d696e1dae3965baaf82d8a31ee33e2a25ef6122ad7677c10b11d
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\SSEUtils.dll
executable
MD5: 170de010badddc58e471d9afff212f40
SHA256: 4cf33c84ffc4091d95aecc05865662f64709a70e44e667011504adbbe70787ca
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\UploadProfiles\PublishConfigurator.dll
executable
MD5: 9edd423cf750ba5f85664f3546442047
SHA256: 6f8e7bab410251eb654e1928416bafe12da3e8f4dafa4ebd8dce160ff63fec0b
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\uninstall.exe
executable
MD5: ec33bec2a8cdf4e735eb1358cb52f212
SHA256: 6f103e8d9051a1ad5963e7cd2f582d028bbe427ab152190548c11d56c892f661
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\cc32120mt.dll
executable
MD5: a26a70cc553bc7b0b89e90592fd72233
SHA256: 90424dd00519bc71921b19bc4991e6e64eb0371f9a47a94303ce979fd4fe1232
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\avutil-50.dll
executable
MD5: e4fe1e9d51595bddf393edfa026cd489
SHA256: 4f73fa7279d3d3fa4fd11936d8ddbd24fd5445eb3357ee63b47d12582f286911
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\UploadProfiles\FtpPublisher.dll
executable
MD5: 769128b60f33578e1fc002b13281d659
SHA256: 41e92f26c29fcc4e24d0751dde0baec8a92da92c8b1980548d4c7dfc02b320f3
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\WMVExport.dll
executable
MD5: 1e3c2385c42db936019c98551bd498be
SHA256: 3a155d12ff925a9fa6008a6e4d961113c4393ef8a69615d790a5e814944c28d3
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\dbrtl170.bpl
executable
MD5: 99765af48f418ea57e481650ab48e9b7
SHA256: 5141d6ee6b14ff630d7356f4c1d4b375061aab46dd45f5328683d4b401302eda
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\ActiveBand.bpl
executable
MD5: c36a5f6b5582d5fd6c9c19c1bc6b8b1d
SHA256: c6d35a6d689d92cffc29f71a9472fb7244982a6f4ccc4e51d4aca1441045ae17
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\UploadProfiles\YouTubePublisher.dll
executable
MD5: 001a37dd35b29321a1ef3b7ef8dc2ca8
SHA256: a29cc2f76c81c672592fe907a9a274a6636cdfa62fd531c0c07711e1449e41cd
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\Video2FLV.dll
executable
MD5: fba936f0c6d78cd627feaee57aee7c0d
SHA256: 63906c70db2fc4aea8c92bf2849bb53fdc7c036dfc7c745bc98e811602945196
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\dsnap170.bpl
executable
MD5: 7b5b9be2a6c6c2babb21f79c89a11af9
SHA256: 3198dbc852947ea7aa83bb2a832c1d86e32b06f1f8c16a3c003479864134ce91
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\avformat-52.dll
executable
MD5: 99cae080bcf113869af24daa4568fc8a
SHA256: ec575195653173587996d01783ca2cca9fb9c8a7dcc903781e62cef7b89973e9
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\FBO\Blueberry.Logger.dll
executable
MD5: e287de6c5a0fcba0eb6517337379c7e2
SHA256: 735e1627854d89958f5e140df250e9007268fd86cbd79a52e99cdb505799a532
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\VistaCoreSoundAPIWrap.dll
executable
MD5: 747a95dd0129329692326b23fac9d0e6
SHA256: fcba9d7af9bece92912f0b21b665db119ec0a97e0c274218558c51728e67b440
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\inet170.bpl
executable
MD5: 1042eae7ff1be4cd7455ae953493bb87
SHA256: 1e3f887e2b94d3087f95b7d886d1ca8aa63e71bde0661f7b53c65c3af6b3c107
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\avcodec-52.dll
executable
MD5: 85af94108e3430f37310df1a85926e5d
SHA256: 939cb03a4bf7d671035a7b5d41011a0d0800a0c837ab954be23a5f3276f27266
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\FBO\AWSSDK.dll
executable
MD5: 2b61708655108fc7e977027888d34d53
SHA256: 499c31a540713cb8eb57b7fc8f5376f70c1bb6e1e6fb9427af0a1c2cb4eb3b44
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\WMIIntDll.dll
executable
MD5: 82bdf073a392e95a7a64f515b94e2035
SHA256: e94fb584c99416c97f08962cc9c00b0905a4a2f80cc5da7b371ff7c716954aa2
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\borlndmm.dll
executable
MD5: da71a64295ec6c8cc2eb46e8883ca650
SHA256: ab75f5fe353ff19488eeca57a73a4aee29b6eee3fb0ff2e364149c5b0b30c169
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\swscale-0.dll
executable
MD5: 006353b41c8dc6609cddc6004bac3a5c
SHA256: 295403d9c382fe736906dd534d5c1930835c6eadd665f4e730fd32f270e778ed
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\FBO\Blueberry.S3FileTransfer.dll
executable
MD5: 2fd06ba3492216295a8dc53db9a781ae
SHA256: b89600d814e5540b60c5e184a0025246c8f7c0a0a3689d0b019acbf541befb95
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\WebCam.dll
executable
MD5: 6ecb7fd11aa1b5b5e8e099c8a9e5716c
SHA256: 161522809118f7f87f2874cdb014ec909b51a8f728f962a1153f09d1d4ff17cb
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\bcbie170.bpl
executable
MD5: 7a350b18180b71e04ac8f3a88f71db39
SHA256: c6efff0f7498cb7b970fa65d756831d2b25de040c82fbd1bf5e1a46f13c218af
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\FlashBackDriverInstaller.exe
executable
MD5: 79a3b481c3eaa504d843e3d4770820fd
SHA256: 93d61894c19e1083e386a06ec6e499833bc47789c40e0eeb97d9d5766fa39c01
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\FBO\Blueberry.TDFHandler.dll
executable
MD5: 8e2b6cd7440529a494168be0a267df80
SHA256: 04e74b01b30911524899fb95ec743b8153caa719d2f4ffe78a44a8b7bef41c40
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\VE32.dll
executable
MD5: 0439eecf843ee1aaa8fe82809533505e
SHA256: 5e1427000f012ba923c42b97d40c7b6066ec001b51016a12e7095e916439280f
4004
bbfbex5.exe
C:\Users\admin\AppData\Local\Temp\nscF8D2.tmp\Processes.dll
executable
MD5: 3e2db704d739f69d564fdfcb376b4761
SHA256: 456235015edd824ada4469138d97bcc0b3a774a2ddee06c2e922f65aa00f3a53
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\dbghelp.dll
executable
MD5: 5c5e3afd499e5146fef1da5ef8a23205
SHA256: 9a26ffaffb26fa6549c6da75f76238a903ca723f9dad356fba8d91067fe312fd
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\FBO\FTSClient.dll
executable
MD5: 70bf31f09b660e498b54bd6c3a778d9d
SHA256: d4359cbc642b3a253989cf7ba0568b5e2dc6eec6ea761eb5d3525c5d190f50ca
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\RunNonElevated.exe
executable
MD5: ad55cd8776a3bf775af6da1011920472
SHA256: 75830b6a16e248b896290e0823ca41f9f77509813f5789c4fa7c37a3368a8ee1
4004
bbfbex5.exe
C:\Users\admin\AppData\Local\Temp\nscF8D2.tmp\version.dll
executable
MD5: ebc5bb904cdac1c67ada3fa733229966
SHA256: 3eba921ef649b71f98d9378dee8105b38d2464c9ccde37a694e4a0cd77d22a75
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\libx264-128.dll
executable
MD5: de65379e8e402ee36e8fd75d77ba144e
SHA256: a9a38290d0a8e6f3a2819e63fbac70565923d0a4805820a846a52aa2bd921454
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\FBO\FTSUploadAgent.exe
executable
MD5: b1fbc0bb5385795a766a88a3ee0ae351
SHA256: 58e47d761ec4c4f13b559f418eb3a60142f0c65afbdf64f96db0036711a20093
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\BBIPP.dll
executable
MD5: d43e3560e072df52edc5ce342197c1d1
SHA256: 3a6e2c4c3d98996a98735f0c23ab84cb8aa546c3589dc8e94a468cc8a9f5cdf6
4004
bbfbex5.exe
C:\Users\admin\AppData\Local\Temp\nscF8D2.tmp\InstallOptions.dll
executable
MD5: 89351a0a6a89519c86c5531e20dab9ea
SHA256: f530069ef87a1c163c4fd63a3d5b053420ce3d7a98739c70211b4a99f90d6277
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\FlashBackInstall.dll
executable
MD5: ba7ec24590f321bfc9d0e55b39cfc586
SHA256: a2f7d4097d0f5c755a1938a58bb245147c37862d65705840482f1bde5e9a64a5
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\FBO\LogSys.Client.NET35.dll
executable
MD5: b2d2e5a491930aa366ca18185ab7d4b7
SHA256: 810b9c960ac8b1a4b293046099580590fe4afe2334b731a9df43deca59048617
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\libiomp5md.dll
executable
MD5: b85a3b59543ed2df4f9b0f0a74890c91
SHA256: 00fb37350230c254abd3ce102d04da97c43417b7da0df429aea9645f5a56db9f
4004
bbfbex5.exe
C:\Users\admin\AppData\Local\Temp\nscF8D2.tmp\StartMenu.dll
executable
MD5: 8fb72af40578e779e69049cccbfb473d
SHA256: 70a91d4b67b0017beb83e93724e799e2cde82cb2500d872266bf478878840d0c
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\FLVScreenVideo.dll
executable
MD5: 74283d568c482660a7387a16df4c2571
SHA256: 174a460339148532fd8b24c89010c65d6cc1c2085c509247ae86a3e868a22c11
4004
bbfbex5.exe
C:\Users\admin\AppData\Local\Temp\nscF8D2.tmp\ns65B6.tmp
executable
MD5: 30d31b3424ff6b7613eaaf79e9449e0f
SHA256: 8f0f0e254113725b386ff4c6c2967d556ed4d568245fc8af6f2dbea697ba56bf
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\FBPLAYERAPI.dll
executable
MD5: 309dfa965601450b32a0b25991e780ba
SHA256: f1acb1eb5a3fb6da77eb6f4ba0a9b5d74af004a3a5b5ee004af67fa80484f516
4004
bbfbex5.exe
C:\Users\admin\AppData\Local\Temp\nscF8D2.tmp\nsDialogs.dll
executable
MD5: 4ccc4a742d4423f2f0ed744fd9c81f63
SHA256: 416133dd86c0dff6b0fcaf1f46dfe97fdc85b37f90effb2d369164a8f7e13ae6
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\lame_enc.dll
executable
MD5: b22f0d1cfb5322e7a3573175d2156de9
SHA256: a332b34b664722c1b6a751f76ba390fd2f0ed15ec3f4052749a35a934d749092
4004
bbfbex5.exe
C:\Users\admin\AppData\Local\Temp\nscF8D2.tmp\nsExec.dll
executable
MD5: 132e6153717a7f9710dcea4536f364cd
SHA256: d29afce2588d8dd7bb94c00ca91cac0e85b80ffa6b221f5ffcb83a2497228eb2
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\CheckForUpdate.dll
executable
MD5: 7c2c52be2bc8cd999f6bdce0b178d94a
SHA256: 8830834ccad328e3e88ac8de148a2ff6301e4ee91bc783da1ec69bd78fdc028b
4004
bbfbex5.exe
C:\Users\admin\AppData\Local\Temp\nscF8D2.tmp\System.dll
executable
MD5: bf712f32249029466fa86756f5546950
SHA256: 7851cb12fa4131f1fee5de390d650ef65cac561279f1cfe70ad16cc9780210af
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\LibAVEncoder.dll
executable
MD5: c1a5cc69aa99857d2d3a75ea52d9123d
SHA256: b4167928f8ad4e59231609560dba341482bf9c979cd10acf0bb87d62af4c2bf6
4004
bbfbex5.exe
C:\Users\admin\AppData\Local\Temp\nscF8D2.tmp\ns67F9.tmp
executable
MD5: 30d31b3424ff6b7613eaaf79e9449e0f
SHA256: 8f0f0e254113725b386ff4c6c2967d556ed4d568245fc8af6f2dbea697ba56bf
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\GDI2MpegConverter.exe
executable
MD5: d60565a286bdc07bacfb1267723d9192
SHA256: b423bfc84e6e1ac53fe10159a6b5a91f59a101084842f8c8871a4e0f7476222e
4004
bbfbex5.exe
C:\Users\admin\AppData\Local\Temp\nscF8D2.tmp\UserInfo.dll
executable
MD5: c7ce0e47c83525983fd2c4c9566b4aad
SHA256: 6293408a5fa6d0f55f0a4d01528eb5b807ee9447a75a28b5986267475ebcd3ae
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\libmfxaudiosw32.dll
executable
MD5: 869cc99d2993b455c8f82984bf088fe6
SHA256: aee2d1e18ec78b74523fa914133e3a34c457059086863b5be326f18549b2fb70
4004
bbfbex5.exe
C:\Users\admin\AppData\Local\Temp\nscF8D2.tmp\ns6A3C.tmp
executable
MD5: 30d31b3424ff6b7613eaaf79e9449e0f
SHA256: 8f0f0e254113725b386ff4c6c2967d556ed4d568245fc8af6f2dbea697ba56bf
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\LogSysServer.exe
executable
MD5: 600c9b73c08b376ebb7af25a04542b7d
SHA256: ee7a32ab5d0c9bba214ea22f461221d7c530156e09ab4cd82981a68931612015
4004
bbfbex5.exe
C:\Users\admin\AppData\Local\Temp\nscF8D2.tmp\RemPendingFileOp.dll
executable
MD5: a06945198bdfaf5925dde537afceaae6
SHA256: b7057bb7065b54f674455d1059116cb7ed1f49ac93cb1ee72602cdc2cd82c514
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\RecorderChecker.exe
executable
MD5: 3dc3c084c30ed2e476f5f04a3077902e
SHA256: e6fd4bfef74df42d7f359f387e8dc5401798dc94936be258ce3de204b9aa708a
4004
bbfbex5.exe
C:\Users\admin\AppData\Local\Temp\nscF8D2.tmp\StatPluginDll.dll
executable
MD5: 7057e24726b7ddc35fdadcdf72629a85
SHA256: c7d62af8bed01a52fe0b87883a365ad499c54f175c1ad4d4c2090cbb51226850
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\LogSysInstaller.dll
executable
MD5: aadb71f27aa7c995fcadd13836983600
SHA256: 5a6231c9def3a96bf2123f4101980a36675a099f74a678b5d4eb818ab3716424
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\twolame.dll
executable
MD5: 0bbe835b43b3a8458d50f54b9b6ffdd1
SHA256: 3a663aeec202656d5e9a2ff17e74b5b9aa0b5d43c121204246eb8184e5f05b17
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\mpglib.dll
executable
MD5: 1407267f8aa58c94d2db2697ac9d1626
SHA256: 50a075a9cf348c64376478a6a60d6f4d5f12535762c17dcd466f9719530a7a8c
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\LogSysUploadCenterClient.dll
executable
MD5: 251ed88da9044ae9b88e03a61fa52cb4
SHA256: 5bccf1513ef879a450e41d7936957d0be8c15a22347375c77ba40dd8e5c75a16
4004
bbfbex5.exe
C:\Program Files\Common Files\Blueberry Software\BandLoader.dll
executable
MD5: 8f8311ab8408372d6d14dc0510fce09c
SHA256: 33a515a02d98a39386f37de370d5e439e1be765e2ed0cf48f14580621b07cd99
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\SWFControlBars\DefaultControlBarMediaPlayer3.fla
mswmm
MD5: ba8eb8e076c77e525b038e396eb3eadd
SHA256: 8fe4b0c95776cce1b703619388fcdece24d0ced0f2d8859ef1f0f7bb7f333efd
4004
bbfbex5.exe
C:\Users\admin\AppData\Local\Temp\nscF8D2.tmp\nsA4A7.tmp
––
MD5:  ––
SHA256:  ––
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x00000468.lgx
text
MD5: 05cbfa100c906c50e1a6446ba1d56730
SHA256: 9dcbc9e3972c9565a9ed3e5128cd2dc396b1cc962f01c4722d7a922731b690d3
4004
bbfbex5.exe
C:\Users\admin\AppData\Roaming\Blueberry\FBExpress5 Recorder.xml
xml
MD5: 00a42633a955ed159c3e1f031f615e41
SHA256: d33d7a8b61fd0d5b79bb0d99f49187fc02690750c5de2e2b0521172e6cf77a65
4004
bbfbex5.exe
C:\Users\admin\AppData\Roaming\Blueberry\FBExpress5 Player.xml
xml
MD5: ec55a3e78aab240da22cceadf89a3f84
SHA256: 1e0eb54e91fbb12742f3ddddc606cfba4d2d959aca4dfe6e7aa1ffa7b5d5de2d
4004
bbfbex5.exe
C:\Users\admin\AppData\Roaming\Blueberry\FBExpress5 Recorder.xml
xml
MD5: 0acf789782a5a39c979aa6c608a8c7ae
SHA256: ab90241c756fb6a7ecaff404685296539f81609aab51f3b4cadab70441870e35
2664
DefConfig.exe
C:\Users\admin\AppData\Roaming\Blueberry\FBExpress5 YouTube.xml
xml
MD5: 2876f69e390b75b6e12967b558a9eab5
SHA256: e1f6fcb742c97f50edc042a544430336992f6e3e7ba4be2f0cd38d42b9e8e412
2664
DefConfig.exe
C:\Users\admin\AppData\Roaming\Blueberry\FBExpress5 YouTube.Upload.xml
xml
MD5: 85094b7baaded64b0fa3b866917067d1
SHA256: e036adabd3a6b00807f2c04e953f64e9af5acc3fa00e77b9fb948754cbe9abae
2664
DefConfig.exe
C:\Users\admin\AppData\Roaming\Blueberry\FBExpress5 Profiles.xml
xml
MD5: 83ea6c14dcc62ffafe01dd8b65fecd9f
SHA256: e44faa4ac2b5f8d1655cc9b1fcfecc3e83529cecbc659b40dd1af631d993b044
2664
DefConfig.exe
C:\Users\admin\AppData\Roaming\Blueberry\FBExpress5 YouTube.Export.xml
xml
MD5: 5319a280acbf06453bee4ef86b6924eb
SHA256: d70d6bb11448a30283b66cf1768708e513ef52d3dd8c5e47025f255f9a75879d
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 FTS Upload Agent\Session_0x00000ddc.lgx
text
MD5: 328893559014840d3a546d01ffc48f44
SHA256: ca47e1321cda3d5603cf93fe149f416656487792f3de3fa3909b0b0a11a65c1f
2884
DefConfig.exe
C:\Users\admin\AppData\Roaming\Blueberry\FBExpress5 FTP.Export.xml
xml
MD5: 8f5ae8f3b6c63b951ed72717813435d3
SHA256: e8216b69e4a0b0208c610e3b6dcde6667491e51a0b8ec5f0e5f88d48dbce6fb2
2884
DefConfig.exe
C:\Users\admin\AppData\Roaming\Blueberry\FBExpress5 Profiles.xml
xml
MD5: 2a493eac679a546e5714819fa0dcfeec
SHA256: 4b76d47ef4346f0a01b1b93aaed17f1a43d513ed98038c418febddea69e9a2e9
2884
DefConfig.exe
C:\Users\admin\AppData\Roaming\Blueberry\FBExpress5 FTP.xml
xml
MD5: 3cb9bf0130d6a3f1cea3f8bd3d653f56
SHA256: 5a4466b23d282e4e57277799e5c667e3c84251df7ebf1a9bb50758849211e84c
2884
DefConfig.exe
C:\Users\admin\AppData\Roaming\Blueberry\FBExpress5 FTP.Upload.xml
xml
MD5: 0f548ddfcd3f15b0da6f052c5a2153a8
SHA256: c3e3988a827c67e425a1d9e687823941749af9b11e5bd30706dd25b47d5e8d3c
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 FTS Upload Agent\Session_0x00000ddc.lgx
text
MD5: bea42e40862d05208a8336956995c42c
SHA256: dd6b2e1115fe1f05ec8f9dd50191f9dfe366669062088d181ac18589ca5ca128
724
DefConfig.exe
C:\Users\admin\AppData\Roaming\Blueberry\FBExpress5 File Copy.Upload.xml
xml
MD5: 278c89179f6cdda99fea5b5fd390380c
SHA256: cdcc2db4e3ac04937afb6bf150af9bbfc1004c79feadc4233c3d96e6489e7854
724
DefConfig.exe
C:\Users\admin\AppData\Roaming\Blueberry\FBExpress5 Profiles.xml
xml
MD5: 8be12a2be6732ed647224cb3a08ce7c0
SHA256: a5be8c379fed5cfabad7c6b6a48036dd0158c4991c84a0ec6ec252d1e598a8a4
724
DefConfig.exe
C:\Users\admin\AppData\Roaming\Blueberry\FBExpress5 File Copy.Export.xml
xml
MD5: 85b34a9d04a885fc83824ab0c9ad744a
SHA256: ff6cca43f00986e2e9d60617f6dcc0ad9a784bf1b0cb3e611ed6fef26fc75291
724
DefConfig.exe
C:\Users\admin\AppData\Roaming\Blueberry\FBExpress5 File Copy.xml
xml
MD5: 00ec25da210f0cb67c99bb2465133b4a
SHA256: 03bae494175d748ed0554572d9ff0d9f68bca30611dbec026b84ee56e97a3ad4
724
DefConfig.exe
C:\ProgramData\LogSys\LogSys Server.xml
xml
MD5: 070a523e8e2240c43ff0052beb08f50f
SHA256: 65ea7e7e3354cafad53cc20679931afeb1f88bc39f12d11f0566dacc25bc3f23
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x00000468.lgx
text
MD5: 04d22b1f5a1a158097cd4a8114b860ac
SHA256: adcd4e63107846c0f1b056f5283a660b58930d1cb3d53fc2f7b5bb20161864b8
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x000008e4.lgx
text
MD5: e7e6cf200a9c0ebaf5d323b7faba948d
SHA256: 3c80cbaaf6aac78790ced43d0b978dbbc5da16e27191f01566a2c5195721050a
4004
bbfbex5.exe
C:\ProgramData\LogSys\LogSys Server.xml
xml
MD5: f4003a3ec2294a933132d2af25150fc0
SHA256: 08b6f943f1b2335b234e89636405fb9627d00eb3c009e3fec835c3d0d75c4636
4004
bbfbex5.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSys Server.xml
xml
MD5: cf96bd46d51d3f5cd53fda4d78fd8eee
SHA256: 4b711bca64aaedc537f9116a059674dba27f9fab903c1038fb23dee5628b2b44
4004
bbfbex5.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSys Server.xml
xml
MD5: 4bbaed2ba4359332dbed8aff142e09d1
SHA256: 3fedef2f1b282fa4ee05b3d192fa637a5ac5c9344fb5215d645d28f9baaf9d0b
4004
bbfbex5.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\FlashBack Express Player.lnk
lnk
MD5: ad3e14644633250ad4d623b5387de688
SHA256: 0fed95e6f3dbbb76562c9bd94564743328b75a616821ad9ba1c8b03d561088c2
4004
bbfbex5.exe
C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\FlashBack Express Recorder.lnk
lnk
MD5: 536c5fc43c672ca9e3d7a6714e426a44
SHA256: f55ee6e766cf4abc5d426d6f19f753fe0e5731afd4024dce538d71d6a6268430
4004
bbfbex5.exe
C:\Users\Public\Desktop\FlashBack Express Player.lnk
lnk
MD5: 9c5f7c16d7d03575647649ed06188626
SHA256: e565725ad9497cebcc24489b149a4b3809ee8b17712bf4e877a6b49fd229d2e1
4004
bbfbex5.exe
C:\Users\Public\Desktop\FlashBack Express Recorder.lnk
lnk
MD5: fe003289bc054b197e13ba1a7628785b
SHA256: 8a667b4bc1a1216ecd753ca935c60275d180ab95c6db9b732f0e7c8f32ddf2c4
4004
bbfbex5.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blueberry Software\FlashBack Express 5\Uninstall FlashBack Express 5.lnk
lnk
MD5: 2d93c170d3dce0ed0b93d6d0f317f233
SHA256: 1244b6842832191e5ac538f43d116205c86e68e07acba3e1d2aa7f623fb8b7be
4004
bbfbex5.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blueberry Software\FlashBack Express 5\Support\Help on Problem Reporting.lnk
lnk
MD5: b88154e33399fc5c37ca05a1265a0be6
SHA256: 393192e6730e76dff605049226abd88c3ffdd92087612f80d0b557f9b129ef66
4004
bbfbex5.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blueberry Software\FlashBack Express 5\Support\Enable Logging Autorun.lnk
lnk
MD5: 250c7a3b396adf472efa70add3a1ad37
SHA256: fcaa9a28e6dfdb26ab248750f6e2d2543d50f18309fc2aae61932051d2361f2a
4004
bbfbex5.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blueberry Software\FlashBack Express 5\Support\Report Problem to Blueberry.lnk
lnk
MD5: 0805b49a88e3a0f7080f52302df21af0
SHA256: 36d0d99b3360a7bf820c091106f176f06e4ae97988630fa617430c2049490f0b
4004
bbfbex5.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blueberry Software\FlashBack Express 5\FlashBack Express Help.lnk
lnk
MD5: 390a97345c619ae25ae2df16df4803b0
SHA256: 6ca55abd7f318712036feef5d5d420d64f3f008a8d0fed1f42eb514d14d70d1d
4004
bbfbex5.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blueberry Software\FlashBack Express 5\FlashBack Express Batch Export.lnk
lnk
MD5: 3610ef3f6add743b47a5a9c2ced083c8
SHA256: 93104751d5e4762b1940fa57754ad523523d5fdc4a1c1bee9e66f6bddaa55067
4004
bbfbex5.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blueberry Software\FlashBack Express 5\FlashBack Express Recorder.lnk
lnk
MD5: 536c5fc43c672ca9e3d7a6714e426a44
SHA256: f55ee6e766cf4abc5d426d6f19f753fe0e5731afd4024dce538d71d6a6268430
4004
bbfbex5.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blueberry Software\FlashBack Express 5\FlashBack Express Player.lnk
lnk
MD5: ad3e14644633250ad4d623b5387de688
SHA256: 0fed95e6f3dbbb76562c9bd94564743328b75a616821ad9ba1c8b03d561088c2
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 FTS Upload Agent\Session_0x00000ddc.lgx
text
MD5: 544986bf32dd6d802d76a11dc40e1b89
SHA256: 8934dc55dbfe816bfd681b801ff82f8711f6dfb758d05557de2cd2d02fa4cab3
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 FTS Upload Agent\Session_0x00000ddc.lgx
text
MD5: 9c7f93c72c21bbba29ae9e22cad4e52d
SHA256: 8c7d63e22166ecde4616ccf5aaa1c9b548568240e8d653c3cf543b20705f24fb
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\FBO\FTSUploadAgent.exe.config
xml
MD5: c424e3ecc23c624f5269519c275b9deb
SHA256: f54bc0592750108147ffd65664f6331bda851dcb3b65e4d0c72ad3734e48bfe3
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x00000468.lgx
text
MD5: 8dc8c4fae2df26d51afdef808f32836e
SHA256: 2e767137da264775d9054e8506e25276212cf6b6542372425522d58be26b6693
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x000008e4.lgx
text
MD5: f0a0191bd28c1a57e0d51e6c70c6e18e
SHA256: 258201d098afcb93a5b351344e5981885aa4cca4230eccf7fe7fbbaab4da67ae
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\FBO\default.ExportToFLV.xml
xml
MD5: f431e57640211916211fd8a3ddbdcbad
SHA256: 76fdfc1871d2dada7653c5156a55c2cde17402a7b99072ba27a32a014e7acaa8
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 FTS Upload Agent\Session_0x00000ddc.lgx
text
MD5: c4582b00b367d6fb80b4b9c038f0e8f5
SHA256: 0737a411d210ad374df1ae82b8d4bcab0b254d471800e1da45fe8231eb1c724a
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 FTS Upload Agent\Session_0x00000ddc.lgx
text
MD5: 301a571ffed7bc879b94b0f7bf690980
SHA256: 06da86a6b20e7da63ba91ac2926eaa2cb9d9ec2b72014f48208e903c74a480ea
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x00000468.lgx
text
MD5: a2338ddc30eeb272ef0b2db8619ac92e
SHA256: 06813747d5775d00398a0a9dfa585fe82c04fcd73547b9fe7c109b0bcae868c9
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x000008e4.lgx
text
MD5: c38645b791dfd6643be74d7a38da9dea
SHA256: a02a91480781fc3d520a1344f646f9ca4c923e214a153fa3e1cf2bdfec220b03
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 FTS Upload Agent\Session_0x00000ddc.lgx
text
MD5: e9e9fc308b268b679fa38184132f2412
SHA256: e07411a8552d92633dfa8e4abe6f94a4c89ad0294cc5569e0b90665ad6fed5c4
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 FTS Upload Agent\Session_0x00000ddc.lgx
text
MD5: 14b1174a55a0d381980c3900ee0ef673
SHA256: 21dbed71d2d9188c87cb2789decffcda52ac3b0cd2b33b1adb25b02cc9098f4c
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x00000468.lgx
text
MD5: ba1f29d730fcca107163a766c9aeb593
SHA256: 19efb985f113df49aa8be78f55db046d48c7e9908c1bfa83ed1edb3ebfaf3eab
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x000008e4.lgx
text
MD5: 68029deef3f6bc3b8a1690684afb2ab5
SHA256: f4b04bf5e5d475ec5f117a7d45461a40c8892923df26315377743377750a09d1
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\SWFControlBars\AS3\Flashvars.as
text
MD5: 5969ff78786eb3bcfea52ff434835558
SHA256: 33e1f9983a5e3fe1910b47c45281144b95670ae95d2dc8c2dcc8f4a6c0b79fcf
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\SWFControlBars\AS3\Element.as
text
MD5: c2ab46e11cc54beb3b57962fb370af15
SHA256: d81b3a9d586f185be9906400582dc5784782ff2157dbf19ecf179b84289097f5
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\UploadProfiles\default.ExportToFLV.xml
xml
MD5: b51b4958d4608f5f686ef9d36eb85175
SHA256: 541c608c5c44cd0e9b5490435cd5b57086bbf062a700f85e7b1460587776efde
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\SWFControlBars\AS3\Elements.as
text
MD5: d2d1e0672244e1062d8916dc1be13353
SHA256: 59284ce183c5794198b769a7760c9c3bc5d8804ac74f0f81daa18c50a2e5a3ab
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\SWFControlBars\AS3\CommonMultiple.as
text
MD5: a71cfb84c217c571b63bb2ab61a6d3c0
SHA256: 505aa40ccb9b5fade9059f69ab9b8f050d4514a54531f93621f7157b66c9062a
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\SWFControlBars\AS2\flashvars.as
text
MD5: fa0024bfae5c710a7c7b70400c0c4382
SHA256: 1f7bf410cd01bf12459be8e980d0ae397f07eda8d97269201d486d12a63bb986
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\SWFControlBars\AS3\Common.as
text
MD5: 632213ecc111367f480fd1cd80d9c052
SHA256: a8114b59ea8df409bff81652bf251560cc2cec710272b622ae77e6cc81a328ad
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\SWFControlBars\AS3\ButtonElement.as
text
MD5: c3e3efc2ed92998dbd6c627dc32ad4b1
SHA256: a3885a9eb610968507e92e1cb0a599be0429abdfd094558784f6eeb09c60a65b
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\SWFControlBars\AS3\CommonSingle.as
text
MD5: b9a8ddcb932774f0ec15a80f65705575
SHA256: f7254a5cb3defcce3c06ba6cc40dfc76aa440842330fa4e3e2b1893794ef8659
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\SWFControlBars\AS2\password_checking.as
text
MD5: 9bf015103b205736666919ae27af3351
SHA256: d3dbc958c2b71b87afc261b9dca1877e7ecdc271f5bd6999bac25be3c8896dc7
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\SWFControlBars\AS2\commonSingle.as
text
MD5: f9bb87dec9b7dec3ede99c9162922785
SHA256: 6ed78612a7c107ae09453e8ba8620adbc89b317e43375e957914988983742229
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\SWFControlBars\AS2\commonMultiple.as
text
MD5: 898c417aa80c2d492a18ed1857465fa7
SHA256: 14e8f732060f35f0122d1702cde515cc00f9eeb1dd16c5359d9818226bed696f
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\SWFControlBars\AS2\common.as
text
MD5: b2a227e3428ffb9816091f95b961e857
SHA256: bf774533e3d9da428d7e557d722147912423eeb5e2b7f87c6f532957963deec4
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\SWFControlBars\AS2\expiring_checking.as
text
MD5: 870988cba20e1a078b6d4f09d2069d27
SHA256: 2251fb68a693001506e97178bff7c0f4fe75556dfbceb2495777ef1c4d5c0e19
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\SWFControlBars\DefaultControlBarCoolWhite3.swf
swf
MD5: e4218e36af85c5d2cbcbf9f5d8375555
SHA256: 7c4cf055648a3550fef6c3f874936939df2a14968cd83261098eb8bfdad040bb
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\SWFControlBars\DefaultControlBarMediaPlayer3.swf
swf
MD5: e39fd22b51dbecd57a96c9de323a07ab
SHA256: 66716b9a2ea4f9153f1a8222571e2b46a3636b87edd2b417c7eff105123df31e
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\SWFControlBars\DefaultControlBar3.fla
mswmm
MD5: a148bc78ad61a98c34973bdc56b9bfe1
SHA256: d2bce452c87e00ba0db90214a8f33b2f898e7da319c82472638db14eda7b1c08
4004
bbfbex5.exe
C:\Users\admin\AppData\Local\Temp\nscF8D2.tmp\links.ini
text
MD5: f3fbbff673bbb0d1ee62fa77bcfbd88e
SHA256: 664b69a2c207b89130ba3f934a85e06cb943983dac2e5622bc5282de603f1fd8
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\SWFControlBars\description.txt
text
MD5: c3cb28760a53fb65bf56b9d0b73cb9be
SHA256: 06b9547e2458bd025e8e2745cf80d41e03405749e19100e40c70422543495fcf
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\SWFControlBars\DefaultControlBarCoolWhite3.fla
mswmm
MD5: 4640268841068162253743b37c6e696b
SHA256: 90aa001d81924e4cd25e4ba7a63ebb1d4e7d74bd430e89a236a990e445ad37ff
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\SWFControlBars\DefaultControlBar3.swf
swf
MD5: 955ea22b3411fef84e07e07a0c51db3b
SHA256: 3bab049ee03687bfcf73d36e42f5424ac23a0c0ad3e91f3358d8b1bc242763a5
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\SWFControlBars\DefaultControlBarMediaPlayerSingle.fla
mswmm
MD5: ab7dac666c989b1b81b376a55089bbe0
SHA256: 19c3674a9e5c321d1b5829206e4e61b7958316421ba989ddeafbd27b30ab95be
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\SWFControlBars\DefaultControlBarSingle.swf
swf
MD5: a21c025f0f8c65e175cb6651c9ccb49d
SHA256: a1c38031b317e2cc8f44616f4300e8130b0c432ac59883261a52f086692d6d5b
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\SWFControlBars\DefaultControlBarMediaPlayer.fla
mswmm
MD5: 789277b12e151873c5dfe5425e7b8afc
SHA256: d23263a62b497bdd5b1b0018254ecc7d34e4cb8c6e846579ecbaa86dfd00a7b9
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\SWFControlBars\DefaultControlBarMediaPlayerSingle.swf
swf
MD5: 150d4ed824893b9035af1c66d3ea2223
SHA256: 9c5fcbf219b24441b4856f3a8f74976101e5e0a3a476497b04b6ed4d02263018
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\SWFControlBars\DefaultControlBarMediaPlayer.swf
swf
MD5: 4cdc9f4c72ce264964427737124dcc58
SHA256: 0bfa99c0805f45c532197e65fe87ebbf8a41196d210ad71e5cbd9ad066e2299c
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\SWFControlBars\DefaultControlBarSingle.fla
mswmm
MD5: 496e52a8f2df4c8b61c4c26a32826436
SHA256: 96b7c20ec4d5cb4cd5886b3ed6448797072f7ac9cb8b66f240f03d72fb0e79b4
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\SWFControlBars\DefaultControlBarCoolWhite.swf
swf
MD5: 961b7cc75b4ff3975ac02ec243429e43
SHA256: 54e53cdb3c31f0d0a3589091baf03ed3a08e5b85fd1902042432f1ac46bdb316
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\SWFControlBars\DefaultControlBarCoolWhite.fla
mswmm
MD5: 01661de233d43f3e36e94b59d009a05f
SHA256: 6e9b7db71f7d9f7b05312c85065803be190bca034acfd1f1ec15e3ac0cf8d0c3
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\SWFControlBars\DefaultControlBarCoolWhiteSingle.swf
swf
MD5: c4f72fd3ff69da82fe8a25ee70c7d687
SHA256: 47d4a5cfdd33a5df45999b73c60e0284085fa76afb387e95a3d7152f4b414ec3
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\SWFControlBars\DefaultControlBarCoolWhiteSingle.fla
mswmm
MD5: 731bc8f397aec7a06034e4bb547eb8a1
SHA256: 1fa47bbb974cb85da7a1276e652f0f2ec7eaf57fbbfed0c8a7a1a0d80d740ccb
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\SWFControlBars\AS2toolbars.flp
text
MD5: 0ea480c1723be6311b8bd21a88ad88bc
SHA256: c2828da5b0a8d1b3104519eb0ab5e28bef5a1d060eed4e252cb56ac8133abc07
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\MicroPlayerLangs\en\resources.txt
text
MD5: 9e51c3b924feee6fbf9bd3b8ed346b08
SHA256: 809584778419395f9e3a5ec0575f2e4f03d7d1d2bc6efff386ff1b48fcfcbb89
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\SWFControlBars\DefaultControlBar.swf
swf
MD5: d45d9474883a439ce2f2712b68c8fbe1
SHA256: ec705bcfe67a550d23ce2c8450038a840281abd6b81c27120a90eed6cfa624ad
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\MicroPlayerLangs\en\Watermark.bmp
image
MD5: d6bb83f14b3d8135a948a6643c68840d
SHA256: 17b90c69dc268d565eb5529df230baa6609c7dea9ca5a6bc72cf7509f03eef47
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\SWFControlBars\AS3toolbars.flp
text
MD5: cc5114381e04712493a37aa1190a1ffe
SHA256: 66f201b4508fc0b52b40d93c91bb3366962b3516414733c576487ac75e48f042
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\SWFControlBars\DefaultControlBar.fla
mswmm
MD5: 1e7e6ad3d675fb930ec4035a8e8617ea
SHA256: a29c5620868b9e8aee2b20db45634d63f31291b8bd61ed703643cdc204a0423a
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\DefaultTextBoxStyles\Orange.xml
xml
MD5: 6e0c97183b320251991a687af4b40bb3
SHA256: 14b63905e29855eacc7b479040d243f1ec72bef7b5d9dbd4f1b303752e80abf8
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\DefaultTextBoxStyles\Postit.xml
xml
MD5: 920c55feffc8591fd7ea325ab65f57bd
SHA256: 02c7a2309d027da15ca4d668bbaf2542959f5b052fb69059be2d84f9c00e9c10
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\DefaultTextBoxStyles\Purple - light.xml
xml
MD5: e0d85ce707187421b4f3e9a643c783fc
SHA256: db27f1914debf8a15890780e50daa0d6dbc48053add704e970477dcef07a7159
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\DefaultTextBoxStyles\Longhorn.xml
xml
MD5: 31466f3f52f01851dc10709ceac58353
SHA256: 682f12679e83a9a2a506ecdc828e8bdae029dc99001735fe9ecd8434f34b8d53
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\DefaultTextBoxStyles\Purple - dark.xml
xml
MD5: e499afb0d66a95396832edbf9155fe0d
SHA256: b7777f5a77d6a773f161d1424111febcfe0e7834a8ab6642c99b167a5740b0fb
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\MicroPlayerLangs\en\Help.gif
image
MD5: 0a0beddf9218cb531ef81659cb3a1f72
SHA256: 565b0ccb8db9cfd61bf2562d34d3175957e06657809d478d907d10471c912c68
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\DefaultTextBoxStyles\Green - light.xml
xml
MD5: 180dfb3d63059bcba6c433d7483d7751
SHA256: 2aa44560eefa94e1a13e6df04e62aa09f0684e0166eacf58365908efdd8178a5
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\DefaultTextBoxStyles\Grey - light.xml
xml
MD5: bd023e28730fb9ba0d3b7eedb79adaee
SHA256: ad47d2eda111446fca2d66c942954d1a94380b83467935a0d8074ee0c3414e30
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\DefaultTextBoxStyles\Blue - dark.xml
xml
MD5: 1b9fbced448575e16fccf44c6be3783e
SHA256: 3461677acee78aa7e5b98dd074d1a864ea226bc0d6cbadb832dbd8923c576c31
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\DefaultTextBoxStyles\Green - dark.xml
xml
MD5: 8d0d096f0502d9459016b32830475b3c
SHA256: f257d2b1a3fbcc175b4835370f6dbcb736aa25f92fe1207266bbcc42ba67186d
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\DefaultTextBoxStyles\Grey - dark.xml
xml
MD5: 67635798f48dbb03f99d7161235b9df1
SHA256: 19e8e4063c3f84d7689d82079a74ab9ba962938a013ff23422b9f116a627a1f0
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\DefaultTextBoxStyles\Blue - light.xml
xml
MD5: a9b0d7bffe22e5bf7278188a73e22712
SHA256: e128f5534e48936572ce12f1eccdf7bcee07dec3bc3afb4a5fa5fdd66d973d8d
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\Custom\WheelMouseUp2.bmp
image
MD5: 3f9f26753d01f5bfb484079326932fe1
SHA256: c09f96e33b5d1d5081c2af250f61585b6c19c598b203a96ec8c2c7a5aaae2d55
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\Custom\WheelMouseDown3.bmp
image
MD5: f54725e0acb0e6603956fbe2415790f1
SHA256: 75058b3a1efbf96eeb74719ad1fe7e4df6292beaafd98141c3154d1fc0cdd92c
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\Custom\WheelMouseUp3.bmp
image
MD5: 27aec2f166f1789ef5a7afbeba56ff7b
SHA256: d29d8ba56604b74e4968cc44b2ba38ea76941de79e2c375a229564ee9ab1a0e2
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\Custom\WheelMouseUp1.bmp
image
MD5: 8395fdcdbd3ac47c06094fe1b4dab656
SHA256: ff8abc6616e065c9e7d392f1932065cdeee6c7bb008ccefc5424d40ba280569c
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\Custom\WheelMouseDown2.bmp
image
MD5: 861374f7ee979be84027d1dee227e1fd
SHA256: db5ed21ea2480cda1328b5441e70dc8912738263fa489b06e07d5261fd1a1010
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\Custom\WheelMouseDown1.bmp
image
MD5: b0356dca9f456a577d9831ffdd054811
SHA256: 2d0323e09ce9af3e93c8c06e69974fe5ee383940f1b5261cdf8568b50776f5a1
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\Custom\RightMouseUp3.png
image
MD5: 2838602717a69c0a121c1015eaf931ab
SHA256: a2ad1ed3598017cd7696c415fdbde67b1644ce954c59b2ffcc9858a0738927e4
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\Custom\RightMouseDown3.png
image
MD5: f306fe44a267a932cc627858d294cfa4
SHA256: 05244f383ff0352d50546db373f733faa8654ee74f83e3d6b490871e088e092f
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\Custom\RightMouseUp2.png
image
MD5: aa39d037bd93acc8440bc86224851ba8
SHA256: d5b7fae9db1dc1de687a282ae8d4ac10ec8c34a78515c98aa194c765c9f2660d
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\Custom\RightMouseUp1.png
image
MD5: ad1fa373b598760e0f07ba177e39cb78
SHA256: 8698d2514c90e0b974ff1948bbbff438144aef4310e1169940d49dc3a87352af
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\Custom\RightMouseDblClk2.png
image
MD5: 1a97f5a71b79f3aace520da0a24ce3c5
SHA256: 3ee0031c7683a900b7c8ce1d4225b9d73bde93ccee23646ac2f9303fb5ae71f6
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\Custom\RightMouseDown1.png
image
MD5: 73a022958034e16fb50c8572642918de
SHA256: 0fba4e2854b7014d354f7fbaba23815b945391f67842ff605e7f835b5daa8f61
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\Custom\RightMouseDown2.png
image
MD5: 2711660934c05e95dba9ba6a4eadfef6
SHA256: bbe7eccd4b1006f0a9140b8e3e541dc7e35e9315af3f02b362ef90554a5b5c24
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\Custom\RightMouseDblClk3.png
image
MD5: c840e3a29f0131dcab7b6633cd773dc6
SHA256: 05fbba6584d982c00f7ecc479fd6a9e8f77c32616a6ef5549b3c7097adcbd0d5
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\Custom\RightMouseDblClk1.png
image
MD5: 2a6d2315fc9836b08cee700ffd4a3c33
SHA256: da4bf165c7c720455759099ff7b9d1a1126c8d90ef5f4561634b49e507124f5b
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\Custom\MiddleMouseDown2.png
image
MD5: 66efe81b2fc6cfb2bb281cca3b990f35
SHA256: 8b138eec05fd6a99c5e988e30ce366c19ea6b29e027aba23f66b65ba0d114ac7
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\Custom\MiddleMouseDblClk3.png
image
MD5: b49f5a07972f9a803e75725259b075f3
SHA256: c6dd3d69bfdca5e7b682290c8fa9796de6e68807bafa0f5fdf74b69c25ff3a5b
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\Custom\MiddleMouseUp3.png
image
MD5: 2afc41ef93bbaefe0f66e3795787090c
SHA256: 9bf644e3f73ec3c0db6a833dc44a7421bd88dcd3e4f6b84f519803e02eee2e47
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\Custom\MiddleMouseUp2.png
image
MD5: f4b0bebb0fa0881bc043bb35387c0c34
SHA256: 3918a577962d7d692d4a4e7956498df97d23266649fddc6339367bfb8b9e6e87
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\Custom\MiddleMouseUp1.png
image
MD5: eeb2bfa295f1907ae66680c7a734e1ec
SHA256: 3dba8c414775fc52d3aea62eed561731c9a049b5f1e7e0d51bbcde3602e987b2
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\Custom\MiddleMouseDown1.png
image
MD5: b2e157093e802176e77a580fb50f0b20
SHA256: 21fb341bd8ed5be68d07dc02d67ad964f49ae4919313d74da87a3d6b694a681d
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\Custom\MiddleMouseDown3.png
image
MD5: 92c92a752f83b0dda26e6b15d1340215
SHA256: 8441f5f678c0cee5e7a7163d17ccd19b3ba6ff0ceea8c06ae47021239096792f
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\Custom\LeftMouseUp1.png
image
MD5: c8e26e8cf97c3d410eb998d44f112181
SHA256: 797d6ef23214a367890fb522b4776e1c25ba206140e51e9cad437b8352437562
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\Custom\LeftMouseDown3.png
image
MD5: 14068ca13d016d2a9f07ff3b5de7a60e
SHA256: 2042117efb19ab006a49bf753661a174f22b6c1402dc076d96f8c1e4c31c95c8
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\Custom\MiddleMouseDblClk1.png
image
MD5: 806693a070dc776e5d434adce690536e
SHA256: d34fb4a6c609f23b8fd33a7115998f6ebfc978a466dbeb47185b581ebd20c700
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\Custom\LeftMouseUp3.png
image
MD5: 7e477b729c00ea521a408c2f713f2a2e
SHA256: 7980b57313a5306f18f83bbeb8115e06aeba1a9b9798f1348875376a889045f9
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\Custom\LeftMouseDown1.png
image
MD5: 7f05d7977a15645f7ed34b3e8f19c74a
SHA256: c59c1b90cf53df5f91c5e59a46f904880d5353782062489facb71e62289be9ba
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\Custom\MiddleMouseDblClk2.png
image
MD5: 15eb30ed1c24644865c7764d30342254
SHA256: 3cba9c62fc49b56f4a0a43356d4728512a0d0162b0b8d970b86ce47c0b3848f0
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\Custom\LeftMouseDown2.png
image
MD5: 2a987924d8e483da13181cf5e00dbba3
SHA256: f3e40ac947a81c1fde1145d58ff2fae2ed73aa81583956153d15335a075d8590
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\Custom\LeftMouseUp2.png
image
MD5: 2a987924d8e483da13181cf5e00dbba3
SHA256: f3e40ac947a81c1fde1145d58ff2fae2ed73aa81583956153d15335a075d8590
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\Custom\LeftMouseDblClk3.png
image
MD5: e4102859c224de6c84c70f120aa6ac3b
SHA256: 89b4caed57afd9eb4db2a4de27ee358efa812e5febe03c44116a6c894982046d
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\Custom\LeftMouseDblClk1.png
image
MD5: 34c51de90fb194e16c3614d86993df97
SHA256: b424d489b0b9cf07a7f8f347e2b1cb726b98821d168c8645118bd39fc423e07e
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\Custom\custom.cfg
text
MD5: d336796f4e33d7d3cfa22afbbc91098e
SHA256: 889a42a503fcdb4335e0025fc9236e0121f196621fcae89f6691bbb03dd59146
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\Custom\LeftMouseDblClk2.png
image
MD5: 1ddb91d0bc8f030bd86bbd89a63386e5
SHA256: 560ea4e10d283cd07bddfb8ae95bc1dbf335669e4cee213baa0dc1cbec533ff3
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 FTS Upload Agent\Session_0x00000ddc.lgx
text
MD5: 222a0073670f883cb9554e7a5dc40090
SHA256: 2107178d0f436f7396ef7cbd6ff3d56fc25566af735fd48c1784194c7da751b3
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 FTS Upload Agent\Session_0x00000ddc.lgx
text
MD5: 345fc31b6ddf4a0ed9c88a048a3e05ed
SHA256: 86b6dfd3b1f6c3a6115f7d6199b2d722b0baf4df2683d57fed83b035cb0d4f19
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\FlashBack Recorder.dbg
binary
MD5: afebc10ce39c093a6529b03bb735e8c1
SHA256: a2948ef247fbf5a4a64bb7c302487e2a28a2fdfe815a50fdfeaa817a59e0f2ea
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\FlashBack Player.dbg
––
MD5:  ––
SHA256:  ––
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x00000468.lgx
text
MD5: 9034ba4bd6df9ae671ec5e8cf27b9b5e
SHA256: d597567c8df38e12a364860b80a49df5311de455a66dbee82a920668f705f0e9
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\FlashBack Express 5 Help.chm
chm
MD5: 96f07acad9501b6bbd0877157eae6c22
SHA256: e003385f1fcfa48abe1783352c0d8cd19114088e18c0d51134d2920983bdc1f4
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x000008e4.lgx
text
MD5: 9677fb8afe9bdb9833a8c7bc226b1645
SHA256: 3aa590bb9699b216a3f9bb3571ab43c9c729c97d1e17d63ceb14b97d109615b6
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 FTS Upload Agent\Session_0x00000ddc.lgx
text
MD5: 580eff29a33293fcf4c220c76930c4b6
SHA256: 6716f46b93ee10de1427df8d66e641a47896c6941b29b9d5e5b7177174863e63
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x00000d30.lgx
text
MD5: a9cd239c43dd0e8fe1ff6e43a4782bfb
SHA256: 4761471de47327667bcb1ceeac54a5f1915a6541955e5fd6c0774094e99dd08f
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x000008e4.lgx
text
MD5: 4a6a733fea84ac33c24c7c6e67ac7851
SHA256: 157fbe4faefa3785ab940c061a1ac500494525612cb1747c05e80a6e38aba3ba
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x00000d30.lgx
text
MD5: 706d818ae71b9050cf8f52cdb5e51fd4
SHA256: bb65c2d53d4543c02c701b85cf5e3bec7602bb7d44740237c00a028cb25c5dc0
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x00000d30.lgx
text
MD5: 8628ccd88206d38eb91f50b569a4b8b0
SHA256: a4eb4f27df055cee3514aa54627d7878b8b58d2b3a32311d550ecf5e91e77647
4004
bbfbex5.exe
C:\Program Files\Common Files\Blueberry Software\FBExplorerAddOn.log
text
MD5: a940160ed70f14713a98ab884c8b7c56
SHA256: 2606249affa4ed5bd86815a88989d5429939328cf6b79af1e008c49d45be5e27
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\Readme.htm
html
MD5: 57ab9c6eec992b9bb24833fbf520274c
SHA256: 9b8eb8f41dd7fc4ef79ed391622b58a5249afda4cb902f0e8fd14f1ebf38aa5c
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\Licence.rtf
text
MD5: b25b715be32a3fb317fe553b3693759f
SHA256: 231c9416b781602277d5df7da0d51440f6433ea6eb26f3953498051219b90db8
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x0000084c.lgx
text
MD5: f910ea72582cf4c6cbd98902c5a05e5f
SHA256: b0b987c8e1fed3aed727ac80d6d50a86aa2c942181c7a00e746114f5219dab3b
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x000008e4.lgx
text
MD5: 58c157e820f49ab6e2f2b6c3ce3a319d
SHA256: 8af8e7cfa179ca3451b1a34b0bdcbcccf3f6c103feea76c14c9b3e36360f7072
3184
FlashBack Recorder.exe
C:\Users\admin\AppData\Roaming\Blueberry\FBExpress5 Recorder.xml
xml
MD5: 04f7e415d4d0f7f40c74d6b26d51e22e
SHA256: 9761b56b61e415f1a3927d417305a090f3e384bdaf8a7ffb9c679a7700ef33d5
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 FTS Upload Agent\Session_0x00000ddc.lgx
text
MD5: f38bd344667c5386cd741aec1b90c14c
SHA256: 0b2147aa1d9bad44673f11eb130d5f55cfc42d6330922075c18c751d797704fe
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\VistaCoreSoundAPIWrap.pdb
pdb
MD5: 444452a3337e958689ac490f74fd68fc
SHA256: 2618088747f3fcdf7b31bfedbf165be4f51c8943beb1fb876bc94b273655103e
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 FTS Upload Agent\Session_0x00000f2c.lgx
text
MD5: 59f90ae183d8f18d361e22d2dc1cf563
SHA256: 96ed5027b7a6d51ac101d1aee114c8bcc7cb734ff85398191d72055c25f46992
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x000008e4.lgx
text
MD5: 9728c3926d2b7da5b14efab79cd58213
SHA256: 6cc7406ba0a7be8de201cf81987a38d041f2058e06cf51b0eba5d9f96a16d404
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\VideoPlayers.txt
text
MD5: e501ab552018fb5c67516b5c6defac9a
SHA256: e885c4e539e8fcc21ad17070ff0a0f3fb93022150290a414ea20e749e6a0d63e
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x0000084c.lgx
text
MD5: 2ebff3ce448a4d072d09090a97f00803
SHA256: f9686434db71bec1554c0b2e96aec77a8f0becf73454c101ffd72d055be38ed3
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x0000084c.lgx
text
MD5: 456d35d49aa0b8ce1ad108d89f64d81c
SHA256: 2b623aaad671336958b124b7417e54aebb2f90834d548a638526efd9fb04a6ee
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\PredefinedGallery.dat
––
MD5:  ––
SHA256:  ––
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x000008e4.lgx
text
MD5: a4fde9a77261e69150d07f5769037797
SHA256: 8e8259fa46d7c6dbc19a9b21e07c5b61247ab6bcedbeeed15893faeae9328907
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSys Server.xml
xml
MD5: 7109da33551acd9f3b7574f303cb0625
SHA256: 41a59613a18362aa3715c5fed4ddb32236885fb47bd4ee6a932c76e26e37af6e
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\review.xsl
xml
MD5: 9b846f33c1e7920a8f44ca24b79e36ad
SHA256: c0e65362737b10346d45f15decd620ae88f587f68c09db4cb70cc26eb1d26c47
2156
LogSysServer.exe
C:\ProgramData\LogSys\LogSys Server.xml
xml
MD5: 4ef3612ec02997f528fe57291dc8c0a5
SHA256: 80f7f2c153ad698cd6a0ccf2047bc27b37fa0dd8bb51992bd724e1ee7ba2c516
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x0000037c.lgx
text
MD5: f52c2070a2916897e53e3ccb88dc2a0b
SHA256: 60fb45bcae6992443e5187bddc9b2c6edb96a80de155f3834e2ae61a28efdf38
1040
FTSUploadAgent.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\74FBF93595CFC8459196065CE54AD928
der
MD5: 1edaf9ae99ce2920667d0e9a8b3f8c9c
SHA256: 4f32d5dc00f715250abcc486511e37f501a899deb3bf7ea8adbbd3aef1c412da
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\LOGSYSINFO.HLP
hlp
MD5: a5881364e84ca9583b05e8f8f7abd32c
SHA256: 15186e1d1fac3f943b78fcb53918951bf312bb2191a23b0cce017b400498311b
1040
FTSUploadAgent.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\74FBF93595CFC8459196065CE54AD928
binary
MD5: b4b90c20d1361a1de7ec75983157210a
SHA256: 039520a7424a20e2621004d94008ae2d2795fe2a314e98841436ef8479d4eb1d
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x0000037c.lgx
text
MD5: 73b4f738f9b18f089e2150747b988abc
SHA256: 71ce471bd08c00840e31c6fe2b51533db0f49cb5c7920973e1683f80a85823b1
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x00000854.lgx
text
MD5: f4e087dce3c2d7482d01ce41cb8d86ab
SHA256: f93f8357cd9027900dd19f71d29ddaec969234bbc9e469ab67e5a4c4512cd3da
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x00000854.lgx
text
MD5: 64fb36e7d72921e7cd8fad18a078ea40
SHA256: b173c2db7da77d00f677712417149b57cbf8fab826fe87907baadd792b56625b
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x000008e4.lgx
text
MD5: bd8547f1883aa8a644a5f606c1b239b0
SHA256: 979826f6636af43bff14708b1783bc37ec3e16b2f22a54ac7cfa59aa6b1d9084
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x000008e4.lgx
text
MD5: e940e9f8ca208d12ffd1349c77c6ea58
SHA256: b688615fc60282c482b37c06ce83a8edb1563fa8bf6c629933264e6ee04fc2ba
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x000008e4.lgx
text
MD5: 17f4fe976503410e1b100ccf9601f642
SHA256: 36a37b72dced2b0f2e3b01fcb3f0a8fe275980697ba7ca2bd7644b1231b62e09
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x00000468.lgx
text
MD5: fcf4a484fcc5b049150d39054b0cc63f
SHA256: ef388f1d06940a1f430051bdf727de33703d13a0ceeec67ff619cb44f9d19eab
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x000008e4.lgx
text
MD5: 1e4f1c8341a0b4dcc52ff09032a6d284
SHA256: 37a4445a3dec47ba40831569fec29d19437c3ba42eb08a41feefd31c0a2271ff
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x00000ff4.lgx
text
MD5: 9b583eaea28415edbce412d01736060e
SHA256: 32e4b9b145087639123e5c5c2bb398575860c7df64519aabd3e9abff6e9790db
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x00000ff4.lgx
text
MD5: 90873d588e7a03022bc0883a977647e1
SHA256: a9bbe26a8ad5c8976f8d049c9cf141c23244d6f8974d95595e03e6d67e3ea747
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x000008e4.lgx
text
MD5: 8363217396b1dc70097bf05b92eac369
SHA256: ebd6bd65dea5c5497dcf648a77673c8416301a52b2af7911f4237100ea09e6d4
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x00000468.lgx
text
MD5: ebf026d616171fac3a7a00930e34ae48
SHA256: bfa29d9fb9e71d02285e36ea31c0f27c8cb9477bfc837dbbd2f246a36f149adf
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\BBBR-FlashBack Express 5.xml
xml
MD5: b751c9f69b04bfba5b56b3735d2fcc11
SHA256: 9b72fa14e1eeb677daddc239b376805007969952a07c8a485332f03a9af30bed
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\FBFields.xml
xml
MD5: 4a9cd39e5f1b15a4e4df34f7b4147dc6
SHA256: fd245f4ad6f486d443f6576745119df4626b43f5085107303d78de9979d8407b
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x00000468.lgx
text
MD5: 29b55bfd71428b9958cf7c40d833461f
SHA256: 42c0587b33014ec2e9299f004a3e7edbc53b958fe8ae9d0bac1e76f7e9e650af
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x000008e4.lgx
text
MD5: 2f4508e1a74cf22cb66381057b02ea20
SHA256: 328c49ff56817ac1d25cbe65c59ebe1164cff5a5fc5e3a4fda88a3c2701dda25
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x000008e4.lgx
text
MD5: 26375c0aef9e3f2d4266a3a325363c78
SHA256: 7465d618dc0f322102cd04cabc550bb337ca31b0dffde9dffae4da6071bb66b7
3184
FlashBack Recorder.exe
C:\Users\admin\AppData\Roaming\Blueberry\FBExpress5 UsageTracking.xml
xml
MD5: 77504b8facd85a296b3fa2f0b70f4b8c
SHA256: 398ae0ced53eb1b1bc416137977b0ef71538bcc67992c96a7d38ca3dc175c5b0
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x000008e4.lgx
text
MD5: 9b0c96d1583bd7ca05e3eb95f1524b59
SHA256: 7ba0083efad78392f2f8a586d5cb14d7fd2d5acf8c2bad02a080f39d6ae1757e
3184
FlashBack Recorder.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
text
MD5: fe962608dba24242516b1ce914d1fcbb
SHA256: 50e9780fc22cb3449ffbea9fbda86921c7f45e634daa02896119f77b4c7bed05
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\welslayer.cfg
text
MD5: c6d902fecabac5acc1f71f9aa06b2ab4
SHA256: cb71e57aa74903079974f5094e695f5f551bed82329e0534d92dc32145871465
3184
FlashBack Recorder.exe
C:\ProgramData\Blueberry\Updates\settings.set
binary
MD5: 7ec42020f81475a6e02409dc559dcff4
SHA256: de93304854dd334e2dd7cc678c1c0af51273ab8b354cd3b4034fe92791458d60
3184
FlashBack Recorder.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
––
MD5:  ––
SHA256:  ––
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x000008e4.lgx
text
MD5: 493f24fe68aa57eaf1cf26f2291e6e17
SHA256: efc6e4a843614ebd326bdd5eb7534112e95b8f62b4628e0b7a345d05408f5131
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x000008e4.lgx
text
MD5: b12ee85a29f3d2a66de58818894cc271
SHA256: 269e1b7f25f2f851d7d057dd0e11f154c0a61b48bd6fdb6d7dd103f9f2f261b5
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x000008e4.lgx
text
MD5: 13f9251988ca768b5705ac5237bcc8ab
SHA256: 0d8c5fc3e90d2b88bad09126b2bd6ac118c3da169c5493d2502b5d4641bde121
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\welsenc.cfg
text
MD5: aa2a983a8560f4cdaaea27820e2dc635
SHA256: 30c664d956d5cdb1484adb4896a0a9cdd95a9f74a83a0b09a24a9cdeafe39628
3184
FlashBack Recorder.exe
C:\Users\admin\AppData\Roaming\Blueberry\FBExpress5 UsageTracking.xml
xml
MD5: 51d2583baebe209b0155d168b5653506
SHA256: 4ecbff296946e16d8fc81ffa39fdbd677554a8be775ca5fe26f10ed2dcec2c2e
3184
FlashBack Recorder.exe
C:\Users\admin\AppData\Roaming\Blueberry\FBExpress5 CrashTracking.xml
text
MD5: 7eae4e87c940066ea74251e711c5892c
SHA256: 64396d14e14e895a0614c598337e66ccbb88f077859aa18715da876fc7988449
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x000008e4.lgx
text
MD5: 9bf527a4f37eb1b3aebd226992272f31
SHA256: a52efc671549b77dea0b73060d2011bc2d221af89a7e0cf2db5288396855f318
3184
FlashBack Recorder.exe
C:\ProgramData\Blueberry\Updates\settings.set
binary
MD5: 9f37fb10da1c1cb785201e2a18432d92
SHA256: 9df9ac49a00e343314ea926802f00a57efc6e21bfb03ed4c15ecbb59772839a2
3184
FlashBack Recorder.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
text
MD5: 4d94b492ec11630ca399379d2c4a1069
SHA256: ba4c3038192a7e9488c43fa8412657fedc2bade53d1cfdd1205f5d8d43513e32
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x000008e4.lgx
text
MD5: 87a27cc188ae65f04ea6072520bd8929
SHA256: 3d9243b4e746520be4e94e9e78bc57c9da515629699dbfdc649c5a85a307f0c8
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x000006a4.lgx
text
MD5: b24e58bd334568b7a5fa5f84c5f1440b
SHA256: f253f8935ed735b48b33e55c414ab936719d891fdc2d2cbf09ae6ad043b700e0
3184
FlashBack Recorder.exe
C:\ProgramData\Blueberry\Licences\FlashBack Express 5 English.xml
binary
MD5: f1492963d01485a31bcd3257c7d1e34f
SHA256: b8b7bd34278a83ebb28f3ce03f463e6ab4381c37fc656f21e2fff0d6642d5e68
3184
FlashBack Recorder.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
text
MD5: 47699964dfb586792fc049fecf749929
SHA256: eeef9212323dddc3f78a0b4b1ad5dc825e84c2e06e8487536d817a7e05c80486
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x000008e4.lgx
text
MD5: 91c7ef13f0c546c595cae3ec402a99c5
SHA256: 588d808358a4560d16f8d7599159439cb8eb7717b5f9952d3a809b0047cc9499
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x000008e4.lgx
text
MD5: 1a4a83ed0a52ec1e99167b7fa9718d92
SHA256: 8f3a26fc7f9a370a27a2a5d5c7fdf53cd1a639599cbe6e6bc56da69622d2e4fc
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x00000e00.lgx
text
MD5: 4bb70ca6521bb9245d714276879627e7
SHA256: d637a1e3446494ec4474afbecdf6d81fdba634ba1f3050443b58c7c995f399c7
3184
FlashBack Recorder.exe
C:\ProgramData\Blueberry\Licences\sys_mtslog_5sserpxE
binary
MD5: 9a263bf4df2a69742640fbd9d6e1f8ba
SHA256: 6a6f098ffb03f3f6cb1a8c251dae22d5d29afc4ca597d06ecfb43bf86e7bd668
4004
bbfbex5.exe
C:\Users\admin\AppData\Local\Temp\nscF8D2.tmp\links.ini
text
MD5: 4fca41133161ce24af03a3772e3e1519
SHA256: d8f3e126b9072071013fe2b1f619b84864ea59cb32a59e95d076c58cf908b3d6
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x000008e4.lgx
text
MD5: 20d10aee5edb4ad91c0c1d5ea06beb7f
SHA256: 565df03e671ab230646aea5e386555c267bc66b540ab01143439d8262a5fdc78
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x000008e4.lgx
text
MD5: 79b32469ecf285c635a1a502b9260d95
SHA256: fd737b6a52bf9bb0c1b5d7ab9974582847c5eed62a6dad551aaeb1a0c1609703
4004
bbfbex5.exe
C:\Users\admin\AppData\Local\Temp\nscF8D2.tmp\links.ini
text
MD5: 4362aaec98aa896b45399fc7d46908db
SHA256: 15dff81a52757491320170d88ad31e7cb046ec970629fb9fe0c9e79031afc208
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x000008e4.lgx
text
MD5: 4a952fe33e7f258b5ff94d69b689e465
SHA256: 3b5b48cf8246b360feb6ab99d293dae327ea649c827460969807fa3161cb292a
3272
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\logsysserver.log
binary
MD5: 20dca6c8d6c4f160e5fb6c651a6b3d26
SHA256: 853c51724bdb8a9c3e5ce645534d2c758a3df88bee19a9ed9bc00b19b30a3e17
4004
bbfbex5.exe
C:\Users\admin\AppData\Local\Temp\nscF8D2.tmp\modern-wizard.bmp
image
MD5: cbe40fd2b1ec96daedc65da172d90022
SHA256: 3ad2dc318056d0a2024af1804ea741146cfc18cc404649a44610cbf8b2056cf2
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x000008e4.lgx
text
MD5: 7c4b59703b204a69347ac45f94319b07
SHA256: 23975f83c4f940052ea0e2942bf329b434a179b0630753007f55ff316dcd2705
3184
FlashBack Recorder.exe
C:\ProgramData\LogSys\LogSys Server.xml
xml
MD5: 7df7562ac9d79f3a5db00812af8280d1
SHA256: 087c6c174f43a1ef146c3bd57f317d1dc019b626faad8cd0b39a72afef042948
4004
bbfbex5.exe
C:\Program Files\Blueberry Software\FlashBack Express 5\install.log
text
MD5: ddc6fe533a0c621be15707468ae06edb
SHA256: bd70faa732560dcea03caac413a74b9eb46369934d40dd47e8f3d7396dfacdea
4004
bbfbex5.exe
C:\Users\admin\AppData\Local\Temp\nsnF8C2.tmp
––
MD5:  ––
SHA256:  ––
4004
bbfbex5.exe
C:\Users\admin\AppData\Roaming\Blueberry\FBExpress5 UsageTracking.xml
xml
MD5: 284c4281821f84f0c6b890a047cb200f
SHA256: 09b27e57481b3ed6bb4212a7a16ebac9edfea1a49b03e189ec186c41b8952f95
4004
bbfbex5.exe
C:\Users\admin\AppData\Local\Temp\nscF8D2.tmp\spltmp.bmp
image
MD5: 773a9a6e0a41f2f7befdadfc49bb03c9
SHA256: 75f9d45676036c8e7f2373b64c1b13dbd2865e1311ded0040da3df8cac5080b2
2156
LogSysServer.exe
C:\Users\admin\AppData\Roaming\LogSys\LogSessions\FlashBack Express 5 Recorder\Session_0x000008e4.lgx
text
MD5: a24edcad79bc4718efae34cb922a6ea3
SHA256: 85ba6dfe2557f9f604477bfa72e7b8366199a9ade94a1c6e8ee8e75b5e79a97b

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
7
TCP/UDP connections
5
DNS requests
5
Threats
0

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
3184 FlashBack Recorder.exe POST 200 104.27.151.13:80 http://regsys.ws.bbsoftware.co.uk/regsys.svc US
xml
text
shared
3184 FlashBack Recorder.exe POST 200 176.34.137.58:80 http://stats.ws.bbsoftware.co.uk/stats.asmx IE
xml
xml
suspicious
3184 FlashBack Recorder.exe POST 200 176.34.137.58:80 http://updates.bbconsult.co.uk/Updates.asmx IE
xml
xml
suspicious
1040 FTSUploadAgent.exe GET 200 91.199.212.52:80 http://crt.comodoca.com/COMODORSAAddTrustCA.crt GB
der
whitelisted
3184 FlashBack Recorder.exe POST 200 176.34.137.58:80 http://updates.bbconsult.co.uk/Updates.asmx IE
xml
xml
suspicious
3184 FlashBack Recorder.exe POST 200 176.34.137.58:80 http://updates.bbconsult.co.uk/Updates.asmx IE
xml
xml
suspicious
3184 FlashBack Recorder.exe POST 200 176.34.137.58:80 http://updates.bbconsult.co.uk/Updates.asmx IE
xml
xml
suspicious

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
–– –– 130.159.196.117:123 Jisc Services Limited GB unknown
3184 FlashBack Recorder.exe 104.27.151.13:80 Cloudflare Inc US shared
3184 FlashBack Recorder.exe 176.34.137.58:80 Amazon.com, Inc. IE unknown
1040 FTSUploadAgent.exe 91.199.212.52:80 Comodo CA Ltd GB unknown

DNS requests

Domain IP Reputation
ntp.cis.strath.ac.uk 130.159.196.117
130.159.196.118
unknown
regsys.ws.bbsoftware.co.uk 104.27.151.13
104.27.150.13
unknown
stats.ws.bbsoftware.co.uk 176.34.137.58
suspicious
updates.bbconsult.co.uk 176.34.137.58
suspicious
crt.comodoca.com 91.199.212.52
whitelisted

Threats

No threats detected.

Debug output strings

No debug info.