General Info

File name

npp.7.6.6.Installer.exe

Full analysis
https://app.any.run/tasks/882ca941-ee14-4267-bfc6-6dfb8fb37b83
Verdict
Malicious activity
Analysis date
5/15/2019, 21:32:20
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5

0c800b1023015ea56e0646b104bcd6a2

SHA1

ac88ecc39661fa1bdafca53eb2db02fab3fc7b41

SHA256

9582fec10e6ca488ab506a96dfeb5da56c9425ca32a8481e060bd06893fb1b3e

SSDEEP

98304:zvhI/t8RBSYZtXEoJClv8ztoHh6DGVX2G5oxBItk:zJ8O8YZtXE5lOuh6DG12G5oxBYk

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (73.0.3683.75)
  • Google Update Helper (1.3.33.23)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 65.0.2 (x86 en-US) (65.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Application was dropped or rewritten from another process
  • notepad++.exe (PID: 4004)
  • gup.exe (PID: 2736)
  • notepad++.exe (PID: 1336)
Loads dropped or rewritten executable
  • notepad++.exe (PID: 4004)
  • gup.exe (PID: 2736)
  • notepad++.exe (PID: 1336)
  • regsvr32.exe (PID: 2744)
  • npp.7.6.6.Installer.exe (PID: 2776)
Registers / Runs the DLL via REGSVR32.EXE
  • npp.7.6.6.Installer.exe (PID: 2776)
Creates files in the user directory
  • notepad++.exe (PID: 1336)
  • npp.7.6.6.Installer.exe (PID: 2776)
Creates COM task schedule object
  • regsvr32.exe (PID: 2744)
Creates files in the program directory
  • npp.7.6.6.Installer.exe (PID: 2776)
Executable content was dropped or overwritten
  • npp.7.6.6.Installer.exe (PID: 2776)
Creates a software uninstall entry
  • npp.7.6.6.Installer.exe (PID: 2776)

No info indicators.

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable MS Visual C++ (generic) (67.4%)
.dll
|   Win32 Dynamic Link Library (generic) (14.2%)
.exe
|   Win32 Executable (generic) (9.7%)
.exe
|   Generic Win/DOS Executable (4.3%)
.exe
|   DOS Executable Generic (4.3%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2018:12:15 23:24:36+01:00
PEType:
PE32
LinkerVersion:
6
CodeSize:
26112
InitializedDataSize:
141824
UninitializedDataSize:
2048
EntryPoint:
0x34a5
OSVersion:
4
ImageVersion:
6
SubsystemVersion:
4
Subsystem:
Windows GUI
FileVersionNumber:
7.6.6.0
ProductVersionNumber:
7.6.6.0
FileFlagsMask:
0x0000
FileFlags:
(none)
FileOS:
Win32
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
English (U.S.)
CharacterSet:
Unicode
CompanyName:
FileDescription:
Notepad++ : a free (GNU) source code editor
FileVersion:
7.6.6.0
LegalCopyright:
Copyleft 1998-2017 by Don HO
ProductName:
Notepad++
ProductVersion:
7.66
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
15-Dec-2018 22:24:36
Detected languages
English - United States
CompanyName:
FileDescription:
Notepad++ : a free (GNU) source code editor
FileVersion:
7.6.6.0
LegalCopyright:
Copyleft 1998-2017 by Don HO
ProductName:
Notepad++
ProductVersion:
7.66
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x000000D8
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
5
Time date stamp:
15-Dec-2018 22:24:36
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x00006409 0x00006600 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.41619
.rdata 0x00008000 0x00001396 0x00001400 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 5.15491
.data 0x0000A000 0x00020358 0x00000600 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 4.0044
.ndata 0x0002B000 0x0001A000 0x00000000 IMAGE_SCN_CNT_UNINITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.rsrc 0x00045000 0x000261E0 0x00026200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 5.73115
Resources
1

2

3

4

5

102

103

104

105

106

107

110

111

202

203

204

205

206

207

211

302

303

304

305

306

307

311

402

403

404

405

406

407

411

502

503

504

505

506

507

511

602

603

604

605

606

607

611

702

703

704

705

706

707

711

802

803

804

805

806

807

811

Imports
    KERNEL32.dll

    USER32.dll

    GDI32.dll

    SHELL32.dll

    ADVAPI32.dll

    COMCTL32.dll

    ole32.dll

Exports

    No exports.

Screenshots

Processes

Total processes
43
Monitored processes
8
Malicious processes
3
Suspicious processes
1

Behavior graph

+
drop and start start npp.7.6.6.installer.exe no specs npp.7.6.6.installer.exe regsvr32.exe no specs explorer.exe no specs explorer.exe no specs notepad++.exe no specs gup.exe notepad++.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3792
CMD
"C:\Users\admin\AppData\Local\Temp\npp.7.6.6.Installer.exe"
Path
C:\Users\admin\AppData\Local\Temp\npp.7.6.6.Installer.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
Don HO [email protected]
Description
Notepad++ : a free (GNU) source code editor
Version
7.6.6.0
Modules
Image
c:\systemroot\system32\ntdll.dll

PID
2776
CMD
"C:\Users\admin\AppData\Local\Temp\npp.7.6.6.Installer.exe"
Path
C:\Users\admin\AppData\Local\Temp\npp.7.6.6.Installer.exe
Indicators
Parent process
––
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Don HO [email protected]
Description
Notepad++ : a free (GNU) source code editor
Version
7.6.6.0
Modules
Image
c:\users\admin\appdata\local\temp\npp.7.6.6.installer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\version.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\shdocvw.dll
c:\users\admin\appdata\local\temp\nsd4655.tmp\langdll.dll
c:\users\admin\appdata\local\temp\nsd4655.tmp\system.dll
c:\windows\system32\riched20.dll
c:\users\admin\appdata\local\temp\nsd4655.tmp\installoptions.dll
c:\windows\system32\comdlg32.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\users\admin\appdata\local\temp\nsd4655.tmp\nsdialogs.dll
c:\users\admin\appdata\local\temp\nsd4655.tmp\userinfo.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\program files\notepad++\notepad++.exe
c:\windows\system32\regsvr32.exe
c:\windows\system32\netutils.dll

PID
2744
CMD
regsvr32 /s "C:\Program Files\Notepad++\NppShell_06.dll"
Path
C:\Windows\system32\regsvr32.exe
Indicators
No indicators
Parent process
npp.7.6.6.Installer.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft(C) Register Server
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\program files\notepad++\nppshell_06.dll
c:\windows\system32\msimg32.dll

PID
2796
CMD
"C:\Windows\explorer.exe" "C:\Program Files\Notepad++\notepad++.exe"
Path
C:\Windows\explorer.exe
Indicators
No indicators
Parent process
npp.7.6.6.Installer.exe
User
admin
Integrity Level
HIGH
Exit code
1
Version:
Company
Microsoft Corporation
Description
Windows Explorer
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\slc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\actxprxy.dll

PID
2428
CMD
C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding
Path
C:\Windows\explorer.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Windows Explorer
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\slc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\actxprxy.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\program files\notepad++\notepad++.exe
c:\windows\system32\mpr.dll

PID
1336
CMD
"C:\Program Files\Notepad++\notepad++.exe"
Path
C:\Program Files\Notepad++\notepad++.exe
Indicators
No indicators
Parent process
explorer.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Don HO [email protected]
Description
Notepad++ : a free (GNU) source code editor
Version
7.66
Modules
Image
c:\program files\notepad++\notepad++.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\program files\notepad++\scilexer.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\propsys.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\program files\notepad++\updater\gup.exe
c:\windows\system32\windowscodecs.dll
c:\program files\notepad++\plugins\mimetools\mimetools.dll
c:\program files\notepad++\plugins\nppconverter\nppconverter.dll
c:\program files\notepad++\plugins\nppexport\nppexport.dll

PID
2736
CMD
"C:\Program Files\Notepad++\updater\gup.exe" -v7.66
Path
C:\Program Files\Notepad++\updater\gup.exe
Indicators
Parent process
notepad++.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Don HO [email protected]
Description
WinGup for Notepad++
Version
5.1
Modules
Image
c:\program files\notepad++\updater\gup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\notepad++\updater\libcurl.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\sechost.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\credssp.dll
c:\windows\system32\schannel.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll

PID
4004
CMD
"C:\Program Files\Notepad++\notepad++.exe" "C:\Program Files\Notepad++\change.log"
Path
C:\Program Files\Notepad++\notepad++.exe
Indicators
No indicators
Parent process
npp.7.6.6.Installer.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Don HO [email protected]
Description
Notepad++ : a free (GNU) source code editor
Version
7.66
Modules
Image
c:\program files\notepad++\notepad++.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\version.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\program files\notepad++\scilexer.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\uxtheme.dll

Registry activity

Total events
629
Read events
451
Write events
174
Delete events
4

Modification events

PID
Process
Operation
Key
Name
Value
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\notepad++.exe
C:\Program Files\Notepad++\notepad++.exe
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Notepad++
C:\Program Files\Notepad++
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
DisplayName
Notepad++ (32-bit x86)
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
Publisher
Notepad++ Team
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MajorVersion
7
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MinorVersion
66
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
UninstallString
C:\Program Files\Notepad++\uninstall.exe
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
DisplayIcon
C:\Program Files\Notepad++\notepad++.exe
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
DisplayVersion
7.6.6
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
URLInfoAbout
http://notepad-plus-plus.org/
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
VersionMajor
7
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
VersionMinor
66
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
NoModify
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
NoRepair
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
EstimatedSize
8348
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSectionUsed
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_C
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_C++
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Java
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_C#
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_HTML
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_RC
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_SQL
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_PHP
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_CSS
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_VB
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Perl
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_JavaScript
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Python
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_ActionScript
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_LISP
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_VHDL
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_TeX
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_DocBook
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_NSIS
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_CMAKE
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_BATCH
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_CoffeeScript
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_BaanC
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Lua
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_AutoIt
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_NppExport
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_MimeTools
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Converter
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_AutoUpdater
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_PluginsAdmin
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_afrikaans
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_albanian
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_arabic
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_aragonese
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_aranese
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_azerbaijani
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_basque
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_belarusian
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_bengali
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_bosnian
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_brazilian_portuguese
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_breton
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_bulgarian
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_catalan
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_chineseTraditional
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_chineseSimplified
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_corsican
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_croatian
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_czech
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_danish
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_dutch
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_english_customizable
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_esperanto
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_estonian
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_extremaduran
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_farsi
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_finnish
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_french
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_friulian
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_galician
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_georgian
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_german
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_greek
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_gujarati
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_hebrew
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_hindi
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_hungarian
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_indonesian
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_italian
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_japanese
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_kannada
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_kazakh
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_korean
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_kyrgyz
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_latvian
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_ligurian
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_lithuanian
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_luxembourgish
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_macedonian
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_malay
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_marathi
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_mongolian
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_norwegian
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_nynorsk
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_occitan
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_polish
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_portuguese
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_punjabi
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_romanian
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_russian
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_samogitian
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_sardinian
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_serbian
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_serbianCyrillic
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_sinhala
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_slovak
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_slovenian
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_spanish
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_spanish_ar
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_swedish
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_tagalog
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_tajik
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_tamil
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_tatar
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_telugu
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_thai
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_turkish
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_ukrainian
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_urdu
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_uyghur
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_uzbek
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_uzbekCyrillic
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_vietnamese
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_welsh
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_kurdish
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_piglatin
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_zulu
0
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_BlackBoard
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Choco
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_HelloKitty
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_MonoIndustrial
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Monokai
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Obsidian
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_PlasticCodeWrap
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_RubyBlue
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Twilight
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_VibrantInk
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_DeepBlack
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_vimDarkBlue
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Bespin
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Zenburn
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Solarized
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Solarized-light
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_HotFudgeSundae
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_khaki
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_MossyLawn
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_Navajo
1
2776
npp.7.6.6.Installer.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Notepad++
MementoSection_explorerContextMenu
1
2744
regsvr32.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\ANotepad++
2744
regsvr32.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}\InprocServer32
2744
regsvr32.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}\Settings
2744
regsvr32.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}
2744
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}
ANotepad++
2744
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}\InprocServer32
C:\Program Files\Notepad++\NppShell_06.dll
2744
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}\InprocServer32
ThreadingModel
Apartment
2744
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}\Settings
Title
Edit with &Notepad++
2744
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}\Settings
Path
C:\Program Files\Notepad++\notepad++.exe
2744
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}\Settings
Custom
2744
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}\Settings
ShowIcon
1
2744
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}\Settings
Dynamic
1
2744
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}\Settings
Maxtext
25
2744
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\ANotepad++
{00F3C2EC-A6EE-11DE-A03A-EF8F55D89593}
2428
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2428
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
1336
notepad++.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
1336
notepad++.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1

Files activity

Executable files
15
Suspicious files
0
Text files
150
Unknown types
2

Dropped files

PID
Process
Filename
Type
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\LangDLL.dll
executable
MD5: ab1db56369412fe8476fefffd11e4cc0
SHA256: 6f14c8f01f50a30743dac68c5ac813451463dfb427eb4e35fcdfe2410e1a913b
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\updater\GUP.exe
executable
MD5: a32bc652f450d4e220cf4423b527ba36
SHA256: 4c8191f511c2ad67148ef809b40c1108aaa074130547157c335a959404d8d6f6
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\plugins\NppConverter\NppConverter.dll
executable
MD5: dc37dd0c47f64658c72c11dd51b7482e
SHA256: 8265cd47405453bb4cda63d350c0dffd70408ee23e8fb3394bee08a285d5031b
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\plugins\mimeTools\mimeTools.dll
executable
MD5: 05e93d7b999e49155d61d00b1deba545
SHA256: baaa72bf24911a5f14511d1b2ce31800b7288d575d4ae5c92cfb0b4b5cc73f98
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\UserInfo.dll
executable
MD5: 9eb662f3b5fbda28bffe020e0ab40519
SHA256: 9aa388c7de8e96885adcb4325af871b470ac50edb60d4b0d876ad43f5332ffd1
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nsDialogs.dll
executable
MD5: 466179e1c8ee8a1ff5e4427dbb6c4a01
SHA256: 1e40211af65923c2f4fd02ce021458a7745d28e2f383835e3015e96575632172
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\NppShell_06.dll
executable
MD5: c58106bc6bf213d84b4732869f71b444
SHA256: 190fb075a78b32ec5b7f38e1c80d1ac41e900f00cccf0f9feb2c5ee753313ca8
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\InstallOptions.dll
executable
MD5: 05bf02da51e717f79f6b5cbea7bc0710
SHA256: ca092ba7f275b0c9000098cdd1a9876fe8dc050fcb40a0e8a1ab8335236e9dc5
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\uninstall.exe
executable
MD5: 120b800cce40a24db4970b621b5fb039
SHA256: 0c3205783c1365cb2689523442ca6d1d8a46d5a3183251e5e6d56eeb6e890cfe
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\System.dll
executable
MD5: 0d7ad4f45dc6f5aa87f606d0331c6901
SHA256: 3eb38ae99653a7dbc724132ee240f6e5c4af4bfe7c01d31d23faf373f9f2eaca
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\plugins\Config\nppPluginList.dll
executable
MD5: 7e1295169b68dfcdd7f689ef576181cb
SHA256: a4a7e57d605f29b294378d0d94fc867b9febd6a1cc63f1bb69bcb7609dc25f2c
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\updater\libcurl.dll
executable
MD5: eb40183bdb2037b0d3e8f3b2e3b2181b
SHA256: 062a8baf2c799712a64ff160d8baf10e64e3d8cb5240e60783b4620b95b5b2d1
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\SciLexer.dll
executable
MD5: a23b9ddf9dc8fa69f29a97257605f74e
SHA256: 03c9177631d2b32de3d32c73a8841cf68fc2cb17f306825489dc3df98000db85
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\notepad++.exe
executable
MD5: 9f2b4ee36473c6f57157972a6a3fb97a
SHA256: 1e573140f4eb5ab3ca9b82b3db1bb80cb30b0218f7eefc159294b9b52c480a5c
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\plugins\NppExport\NppExport.dll
executable
MD5: 3b8903d6dce656df57b53056c662a31e
SHA256: 156228bff7a4f6711e7c82771beb3926d5f406566d5cdc6f0879fd128984b0d1
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\vietnamese.xml
xml
MD5: 4648aecae4e9d1df3ca32d9a0cba8fed
SHA256: 747d88fd1df6f7a703fdd0904b50ff32c3d6d2d26203e0ae07b44786b44a9961
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\urdu.xml
xml
MD5: cf965dfcf2257d8046c453ac36fcf65e
SHA256: 0b685abaea6232f3e99d563f01613161251e51aba6a62d83cb306aa5f2d396d5
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\telugu.xml
xml
MD5: a8b6a302f3bda0eeae95e5214df33ec4
SHA256: 82b4b16ee06e668e4ff30e71fcbf42623cf30dc14177c570a7ad1f47c0284e0c
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\uzbek.xml
xml
MD5: b4d6eb9fd0045e43cfabe6fdba4c1656
SHA256: 2df0099a05be6af1ff13b2240b2b4e120746449d0e8356fa36888e9addd9c864
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\tatar.xml
xml
MD5: 84c32874e0fbc009202c86781cf6a6b6
SHA256: 0b20a37e6512a5a3e0c92075db9eb179a156e5e20f9fe52c3260daf8c77825a3
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\ukrainian.xml
xml
MD5: 22f3220f8f1180b9b9c9730b99830430
SHA256: d98d84b3aeb19ca554e7b259343af8f31cb1025647fb859d638a6cbe3c2447b0
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\uyghur.xml
xml
MD5: a5d2661cab9fae284200b5cd84496b41
SHA256: f5d24a6c678b1b54539adeafd2bc2697738f44cea6c184fa442980f1440e5afd
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\tamil.xml
xml
MD5: abc0ae5ed0002512221d682263e41204
SHA256: e23759fd6d60ef9728b620a1a8316fc049ccbf93445a91a1a85d27c4e25f3f15
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\thai.xml
xml
MD5: 8d02b72cdcce6c5a4db56eebba394824
SHA256: 8ce450bcfd9b9617f4e0969ad4e201480b255d473cb1383c90761cc28cbd7ecc
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\uzbekCyrillic.xml
xml
MD5: 71b7ce4804f337f3d5c4fea4a0733691
SHA256: 380e17fd360658921ea937043e540b2af642a7307be691f5c58b825623b61a99
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\swedish.xml
xml
MD5: 3dd7cb019156fbfca56b9eb9c5ddf50a
SHA256: 053bbba683ea3d1d54602972495c90728a45a4affa10eb816cdba7e9494f3e72
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\spanish.xml
xml
MD5: ec6bf9f7b0dc3118f3aed59746687e81
SHA256: 59ff95c1b6f43bf76e85d08b4dbfafbb1d81bc659cbe3d30363ced368e9d8ea5
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\slovak.xml
xml
MD5: e56b5a5257bf4e743e9abb688b9e7215
SHA256: 52b86604adc29058a0efe7109857cc37cb452fd46f6210467543af2bf81b8b3e
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\tajikCyrillic.xml
xml
MD5: c28fc035726b0fe6f56c129d87c2aabc
SHA256: 70a7f699ee317a25cb74524995037b145477b4df0c39d674381ff5c8895fb63f
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\spanish_ar.xml
xml
MD5: e6e44ee7c6b6a0ff89f0fe490f3c11fc
SHA256: 2fadeca7c44132ef9a9243bd67eee23c93a25f96bc6c80b81d527d18128d284d
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\tagalog.xml
xml
MD5: 04e3e27d9d635c6b23c8e40dcbbdd442
SHA256: 047c63c449c5e2a9a4f97637c741eb07e6ec034bc829d85c6565bb0292c1cd72
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\samogitian.xml
xml
MD5: ebba131558f344afe63e1c5718d0f7ad
SHA256: 75eca9974de1fca41651975a92f374660e1a7c273a3d1dab0ef6dd573230878b
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\sinhala.xml
xml
MD5: 9986ce0334af5335ae8c7e5a3cbc818b
SHA256: a8b55a8115a50bd3b7b07c359c49fe7da48a5acf1dacc2c0e3708f6f48636fd6
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\serbian.xml
xml
MD5: 174e7dc367ff1c213432b891f11d25bb
SHA256: 1a07c6a9c2639fa12bb000f599498ddf84827449afbb7952f4bdc4cf526c2117
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\sardinian.xml
xml
MD5: 064889342004d04b1de62578aa733216
SHA256: 0169ebd43b3cec4a4f3b0143a2af6f07ec9bf73cb04882a3d4507f01931c08de
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\slovenian.xml
xml
MD5: cfa148c41f87a5877bd41c932d1fa9ee
SHA256: 5264e700e193129c25f864874ae69f89439a04517b1e7a30233bb70073f5eac3
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\serbianCyrillic.xml
xml
MD5: e6c94316e6d065533305b94e7d5af2bc
SHA256: 289d7cdd9d9af5b2992e3b0ac38022f91e3d9dc0051e40733983e26e2ddcf594
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\romanian.xml
xml
MD5: a05753edcaceaff2dfe5d6ee4d83bcdb
SHA256: 955898e29c7a7594e14800ab81f62c5764724b4b2d5869a08e64fff87702601d
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\piglatin.xml
xml
MD5: e57e7d60833241e6307f5666fb7682cc
SHA256: 1fec93f265e064820f37cc450b8cb8c60b9250bffb4bf1612a70e81527068010
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\russian.xml
xml
MD5: 7817e943a4add3ef56711215234410d9
SHA256: 4078636c1db889ed2f70833ee4ad397291f11a52f1737d091071070ce617b6c0
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\marathi.xml
xml
MD5: 40a6d310ece1419315c5e98fa1bcc966
SHA256: 907b949d2aa52365d84978a3c131bd2bad50227e6ecfd135ed112a8567628e25
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\nynorsk.xml
xml
MD5: 694867a6ade700da42a55da24da74200
SHA256: 319a9e846a610811fdf12b96bf352e4e07f2d7de5a6bec3000cebc1b1e21a1fe
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\punjabi.xml
xml
MD5: 1b2298a7b847f23751010f2b01e7a2ab
SHA256: e3e009b986ed53654ea1c89d828ba3998039db4fae20a877f097e41a2ebb7771
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\occitan.xml
xml
MD5: 282135aa211f86afebb1be689de3480c
SHA256: a65ef81488df5ddd0cdcc6e65be1b6992b79197fb7980740a750d2f5f5def463
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\polish.xml
xml
MD5: b6fe2b47e9118deeedba46078bad74d3
SHA256: aab6f7be1c52762cd91d7424adeec856beb2aead9051f62b2591657b82618681
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\norwegian.xml
xml
MD5: f5519b853316445aab668c1dfd480f87
SHA256: bb9a79755d37d449acff570c20e78a9e0c58482414435cf0f493e15e6216fce3
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\portuguese.xml
xml
MD5: bbdcaf6faf7f8548c07f2bb8e617a15e
SHA256: 80b8d3026279141c07722981cc3c6f356674099fd02b8f82b74104fe625e2236
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\mongolian.xml
xml
MD5: 7ff28b9242fe6bd774fcd71fbed5563d
SHA256: 5d35c3c2f10b6f6923c0b11bd7d82f569ba6a0a8fb854aac20988c77d35bf934
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\malay.xml
text
MD5: 3158e10e8a9b3c0e84a770f5f11aaa1f
SHA256: 690416e418c9821bfe71805f76d9e18ee39fd092742d173cc9fe595268b131fa
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\kabyle.xml
xml
MD5: ec924dd39f1e36164ef4e93cd5883a2d
SHA256: 56714b11409a13fcd706f2d73674919a0bb70c80c7ec18eccf865ad67ad7b48f
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\kurdish.xml
xml
MD5: 713c7613217038dead56ba13741d70b5
SHA256: 6a54a7235f8f4cbf5cb4c34f6bdf0bf9ee0d7e3ac62654d5c46e2fdf71868593
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\ligurian.xml
xml
MD5: 58a86031153e6bd8ae1ad5bf80fcc894
SHA256: 5fad85ea1c785dca218106e2b409c20b3cb103e8cdc87c542aae5d630599c33b
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\kannada.xml
xml
MD5: f0baf174376d1811fd49d05ace8eb0c6
SHA256: 99f75ff79aad8084802bf1d52e7dc78eef18194d399c5248eb205db85348955d
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\japanese.xml
xml
MD5: 76e62d9c62bea373eb90bebf31da09e8
SHA256: 5333dbb1359c8428750442aa18279a4eb1f72e4568f1d43a4c2277ca825a5420
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\korean.xml
xml
MD5: a81c00ae49aeb5c5ded60220e6e42199
SHA256: 50b2b6820683551838ea1533d21624dac75daded6ce9d4227153a4f2986cdf4d
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\indonesian.xml
xml
MD5: 258f097d09f9878310e7900bb35cbff3
SHA256: bf7292893bd1700d22e328c4b542929122a027e504a179d7270637e5476befe5
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\kyrgyz.xml
xml
MD5: ad3a31d477ad1e09dc3f6911c1f50d1e
SHA256: 4964c0b9f36b7fec44ec0805ba153d88293311cd703680719187cdaa68fbd090
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\macedonian.xml
xml
MD5: 59f590ee75294f37ccb5ed1c7a441a11
SHA256: 59dbcc4618fa64eebd71808b16b4736b7af8855bef760aec3eb31c6f8f5f470e
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\latvian.xml
xml
MD5: 170d9e9a92a604a309259d3d6f3b9bb6
SHA256: bbaa6bc087ab351b182d204a60eab8bc93bd5e75ca2a4a4eaf80b1d5e0fec59b
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\lithuanian.xml
xml
MD5: 98f5a618f8cf3ca48774c15ca95bc2bb
SHA256: fb94b9381592015b27e12358c44a522409ec5c180fec694b2ddceff960294d0c
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\luxembourgish.xml
xml
MD5: cc2d7d26c9d221def534845ec7453ddb
SHA256: b73cb0703537af9d58c2e1f040f2e7f741199eef954d5e109eb301fc4498ffe0
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\italian.xml
xml
MD5: 384f12abbc790c175e57f873f3becfb2
SHA256: 500cfbf34b04f1299e61fe1473b73e0963024c53e6435e719b23298138d1d338
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\kazakh.xml
xml
MD5: 42d3d22d81645a44258aa730177896db
SHA256: 3942e9c344acae7caa9d28a758b4df80c1211bab80ac88d81449101f9b943c66
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\hindi.xml
xml
MD5: f2926d2f1b4ebcd8d66b8ed0a3490763
SHA256: 22fa20d7c7d0f4f51574ae03bdd1e43c6d35b44242d72d65bec23f5a01164248
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\friulian.xml
xml
MD5: 6d4c069b4c4517f68657be1641bec299
SHA256: d4ffe0a2b5e35fede7e6244be9823e1e946c60db1635e6d3f753e6df938e4b3d
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\finnish.xml
xml
MD5: 99d18eeaa47569147a0395948cb9c7d6
SHA256: 691d523b2a8c2ea14eb5e5259eed9e9de1853b2c2fd8badc77164f2cca2dd006
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\farsi.xml
xml
MD5: 9ddc0ac1e17a56703a3e0a7acb8d0e2a
SHA256: d0acda01c7bb500072f00af882297d08a14821811931e862b5225bef97ab6336
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\german.xml
xml
MD5: 355b310c4e264a059f7ace7bf26ed8fa
SHA256: 95ebc8459d0c7e217e45a2062221832d0bae29eca359ec38b2e450913d16590e
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\french.xml
xml
MD5: 29c2371f2e3575f2be5ae6f5920d0662
SHA256: 0a07a3c4c7babb5f751a984b0f9da58f1ab3ba639ee935fc109ba5844bec2238
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\gujarati.xml
xml
MD5: 5e8d9609900189b29b660d673a78e015
SHA256: 50c0e7a18c922bef1a758cff70d55df46913dddc22ca792e1b55b05a5b29c502
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\hungarian.xml
xml
MD5: b49cd98b5a75f5a2320427653a1a1782
SHA256: 951a0bd8e663bf9a43dbc7e083d7de92defab68836a07422033e4915765b1a86
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\galician.xml
xml
MD5: 191cc6b7ed37fad274f985d7329bd048
SHA256: 89a20e547d17b1006698cd35fbad772403033420808c8299206a8e299961d83e
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\georgian.xml
xml
MD5: cada78594c9838103c479dbda55c9e05
SHA256: b319b96cb4eece88c0cf88b557ce56ce5abe85bdf0a6a1007b64310a708a6572
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\hebrew.xml
xml
MD5: 07c8ebe76b6352401c0e9c84956d727f
SHA256: 58585868a8164b247c53ad3646076e3404a4fd854ee3632ca9841c1ba3d210d6
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\greek.xml
xml
MD5: 109f64488a006665d76621dcd30e7ef7
SHA256: d65afc086673dc165ce82dd831b5f04c75d7d43c50957475e1c90f25766ad5da
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\extremaduran.xml
xml
MD5: 896b0f1f0854f3bcc23a80c99dcebd47
SHA256: 87e0372bfd2b84316adf2c7d3130fcf2415a96ec2c8bcd5da6f1a8a3a807c8d2
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\english_customizable.xml
xml
MD5: ba660fd5e124a627e7b5b1d53a6ceae5
SHA256: db1c55427bf83385e8713460d515d05aa79b9829be85515f1e46ab1a2cdc198b
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\czech.xml
xml
MD5: 033511f11412f9d0350d2ff2dd70f57f
SHA256: c333179dd5c26d9264b4dd6414baf3278b0049e1eadac107224fa5a34db8421a
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\english.xml
xml
MD5: 03abae43e8e53d9594ced22fdb09965f
SHA256: 6472da400162dc1aecba34146ab92c4d59be1b3629f72ca1e91b9e7d57e667eb
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\danish.xml
xml
MD5: afdca23414d2fa05e0edfed63dc68bd1
SHA256: 3ce52cb27a70640c8f4578ff52f71de18282d54ab91d1db7658be64c6a316d6c
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\corsican.xml
xml
MD5: 2762c8551adc0138beb86c304bd678df
SHA256: 9cc651eca1140c53634b1106a00bf8df96c8b4db49b68dbf165e1feae0740ee5
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\estonian.xml
xml
MD5: a12e2854f772938fd4ccd55345dadd4b
SHA256: f71e4b0ba4fbf616af8f1568f2160d527b78fcf711132c4a38e0bd5378902237
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\esperanto.xml
xml
MD5: 4abf56d03e149ee0569619bbc11815a5
SHA256: e1486a8120d1ef7998b5335536a3a4877fdcb630f87ed9ca7b307ac075b313c6
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\croatian.xml
xml
MD5: 93e193e4ba3b43a8ee9f448819f9fc02
SHA256: 3a1c365a7a66dae03b9d2dc5b2368647ddea54fb1978b5d014fa71464d9ce9c9
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\dutch.xml
xml
MD5: 6ce9f0ae41286f01ccf83b64d48cc238
SHA256: 4dc9faf1ba2806b6ff3f70264c46e2d70007af6f5dafe6fe9d306c3c07eda610
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\chinese.xml
xml
MD5: 95c0eacb92d19a56ad3e9f114355b891
SHA256: 6a6b8625fbe38f8ecd5f8205cefa66a7fb31c17826766c29dfc4494bf71602ad
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\brazilian_portuguese.xml
xml
MD5: c5ac706ffe3cc6abb54272e49d42de5d
SHA256: 690897901b9880c4b4247d5a75140f4ef9804fddd4b1ffe6fbc89d4f9952e520
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\breton.xml
xml
MD5: a28d31b3147d47670455aa249df9e3a8
SHA256: 7d8569dca0eef5ccd411287ed72f70da19f92b96e05e2bfd294263098e3ed38d
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\chineseSimplified.xml
xml
MD5: 7a938d0a8a95b9bd6654e300e7917cf6
SHA256: 7539a0d80c578be28b1a99fcbc26365ed9ff3740095ae70c52da7fbf41497eb5
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\basque.xml
xml
MD5: 7ef1dd1b3280122bac0a69063249fd46
SHA256: 1047a56b9ea18bafbb7fd03daa190cb980883694dfd7fc1556136ab81834d489
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\catalan.xml
xml
MD5: 41dd1e49aec41c8e6e3304703584cb11
SHA256: 21c78bef317e8b067b11083d13113996fd6f1cb06a58e08bd4a2dfa7df57a7ce
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\azerbaijani.xml
xml
MD5: 8cd5c70b03ef9c48585c06fa149f9fcd
SHA256: d2e185e9c8b1e7d994dcb3b44748f1b499f18ca22a573f452a9b0d791344c448
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\bengali.xml
xml
MD5: d081b39bf7a87b8ccd3caa5e9d15087c
SHA256: 5ecd5febabcb4b4616035fab1b567bf2a0ff8b2ded72d74e6ea5511671814484
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\bulgarian.xml
xml
MD5: fc93e8a36720f46bee96051536aee171
SHA256: ca754df6ff0266e2b1e4a8ad0123c610729a5971a7f0fa01184192744e8c6362
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\belarusian.xml
xml
MD5: fd060d45654fa3adec00f943349a535b
SHA256: 1c616bcd978b6f7feb5035c232024baa895f9787183898e4672f70ea3d1ded9c
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\arabic.xml
xml
MD5: 4c43fa51c53e259e9c0df42eab235849
SHA256: f4bb70b47614e639d2035ecf94e4f74413312f7ae593d60a916d940cf3639554
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\aragonese.xml
xml
MD5: ff161db746ade330439882ba0640d2ea
SHA256: 1db8eeb9c6cae8705cacfc3043a7556678e9ed52162fb8ec536c5befc19343a9
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\bosnian.xml
xml
MD5: 6b036835ed9d1ee92cd9bd4c76f41bbd
SHA256: 06ce39e85fc9acd72888da5871fae4d18aa2c5bb6a9fa0c9eca459cf0e949a63
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\aranese.xml
xml
MD5: 333a18acb93ba083e86679c065b69d15
SHA256: de5da809aa6e44c4e6a01c3b5fb7da5a66d9683cb905416f3fcff2ed413ea7c6
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\albanian.xml
xml
MD5: 5803d49d9a1320f50394a0ab36c427b6
SHA256: 508ddd0bd359666186a34b1249b55de31062f2eb4323bce01409e602e7fc0b64
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\afrikaans.xml
xml
MD5: c2f475cc2b49d3aee490c9059529744a
SHA256: 5d285d98f8891bcf73a770fde00c3215062842224b81c4e70537569712f84570
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Roaming\Notepad++\userDefineLangs\userDefinedLang-markdown.default.modern.xml
text
MD5: e6edb9c859b5b97800da9c664a0606c8
SHA256: b7a3e70c69f661e76cc7b6279db21fb32f275a8a3c205a75ae22e40224136031
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\localization\english.xml
xml
MD5: 03abae43e8e53d9594ced22fdb09965f
SHA256: 6472da400162dc1aecba34146ab92c4d59be1b3629f72ca1e91b9e7d57e667eb
1336
notepad++.exe
C:\Users\admin\AppData\Roaming\Notepad++\stylers.xml
xml
MD5: cb27bdda10cb78aa57032f34f0edc3a2
SHA256: fb189953648780dd1d038c918d6165b72fdab0499170eec63cf961a9e68ed165
1336
notepad++.exe
C:\Users\admin\AppData\Roaming\Notepad++\langs.xml
xml
MD5: deba762778514d26e433c3bd45405c3f
SHA256: 9911d492e66e1e02c010fb8d17231e6d4803fcf038866ac40e38520f72fe505a
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\contextMenu.xml
xml
MD5: a7998766b85ee71ff1d82a1198988529
SHA256: aa48a7c2ec3ed377c42c293f732807572f2ea305c9771b6ea210e7b92ef2c199
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\LICENSE
text
MD5: 397ad6fd5743ecc1826add6ea0fb0af4
SHA256: b2a74140769dc8bd34cb72bd2d177e58522e69427f39651b738011f244f835bd
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\functionList.xml
xml
MD5: bd8d804a62a5b9392885a6904033f0bf
SHA256: ea1e92c06735a137cd03c36a252027c013e9224dd3013fbe3ddd5c5c0098b2b9
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\readme.txt
text
MD5: 5c52adcd2bcc000a8b4bd5eb36b84cde
SHA256: f09758a2c953bdd2b817441e9a00255d3685c99369468c2695f0ca39aaaa5e6b
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\change.log
text
MD5: be689f76d411260200ffec6fa81a3ba9
SHA256: d3bc95d6b69b496c24f1a75ea17d668275a453496ca59e00163392a001831b1a
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\stylers.model.xml
xml
MD5: cb27bdda10cb78aa57032f34f0edc3a2
SHA256: fb189953648780dd1d038c918d6165b72fdab0499170eec63cf961a9e68ed165
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\langs.model.xml
xml
MD5: deba762778514d26e433c3bd45405c3f
SHA256: 9911d492e66e1e02c010fb8d17231e6d4803fcf038866ac40e38520f72fe505a
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsy4635.tmp
––
MD5:  ––
SHA256:  ––
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\ioSpecial.ini
text
MD5: 616d00b6984458bd0c1399521325f2e1
SHA256: af0abad769cce2fe3cbd9c182dfca8ee31ed30f38c288e0e67ce1bee1650888b
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\updater\LICENSE
text
MD5: 8e3494bf8cf1967afd3b1016fbbe5bb0
SHA256: 319917f5ccd09878db6f67c9a77dee846055644ca49eb535628b9e020a87261e
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\updater\README.md
text
MD5: 9f56b12cbffcfad543fb1f91e3955f1b
SHA256: aef40520cf12a0842097e8cfbeb9d9128f52573e5f90ca12d4a0a9045978547e
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\updater\gup.xml
xml
MD5: b023cc4d768b34a5401f317479740a53
SHA256: d3e6404c7286961cbab82d4c49f82bcb166db9b5a13eacaa0eeb59a0709a0c14
1336
notepad++.exe
C:\Users\admin\AppData\Roaming\Notepad++\plugins\Config\converter.ini
text
MD5: f70f579156c93b097e656caba577a5c9
SHA256: b926498a19ca95dc28964b7336e5847107dd3c0f52c85195c135d9dd6ca402d4
2776
npp.7.6.6.Installer.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++.lnk
lnk
MD5: 9369013c6f4b35bd1d3e31f537b7f591
SHA256: aa43b0a4d39abec02e154581514b5e69e046117fca49914b500363427ebfa9a3
2776
npp.7.6.6.Installer.exe
C:\Users\Public\Desktop\Notepad++.lnk
lnk
MD5: b60c2a23fca292f01c026d8c50367e6d
SHA256: df8c554c97efc18ce081bd61f08e821c362b82979bd210515765346283e3616b
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\welsh.xml
xml
MD5: 538acafd2ef4e67581a908f970838626
SHA256: 11fd56a75e14493a7305d6cd2aa79dd6990465eb0dec8bdf6354dd6e5db35634
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\autoCompletion\autoit.xml
xml
MD5: 24091974377d7e76106add1210d5853a
SHA256: 07cb7ea3f8d1eee1142bcdf876e29f14e6ae2a72ef28f2310263da531c7e8711
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\autoCompletion\lua.xml
xml
MD5: bdb4f044ba52f6a83953ffd659c9252a
SHA256: 3daa67cc9dd0370566566ce0492597a3698b7d9edd361a759c58e1fbd7abb349
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\autoCompletion\BaanC.xml
xml
MD5: 2537a01a4619a19962fb1b85cbee9a13
SHA256: 9780d21f36eca4cb7f85c67fe9113c3c223822662812f6ab533c011cd2f56e7e
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\autoCompletion\cmake.xml
xml
MD5: bb3c098e3c76d30df480e3e17abe5a7b
SHA256: b5616caa363cd62310287f60e6c61eeed9297be5d2da913a390fedc26217cae0
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\autoCompletion\batch.xml
xml
MD5: 713831a4916810500b39efbdb41435a2
SHA256: d43ce011aa2d5a946c36b4c3a6a0a98fd9570253bc461a267d3b44aaec3cb6b0
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\autoCompletion\coffee.xml
xml
MD5: 633f1e56a9f5b7e1c7c75e6dff944b25
SHA256: 46d379e7ad5565fc197a32b62d04ceb1be4452af2ae45663415809bc7badb0bd
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\autoCompletion\xml.xml
xml
MD5: 432b0a7d34b59ad7512c347f8670ff23
SHA256: 7cdfb59901b0dbda488745f9bd749ce9a1c3e228931162e3a5764c5674330601
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\autoCompletion\nsis.xml
xml
MD5: 7985ac923ccbf94742d29d96c405c843
SHA256: 5c1482f16fc8a1b99ec87eb4edef5c1d3f2d1c750f1647416369c6124498ad3e
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\autoCompletion\tex.xml
xml
MD5: 03f74d2063099160e73faa1a5dee7f9a
SHA256: d19fe5a6b68b50e0820641489fd73368ba4ba58adb07948e39073ddce8e08d37
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\autoCompletion\actionscript.xml
xml
MD5: f8876462309eeb4204eaaf5777dc4eea
SHA256: 7bdab6f3b572773331a17bfbb6cc4bbd71dfd89e4f11e404b7466925678a3a26
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\autoCompletion\python.xml
xml
MD5: 7bedd66d0b8a71da1467f63db6184420
SHA256: cc27e0ea6542eb7bb249d169f42f9ac6fcbb794c2ef5d85f2b502e124ceef916
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\autoCompletion\lisp.xml
xml
MD5: 310ae71e554b99a4c71b546097de55c0
SHA256: 83478867f319bf093ce02f0c98a88b183862c235025580cca9ec7a9515521833
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\autoCompletion\vhdl.xml
xml
MD5: 1ba07e9e9c7ccbf095fee8c248375527
SHA256: 29967c6650ce9fce73b7b9dda3390ae3b5cff4ad8ef2265f2c6980da55f42f97
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\autoCompletion\php.xml
xml
MD5: 1e9d31476dddc00249463ede7ba491d7
SHA256: 43391307f2829b77df05725a13670f6ad0650f8b92b4503cba65d7901e1dda10
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\autoCompletion\css.xml
xml
MD5: d2affd6da8aa4fd9457db7b0dcb87517
SHA256: 776187ab9beec87648e5701137f153adeef88c579b15b181c5d4eee2f02262f8
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\autoCompletion\vb.xml
xml
MD5: cb6d0cff9916fa1eae0a4faafc9db82a
SHA256: 74b6701e0c8f2c92eedd563165b61d4813f519f3747b67b3a043a4b85de41401
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\autoCompletion\perl.xml
xml
MD5: 244eb5c1e91dc112130252fe58e49b13
SHA256: e38a882b09330b6dbd56a2a4a90882c371a3c3eb7d29ceae9520a647c185b627
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\autoCompletion\javascript.xml
xml
MD5: 30fc91a7c5194ef8d67e1c7e2fd6f697
SHA256: 7f0564f983478207754a58e66ee6865b8699bd3b9f4fd5c385126d46d7148831
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\autoCompletion\html.xml
xml
MD5: 4025e1158c027cf56c2625e65eb724ec
SHA256: 4300b3a71f387c91548984d017033884e176546ad5b74bac2e4df59caa163530
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\autoCompletion\sql.xml
xml
MD5: 056b92b4d2e16984505990cf379b5486
SHA256: 620fe159db5ce323b78b4768f9f6a3a95ca2c4fa4806ea5145afadac21dcc74d
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\autoCompletion\rc.xml
xml
MD5: 12b972b69130e664e50ac111d298379b
SHA256: 12ad067aa1227b92141bbf9faca8efa74549cff6dabde85899db9272eb7e2dff
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\autoCompletion\java.xml
xml
MD5: 4690cead3d2bffe2ed519f6ea5002266
SHA256: 862a83be2906ce28b6d3f1fdfb589d18cd6e971a7eaa51a1c7096cfff929b35b
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\autoCompletion\cs.xml
xml
MD5: c9bc2acde59532d2a9b65e7f9cd55d4f
SHA256: 32076a244afd75a07cd38f1fa27b08eea3a4a697111cde8a1cb636c46c708c17
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\autoCompletion\cpp.xml
xml
MD5: e60ca42b12a8e816892894d321ab8d00
SHA256: b97ffa556f93ec4c51208b2aea4f3d69411404c27f6ea12608ae84bedbd76418
2776
npp.7.6.6.Installer.exe
C:\Program Files\Notepad++\autoCompletion\c.xml
xml
MD5: c92c0a8fa14eb590fdc13287b26689db
SHA256: 2ad09d23098049d7541c703684bca446ccf6f1024a182e7dc30c378efb1b2109
1336
notepad++.exe
C:\Users\admin\AppData\Roaming\Notepad++\shortcuts.xml
text
MD5: ad21a64014891793dd9b21d835278f36
SHA256: c24699c9d00abdd510140fe1b2ace97bfc70d8b21bf3462ded85afc4f73fe52f
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\ioSpecial.ini
text
MD5: 5493f232d5420079982ffe0d5c3f12c3
SHA256: b625c41ea125ec99e562a9bff1df144779261af59830afe37d84c098a3eba613
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\ioSpecial.ini
text
MD5: 92b2997b53376bae1bc75e4fa1003e63
SHA256: ed542b95423a4569ce1e8edbbdec552ea82bd2a286be66a08762b2400815a5d8
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\modern-wizard.bmp
image
MD5: c2cf6928a3ab574a5548b4dc1c38b6c0
SHA256: 2125550c12fa512782f2016e802d70bc51f4a06017cfbd4176b4a994eb2542f0
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\modern-header.bmp
image
MD5: 56da15fdb8d96f8f5c649dcb5e79d775
SHA256: bb90d4338d2474138473e6b16e94b0237ee847bea45019ed0dd4439c71bd233e
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\zulu.xml
xml
MD5: 9440a55f71dac040b123de16d6557951
SHA256: 16ef44efd21a556cfed5aa07b70437a16016754fcd3ce2a9e7048061716591df
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\nppLocalization\turkish.xml
xml
MD5: 71917c8e37640e6a446596169a51bdb0
SHA256: f43bdf1b4d8967252ab47eda4b49c23a291e6d947213f77e987ad4cfa999197a
2776
npp.7.6.6.Installer.exe
C:\Users\admin\AppData\Local\Temp\nsd4655.tmp\ioSpecial.ini
––
MD5:  ––
SHA256:  ––

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
0
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

No HTTP requests.

Connections

PID Process IP ASN CN Reputation
2736 gup.exe 37.59.28.236:443 OVH SAS FR whitelisted

DNS requests

Domain IP Reputation
notepad-plus-plus.org 37.59.28.236
whitelisted

Threats

No threats detected.

Debug output strings

No debug info.