General Info

File name

washandgo.exe

Full analysis
https://app.any.run/tasks/f3aad629-5b2b-41b8-8cb8-97aef2eb75e8
Verdict
Malicious activity
Analysis date
12/3/2019, 01:01:32
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

dd9c5b19388a94122b2ee73052a74fab

SHA1

b04f12972af50cba5f94e2f0f6572489375fcf82

SHA256

acf76d0f3e7e1d385f808d6641674a9fb0a40cb5af7d4d6be2a7e8d37415a3f9

SSDEEP

393216:o9sV3nQt83YuJ8fF7YpFX/GnPPR84qgMDYb/vIizoeLHByuY8E2Jmi8/i0YNEzUw:o9ON3YrYLOPHbM4/vfyoEk4/i10Uc9b

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
300 seconds
Additional time used
240 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (75.0.3770.100)
  • Google Update Helper (1.3.34.7)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.7.2 (4.7.03062)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Groove MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office IME (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office IME (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Language Pack 2010 - French/Français (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - German/Deutsch (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Italian/Italiano (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Japanese/日本語 (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Korean/한국어 (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Portuguese/Português (Brasil) (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Russian/русский (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Spanish/Español (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Turkish/Türkçe (14.0.4763.1013)
  • Microsoft Office O MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Arabic) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Basque) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Catalan) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Dutch) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Galician) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (German) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Proof (Ukrainian) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (French) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (German) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office SharePoint Designer MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office X MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (14.21.27702.2)
  • Microsoft Visual C++ 2019 X86 Additional Runtime - 14.21.27702 (14.21.27702)
  • Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.21.27702 (14.21.27702)
  • Mozilla Firefox 68.0.1 (x86 en-US) (68.0.1)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • Update for Microsoft .NET Framework 4.7.2 (KB4087364) (1)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB4019990
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads dropped or rewritten executable
  • WashAndGo.exe (PID: 1752)
  • WashAndGo.exe (PID: 2984)
  • AbLauncher.exe (PID: 3868)
  • AbLauncher.exe (PID: 2988)
  • AbLauncher.exe (PID: 3152)
  • WashAndGo.exe (PID: 2868)
  • WashAndGo.exe (PID: 2424)
  • AbLauncher.exe (PID: 2820)
  • WashAndGo.exe (PID: 2400)
  • WashAndGo.exe (PID: 1904)
  • AbLauncher.exe (PID: 3024)
  • AbelssoftPreloader.exe (PID: 2080)
  • regsvr32.exe (PID: 2532)
  • WashAndGo.exe (PID: 3912)
Application was dropped or rewritten from another process
  • WashAndGo.exe (PID: 1752)
  • unins000.exe (PID: 4068)
  • _iu14D2N.tmp (PID: 2676)
  • closeapp.exe (PID: 1820)
  • WashAndGo.exe (PID: 2984)
  • AbLauncher.exe (PID: 3868)
  • WashAndGo.exe (PID: 2868)
  • WashAndGo.exe (PID: 2924)
  • WashAndGo.exe (PID: 2424)
  • AbLauncher.exe (PID: 2988)
  • WashAndGo.exe (PID: 3036)
  • AbLauncher.exe (PID: 3152)
  • AbLauncher.exe (PID: 3024)
  • WashAndGo.exe (PID: 3272)
  • WashAndGo.exe (PID: 1904)
  • WashAndGo.exe (PID: 2400)
  • AbLauncher.exe (PID: 2820)
  • AbelssoftPreloader.exe (PID: 2080)
  • WashAndGo.exe (PID: 3912)
Loads the Task Scheduler DLL interface
  • AbelssoftPreloader.exe (PID: 2080)
Changes settings of System certificates
  • WashAndGo.exe (PID: 3912)
Registers / Runs the DLL via REGSVR32.EXE
  • washandgo.tmp (PID: 1636)
Searches for installed software
  • WashAndGo.exe (PID: 1752)
  • washandgo.tmp (PID: 3056)
  • WashAndGo.exe (PID: 2400)
  • WashAndGo.exe (PID: 3912)
Reads Environment values
  • WashAndGo.exe (PID: 1752)
  • WashAndGo.exe (PID: 2400)
  • WashAndGo.exe (PID: 3912)
Executable content was dropped or overwritten
  • unins000.exe (PID: 4068)
  • washandgo.tmp (PID: 3056)
  • washandgo.exe (PID: 2184)
  • washandgo.exe (PID: 3172)
  • washandgo.exe (PID: 3192)
  • washandgo.exe (PID: 4040)
  • washandgo.tmp (PID: 1636)
Starts application with an unusual extension
  • unins000.exe (PID: 4068)
Reads the Windows organization settings
  • _iu14D2N.tmp (PID: 2676)
  • washandgo.tmp (PID: 3056)
  • washandgo.tmp (PID: 1636)
Starts itself from another location
  • unins000.exe (PID: 4068)
Reads Windows owner or organization settings
  • _iu14D2N.tmp (PID: 2676)
  • washandgo.tmp (PID: 3056)
  • washandgo.tmp (PID: 1636)
Creates files in the user directory
  • AbelssoftPreloader.exe (PID: 2080)
Creates files in the Windows directory
  • AbelssoftPreloader.exe (PID: 2080)
Creates COM task schedule object
  • regsvr32.exe (PID: 2532)
Adds / modifies Windows certificates
  • WashAndGo.exe (PID: 3912)
Reads settings of System Certificates
  • WashAndGo.exe (PID: 1752)
  • WashAndGo.exe (PID: 2400)
  • WashAndGo.exe (PID: 3912)
Loads dropped or rewritten executable
  • washandgo.tmp (PID: 3056)
  • washandgo.tmp (PID: 1636)
Application was dropped or rewritten from another process
  • washandgo.tmp (PID: 3056)
  • closeapp.exe (PID: 292)
  • washandgo.tmp (PID: 2336)
  • closeapp.exe (PID: 3828)
  • closeapp.exe (PID: 2004)
  • closeapp.exe (PID: 1532)
  • washandgo.tmp (PID: 1636)
  • washandgo.tmp (PID: 2380)
Application was crashed
  • WashAndGo.exe (PID: 2424)
  • WashAndGo.exe (PID: 2984)
  • WashAndGo.exe (PID: 2868)
  • WashAndGo.exe (PID: 1904)
Manual execution by user
  • washandgo.exe (PID: 2184)
  • AbLauncher.exe (PID: 3868)
  • AbLauncher.exe (PID: 2988)
  • AbLauncher.exe (PID: 3152)
  • AbLauncher.exe (PID: 3024)
Creates a software uninstall entry
  • washandgo.tmp (PID: 1636)
Creates files in the program directory
  • washandgo.tmp (PID: 1636)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable (generic) (42.6%)
.exe
|   Win16/32 Executable Delphi generic (19.5%)
.exe
|   Generic Win/DOS Executable (18.9%)
.exe
|   DOS Executable Generic (18.9%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2018:06:14 15:27:46+02:00
PEType:
PE32
LinkerVersion:
2.25
CodeSize:
66560
InitializedDataSize:
227328
UninitializedDataSize:
null
EntryPoint:
0x1181c
OSVersion:
5
ImageVersion:
6
SubsystemVersion:
5
Subsystem:
Windows GUI
FileVersionNumber:
1.0.0.0
ProductVersionNumber:
1.0.0.0
FileFlagsMask:
0x003f
FileFlags:
(none)
FileOS:
Win32
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
Neutral
CharacterSet:
Unicode
Comments:
This installation was built with Inno Setup.
CompanyName:
Abelssoft
FileDescription:
WashAndGo 20
FileVersion:
1.0.0.0
LegalCopyright:
Copyright by Abelssoft
ProductName:
WashAndGo
ProductVersion:
1.0.0.0
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
14-Jun-2018 13:27:46
Detected languages
English - United States
Comments:
This installation was built with Inno Setup.
CompanyName:
Abelssoft
FileDescription:
WashAndGo 20
FileVersion:
1.0.0.0
LegalCopyright:
Copyright by Abelssoft
ProductName:
WashAndGo
ProductVersion:
1.0.0.0
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0050
Pages in file:
0x0002
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x000F
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x001A
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x00000100
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
8
Time date stamp:
14-Jun-2018 13:27:46
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x0000F25C 0x0000F400 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.37588
.itext 0x00011000 0x00000FA4 0x00001000 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 5.77877
.data 0x00012000 0x00000C8C 0x00000E00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 2.30283
.bss 0x00013000 0x000056BC 0x00000000 IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.idata 0x00019000 0x00000E04 0x00001000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 4.59781
.tls 0x0001A000 0x00000008 0x00000000 IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.rdata 0x0001B000 0x00000018 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 0.204488
.rsrc 0x0001C000 0x000356C0 0x00035800 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 5.57921
Resources
1

2

3

4

5

6

7

8

4091

4092

4093

4094

4095

4096

11111

CHARTABLE

DVCLAL

PACKAGEINFO

MAINICON

Imports
    oleaut32.dll

    advapi32.dll

    user32.dll

    kernel32.dll

    comctl32.dll

Exports

    No exports.

Screenshots

Processes

Total processes
90
Monitored processes
32
Malicious processes
19
Suspicious processes
2

Behavior graph

+
drop and start start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start washandgo.exe washandgo.tmp no specs washandgo.exe washandgo.tmp closeapp.exe no specs closeapp.exe no specs regsvr32.exe no specs washandgo.exe abelssoftpreloader.exe no specs ablauncher.exe no specs washandgo.exe ablauncher.exe no specs washandgo.exe no specs washandgo.exe ablauncher.exe no specs washandgo.exe no specs washandgo.exe ablauncher.exe no specs washandgo.exe no specs washandgo.exe ablauncher.exe washandgo.exe washandgo.exe washandgo.tmp no specs washandgo.exe washandgo.tmp closeapp.exe no specs closeapp.exe no specs unins000.exe _iu14d2n.tmp no specs closeapp.exe no specs washandgo.exe
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
4040
CMD
"C:\Users\admin\Desktop\washandgo.exe"
Path
C:\Users\admin\Desktop\washandgo.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Abelssoft
Description
WashAndGo 20
Version
1.0.0.0
Modules
Image
c:\users\admin\desktop\washandgo.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\version.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shell32.dll
c:\users\admin\appdata\local\temp\is-13n6l.tmp\washandgo.tmp

PID
2380
CMD
"C:\Users\admin\AppData\Local\Temp\is-13N6L.tmp\washandgo.tmp" /SL5="$5012C,27247777,294912,C:\Users\admin\Desktop\washandgo.exe"
Path
C:\Users\admin\AppData\Local\Temp\is-13N6L.tmp\washandgo.tmp
Indicators
No indicators
Parent process
washandgo.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\users\admin\appdata\local\temp\is-13n6l.tmp\washandgo.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll

PID
3192
CMD
"C:\Users\admin\Desktop\washandgo.exe" /SPAWNWND=$40126 /NOTIFYWND=$5012C
Path
C:\Users\admin\Desktop\washandgo.exe
Indicators
Parent process
washandgo.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Abelssoft
Description
WashAndGo 20
Version
1.0.0.0
Modules
Image
c:\users\admin\desktop\washandgo.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\version.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shell32.dll
c:\users\admin\appdata\local\temp\is-mgcub.tmp\washandgo.tmp

PID
1636
CMD
"C:\Users\admin\AppData\Local\Temp\is-MGCUB.tmp\washandgo.tmp" /SL5="$40128,27247777,294912,C:\Users\admin\Desktop\washandgo.exe" /SPAWNWND=$40126 /NOTIFYWND=$5012C
Path
C:\Users\admin\AppData\Local\Temp\is-MGCUB.tmp\washandgo.tmp
Indicators
Parent process
washandgo.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\users\admin\appdata\local\temp\is-mgcub.tmp\washandgo.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\bcryptprimitives.dll
c:\users\admin\appdata\local\temp\is-nalmj.tmp\isxdl.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\msi.dll
c:\users\admin\appdata\local\temp\is-nalmj.tmp\closeapp.exe
c:\windows\system32\imageres.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\programdata\abelssoft\washandgo\program\system.data.sqlite.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\program files\washandgo\ablauncher.exe
c:\windows\system32\regsvr32.exe
c:\programdata\abelssoft\washandgo\program\washandgo.exe
c:\programdata\abelssoft\washandgo\program\abelssoftpreloader.exe
c:\windows\system32\netutils.dll

PID
2004
CMD
"C:\Users\admin\AppData\Local\Temp\is-NALMJ.tmp\closeapp.exe" WashAndGo
Path
C:\Users\admin\AppData\Local\Temp\is-NALMJ.tmp\closeapp.exe
Indicators
No indicators
Parent process
washandgo.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\is-nalmj.tmp\closeapp.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
1532
CMD
"C:\Users\admin\AppData\Local\Temp\is-NALMJ.tmp\closeapp.exe" AbelssoftPreloader
Path
C:\Users\admin\AppData\Local\Temp\is-NALMJ.tmp\closeapp.exe
Indicators
No indicators
Parent process
washandgo.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\is-nalmj.tmp\closeapp.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
2532
CMD
"C:\Windows\system32\regsvr32.exe" /s "C:\ProgramData\Abelssoft\WashAndGo\Program\dsofile.dll"
Path
C:\Windows\system32\regsvr32.exe
Indicators
No indicators
Parent process
washandgo.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft(C) Register Server
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\programdata\abelssoft\washandgo\program\dsofile.dll
c:\windows\system32\sxs.dll

PID
3912
CMD
"C:\ProgramData\Abelssoft\WashAndGo\Program\WashAndGo.exe" -install
Path
C:\ProgramData\Abelssoft\WashAndGo\Program\WashAndGo.exe
Indicators
Parent process
washandgo.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft
Description
WashAndGo
Version
24.7.0.0
Modules
Image
c:\programdata\abelssoft\washandgo\program\washandgo.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\mscorlib\97e047cf68e9a7d90e196d072cd49cac\mscorlib.ni.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll
c:\programdata\abelssoft\washandgo\program\abdefault.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system\e071297bb06faa961bef045ae5f25fdc\system.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.core\21a1606b6c00f9abe7db55c02e0f87c9\system.core.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\windowsbase\0d5a8e6f89227cc5d954e65856f9cf1a\windowsbase.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\presentationcore\e7873d3bd71f6122c2a954be1bb5bb28\presentationcore.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\presentatio5ae0f00f#\b34cda03a984c515b31faf410e5b7e39\presentationframework.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xaml\4d290752f65a065fcde70178562c3383\system.xaml.ni.dll
c:\programdata\abelssoft\washandgo\program\abcommons.dll
c:\windows\system32\dwrite.dll
c:\windows\microsoft.net\framework\v4.0.30319\wpf\wpfgfx_v0400.dll
c:\windows\system32\msvcp120_clr0400.dll
c:\windows\system32\oleaut32.dll
c:\windows\microsoft.net\framework\v4.0.30319\wpf\presentationnative_v0400.dll
c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll
c:\programdata\abelssoft\washandgo\program\guiutils.dll
c:\windows\microsoft.net\framework\v4.0.30319\nlssorting.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.configuration\cd03f9386e02f56502e01a25ddd7e0a7\system.configuration.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xml\7c8f75f367134a030cba4a127dc62a2f\system.xml.ni.dll
c:\windows\system32\shell32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\uxtheme.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\presentatiod51afaa5#\867cbe7462b04e2cf1ae39abb576ae2a\presentationframework.classic.ni.dll
c:\programdata\abelssoft\washandgo\program\ablanguage.dll
c:\programdata\abelssoft\washandgo\program\abregistration.dll
c:\programdata\abelssoft\washandgo\program\abbugreporter.dll
c:\programdata\abelssoft\washandgo\program\abgui.dll
c:\programdata\abelssoft\washandgo\program\nmgui.exe
c:\programdata\abelssoft\washandgo\program\washfusion.exe
c:\programdata\abelssoft\washandgo\program\ablog.commons.dll
c:\programdata\abelssoft\washandgo\program\abloginstance.dll
c:\programdata\abelssoft\washandgo\program\shredder.dll
c:\programdata\abelssoft\washandgo\program\washandgo.api.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.drawing\61dfb69c9ad6ed96809170d54d80b8a6\system.drawing.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.windows.forms\2dc6cfd856864312d563098f9486361c\system.windows.forms.ni.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wintrust.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscorsecimpl.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\riched20.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\userenv.dll
c:\windows\system32\gpapi.dll
c:\programdata\abelssoft\washandgo\program\ablog.dll
c:\programdata\abelssoft\washandgo\program\dll\log4net.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.management\e588691224a17737f3a164cc2d46c156\system.management.ni.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wmiutils.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\microsoft.net\framework\v4.0.30319\wminet_utils.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\microsoft.net\framework\v4.0.30319\diasymreader.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\programdata\abelssoft\washandgo\program\abtelemetry.dll
c:\programdata\abelssoft\washandgo\program\newtonsoft.json.dll
c:\programdata\abelssoft\washandgo\program\icsharpcode.sharpziplib.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.numerics\5ac17cc5b92efda83e2925857f4fa655\system.numerics.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.runteb92aa12#\62a6b39f4f68c25dfd2f6308d7541401\system.runtime.serialization.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.data\1288d7e030bc0c5d8b2cbe5f33aeed7f\system.data.ni.dll
c:\windows\microsoft.net\assembly\gac_32\system.data\v4.0_4.0.0.0__b77a5c561934e089\system.data.dll
c:\programdata\abelssoft\washandgo\program\restsharp.dll
c:\windows\system32\psapi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\credssp.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\secur32.dll
c:\windows\system32\schannel.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\microsoft.csharp\7f0531cbaadefd63fb9c1f7ae51fc668\microsoft.csharp.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.dynamic\770a605d5193c730225204fa780278ae\system.dynamic.ni.dll

PID
2080
CMD
"C:\ProgramData\Abelssoft\WashAndGo\Program\AbelssoftPreloader.exe" install
Path
C:\ProgramData\Abelssoft\WashAndGo\Program\AbelssoftPreloader.exe
Indicators
No indicators
Parent process
washandgo.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft
Description
AbelssoftPreloader
Version
1.0.0.0
Modules
Image
c:\programdata\abelssoft\washandgo\program\abelssoftpreloader.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\mscorlib\97e047cf68e9a7d90e196d072cd49cac\mscorlib.ni.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll
c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll
c:\windows\system32\oleaut32.dll
c:\programdata\abelssoft\washandgo\program\log4net.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\microsoft.net\framework\v4.0.30319\nlssorting.dll
c:\windows\system32\shell32.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system\e071297bb06faa961bef045ae5f25fdc\system.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.core\21a1606b6c00f9abe7db55c02e0f87c9\system.core.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.configuration\cd03f9386e02f56502e01a25ddd7e0a7\system.configuration.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xml\7c8f75f367134a030cba4a127dc62a2f\system.xml.ni.dll
c:\windows\system32\profapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\microsoft.net\framework\v4.0.30319\diasymreader.dll
c:\programdata\abelssoft\washandgo\program\scheduletasks.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.drawing\61dfb69c9ad6ed96809170d54d80b8a6\system.drawing.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.windows.forms\2dc6cfd856864312d563098f9486361c\system.windows.forms.ni.dll
c:\programdata\abelssoft\washandgo\program\taskscheduler.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mstask.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\mpr.dll

PID
2820
CMD
"C:\Program Files\WashAndGo\AbLauncher.exe"
Path
C:\Program Files\WashAndGo\AbLauncher.exe
Indicators
No indicators
Parent process
washandgo.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
ConsoleApplication1
Version
1.0.0.0
Modules
Image
c:\program files\washandgo\ablauncher.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\mscorlib\97e047cf68e9a7d90e196d072cd49cac\mscorlib.ni.dll
c:\windows\system32\cryptbase.dll
c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll
c:\program files\washandgo\ablauncher.updateroutines.plugin.base.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system\e071297bb06faa961bef045ae5f25fdc\system.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.core\21a1606b6c00f9abe7db55c02e0f87c9\system.core.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xml\7c8f75f367134a030cba4a127dc62a2f\system.xml.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.configuration\cd03f9386e02f56502e01a25ddd7e0a7\system.configuration.ni.dll
c:\windows\microsoft.net\framework\v4.0.30319\nlssorting.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\propsys.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\programdata\abelssoft\washandgo\program\washandgo.exe

PID
2400
CMD
"C:\ProgramData\Abelssoft\WashAndGo\Program\WashAndGo.exe"
Path
C:\ProgramData\Abelssoft\WashAndGo\Program\WashAndGo.exe
Indicators
Parent process
AbLauncher.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft
Description
WashAndGo
Version
24.7.0.0
Modules
Image
c:\programdata\abelssoft\washandgo\program\washandgo.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\mscorlib\97e047cf68e9a7d90e196d072cd49cac\mscorlib.ni.dll
c:\windows\system32\cryptbase.dll
c:\programdata\abelssoft\washandgo\program\abdefault.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system\e071297bb06faa961bef045ae5f25fdc\system.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.core\21a1606b6c00f9abe7db55c02e0f87c9\system.core.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\windowsbase\0d5a8e6f89227cc5d954e65856f9cf1a\windowsbase.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\presentationcore\e7873d3bd71f6122c2a954be1bb5bb28\presentationcore.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\presentatio5ae0f00f#\b34cda03a984c515b31faf410e5b7e39\presentationframework.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xaml\4d290752f65a065fcde70178562c3383\system.xaml.ni.dll
c:\programdata\abelssoft\washandgo\program\abcommons.dll
c:\windows\system32\dwrite.dll
c:\windows\microsoft.net\framework\v4.0.30319\wpf\wpfgfx_v0400.dll
c:\windows\system32\msvcp120_clr0400.dll
c:\windows\microsoft.net\framework\v4.0.30319\wpf\presentationnative_v0400.dll
c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll
c:\programdata\abelssoft\washandgo\program\guiutils.dll
c:\windows\microsoft.net\framework\v4.0.30319\nlssorting.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.configuration\cd03f9386e02f56502e01a25ddd7e0a7\system.configuration.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xml\7c8f75f367134a030cba4a127dc62a2f\system.xml.ni.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\uxtheme.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\presentatiod51afaa5#\867cbe7462b04e2cf1ae39abb576ae2a\presentationframework.classic.ni.dll
c:\programdata\abelssoft\washandgo\program\ablanguage.dll
c:\programdata\abelssoft\washandgo\program\abregistration.dll
c:\programdata\abelssoft\washandgo\program\abbugreporter.dll
c:\programdata\abelssoft\washandgo\program\abgui.dll
c:\programdata\abelssoft\washandgo\program\nmgui.exe
c:\programdata\abelssoft\washandgo\program\washfusion.exe
c:\programdata\abelssoft\washandgo\program\ablog.commons.dll
c:\programdata\abelssoft\washandgo\program\abloginstance.dll
c:\programdata\abelssoft\washandgo\program\shredder.dll
c:\programdata\abelssoft\washandgo\program\washandgo.api.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.drawing\61dfb69c9ad6ed96809170d54d80b8a6\system.drawing.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.windows.forms\2dc6cfd856864312d563098f9486361c\system.windows.forms.ni.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\wintrust.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscorsecimpl.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\riched20.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\programdata\abelssoft\washandgo\program\ablog.dll
c:\programdata\abelssoft\washandgo\program\dll\log4net.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.management\e588691224a17737f3a164cc2d46c156\system.management.ni.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wmiutils.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\microsoft.net\framework\v4.0.30319\wminet_utils.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\microsoft.net\framework\v4.0.30319\diasymreader.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\programdata\abelssoft\washandgo\program\newtonsoft.json.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.numerics\5ac17cc5b92efda83e2925857f4fa655\system.numerics.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.runteb92aa12#\62a6b39f4f68c25dfd2f6308d7541401\system.runtime.serialization.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.data\1288d7e030bc0c5d8b2cbe5f33aeed7f\system.data.ni.dll
c:\windows\microsoft.net\assembly\gac_32\system.data\v4.0_4.0.0.0__b77a5c561934e089\system.data.dll
c:\programdata\abelssoft\washandgo\program\abtelemetry.dll
c:\programdata\abelssoft\washandgo\program\icsharpcode.sharpziplib.dll
c:\programdata\abelssoft\washandgo\program\restsharp.dll
c:\windows\system32\psapi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\credssp.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\secur32.dll
c:\windows\system32\schannel.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\microsoft.csharp\7f0531cbaadefd63fb9c1f7ae51fc668\microsoft.csharp.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.dynamic\770a605d5193c730225204fa780278ae\system.dynamic.ni.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\d3d9.dll
c:\windows\system32\d3d8thk.dll
c:\windows\system32\vga.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\winsta.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\presentatio49d6fefe#\f52bfe40c54917622ed3abb98db8f90a\presentationframework-systemxml.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\windowsform0b574481#\c6131c3262a5bf98463da8f219b75baa\windowsformsintegration.ni.dll
c:\programdata\abelssoft\washandgo\program\artefact.dll
c:\windows\system32\msctfui.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\uiautomationtypes\1e1a1bd97e618bc4934ee967bea27ae8\uiautomationtypes.ni.dll
c:\windows\system32\uiautomationcore.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\winmm.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\presentatio84a7b877#\bc98161a485ea05967844bc0b0c55338\presentationframework-systemdata.ni.dll
c:\programdata\abelssoft\washandgo\program\ablogger.dll
c:\programdata\abelssoft\washandgo\program\chuckcore.dll

PID
3024
CMD
"C:\Program Files\WashAndGo\AbLauncher.exe"
Path
C:\Program Files\WashAndGo\AbLauncher.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
ConsoleApplication1
Version
1.0.0.0
Modules
Image
c:\program files\washandgo\ablauncher.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\system32\psapi.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\mscorlib\97e047cf68e9a7d90e196d072cd49cac\mscorlib.ni.dll
c:\windows\system32\cryptbase.dll
c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll
c:\program files\washandgo\ablauncher.updateroutines.plugin.base.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system\e071297bb06faa961bef045ae5f25fdc\system.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.core\21a1606b6c00f9abe7db55c02e0f87c9\system.core.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xml\7c8f75f367134a030cba4a127dc62a2f\system.xml.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.configuration\cd03f9386e02f56502e01a25ddd7e0a7\system.configuration.ni.dll
c:\windows\microsoft.net\framework\v4.0.30319\nlssorting.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\propsys.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\programdata\abelssoft\washandgo\program\washandgo.exe

PID
3272
CMD
"C:\ProgramData\Abelssoft\WashAndGo\Program\WashAndGo.exe"
Path
C:\ProgramData\Abelssoft\WashAndGo\Program\WashAndGo.exe
Indicators
No indicators
Parent process
AbLauncher.exe
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
Microsoft
Description
WashAndGo
Version
24.7.0.0
Modules
Image
c:\programdata\abelssoft\washandgo\program\washandgo.exe
c:\systemroot\system32\ntdll.dll

PID
1904
CMD
"C:\ProgramData\Abelssoft\WashAndGo\Program\WashAndGo.exe"
Path
C:\ProgramData\Abelssoft\WashAndGo\Program\WashAndGo.exe
Indicators
Parent process
AbLauncher.exe
User
admin
Integrity Level
HIGH
Exit code
3762504530
Version:
Company
Microsoft
Description
WashAndGo
Version
24.7.0.0
Modules
Image
c:\programdata\abelssoft\washandgo\program\washandgo.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\system32\psapi.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\mscorlib\97e047cf68e9a7d90e196d072cd49cac\mscorlib.ni.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll
c:\programdata\abelssoft\washandgo\program\abdefault.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system\e071297bb06faa961bef045ae5f25fdc\system.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.core\21a1606b6c00f9abe7db55c02e0f87c9\system.core.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\windowsbase\0d5a8e6f89227cc5d954e65856f9cf1a\windowsbase.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\presentationcore\e7873d3bd71f6122c2a954be1bb5bb28\presentationcore.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\presentatio5ae0f00f#\b34cda03a984c515b31faf410e5b7e39\presentationframework.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xaml\4d290752f65a065fcde70178562c3383\system.xaml.ni.dll
c:\programdata\abelssoft\washandgo\program\abcommons.dll
c:\windows\system32\dwrite.dll
c:\windows\microsoft.net\framework\v4.0.30319\wpf\wpfgfx_v0400.dll
c:\windows\system32\msvcp120_clr0400.dll
c:\windows\system32\oleaut32.dll
c:\windows\microsoft.net\framework\v4.0.30319\wpf\presentationnative_v0400.dll
c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll
c:\programdata\abelssoft\washandgo\program\guiutils.dll
c:\windows\microsoft.net\framework\v4.0.30319\nlssorting.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.configuration\cd03f9386e02f56502e01a25ddd7e0a7\system.configuration.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xml\7c8f75f367134a030cba4a127dc62a2f\system.xml.ni.dll
c:\windows\system32\shell32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\uxtheme.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\presentatiod51afaa5#\867cbe7462b04e2cf1ae39abb576ae2a\presentationframework.classic.ni.dll
c:\programdata\abelssoft\washandgo\program\ablanguage.dll
c:\programdata\abelssoft\washandgo\program\abregistration.dll
c:\programdata\abelssoft\washandgo\program\abbugreporter.dll
c:\programdata\abelssoft\washandgo\program\abgui.dll
c:\programdata\abelssoft\washandgo\program\nmgui.exe
c:\programdata\abelssoft\washandgo\program\washfusion.exe
c:\programdata\abelssoft\washandgo\program\ablog.commons.dll
c:\programdata\abelssoft\washandgo\program\abloginstance.dll
c:\programdata\abelssoft\washandgo\program\shredder.dll
c:\programdata\abelssoft\washandgo\program\washandgo.api.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.drawing\61dfb69c9ad6ed96809170d54d80b8a6\system.drawing.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.windows.forms\2dc6cfd856864312d563098f9486361c\system.windows.forms.ni.dll
c:\windows\microsoft.net\framework\v4.0.30319\diasymreader.dll

PID
3152
CMD
"C:\Program Files\WashAndGo\AbLauncher.exe"
Path
C:\Program Files\WashAndGo\AbLauncher.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
ConsoleApplication1
Version
1.0.0.0
Modules
Image
c:\program files\washandgo\ablauncher.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\system32\psapi.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\mscorlib\97e047cf68e9a7d90e196d072cd49cac\mscorlib.ni.dll
c:\windows\system32\cryptbase.dll
c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll
c:\program files\washandgo\ablauncher.updateroutines.plugin.base.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system\e071297bb06faa961bef045ae5f25fdc\system.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.core\21a1606b6c00f9abe7db55c02e0f87c9\system.core.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xml\7c8f75f367134a030cba4a127dc62a2f\system.xml.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.configuration\cd03f9386e02f56502e01a25ddd7e0a7\system.configuration.ni.dll
c:\windows\microsoft.net\framework\v4.0.30319\nlssorting.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\propsys.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\programdata\abelssoft\washandgo\program\washandgo.exe

PID
2924
CMD
"C:\ProgramData\Abelssoft\WashAndGo\Program\WashAndGo.exe"
Path
C:\ProgramData\Abelssoft\WashAndGo\Program\WashAndGo.exe
Indicators
No indicators
Parent process
AbLauncher.exe
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
Microsoft
Description
WashAndGo
Version
24.7.0.0
Modules
Image
c:\programdata\abelssoft\washandgo\program\washandgo.exe
c:\systemroot\system32\ntdll.dll

PID
2868
CMD
"C:\ProgramData\Abelssoft\WashAndGo\Program\WashAndGo.exe"
Path
C:\ProgramData\Abelssoft\WashAndGo\Program\WashAndGo.exe
Indicators
Parent process
AbLauncher.exe
User
admin
Integrity Level
HIGH
Exit code
3762504530
Version:
Company
Microsoft
Description
WashAndGo
Version
24.7.0.0
Modules
Image
c:\programdata\abelssoft\washandgo\program\washandgo.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\system32\psapi.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\mscorlib\97e047cf68e9a7d90e196d072cd49cac\mscorlib.ni.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll
c:\programdata\abelssoft\washandgo\program\abdefault.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system\e071297bb06faa961bef045ae5f25fdc\system.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.core\21a1606b6c00f9abe7db55c02e0f87c9\system.core.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\windowsbase\0d5a8e6f89227cc5d954e65856f9cf1a\windowsbase.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\presentationcore\e7873d3bd71f6122c2a954be1bb5bb28\presentationcore.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\presentatio5ae0f00f#\b34cda03a984c515b31faf410e5b7e39\presentationframework.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xaml\4d290752f65a065fcde70178562c3383\system.xaml.ni.dll
c:\programdata\abelssoft\washandgo\program\abcommons.dll
c:\windows\system32\dwrite.dll
c:\windows\microsoft.net\framework\v4.0.30319\wpf\wpfgfx_v0400.dll
c:\windows\system32\msvcp120_clr0400.dll
c:\windows\system32\oleaut32.dll
c:\windows\microsoft.net\framework\v4.0.30319\wpf\presentationnative_v0400.dll
c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll
c:\programdata\abelssoft\washandgo\program\guiutils.dll
c:\windows\microsoft.net\framework\v4.0.30319\nlssorting.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.configuration\cd03f9386e02f56502e01a25ddd7e0a7\system.configuration.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xml\7c8f75f367134a030cba4a127dc62a2f\system.xml.ni.dll
c:\windows\system32\shell32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\uxtheme.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\presentatiod51afaa5#\867cbe7462b04e2cf1ae39abb576ae2a\presentationframework.classic.ni.dll
c:\programdata\abelssoft\washandgo\program\ablanguage.dll
c:\programdata\abelssoft\washandgo\program\abregistration.dll
c:\programdata\abelssoft\washandgo\program\abbugreporter.dll
c:\programdata\abelssoft\washandgo\program\abgui.dll
c:\programdata\abelssoft\washandgo\program\nmgui.exe
c:\programdata\abelssoft\washandgo\program\washfusion.exe
c:\programdata\abelssoft\washandgo\program\ablog.commons.dll
c:\programdata\abelssoft\washandgo\program\abloginstance.dll
c:\programdata\abelssoft\washandgo\program\shredder.dll
c:\programdata\abelssoft\washandgo\program\washandgo.api.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.drawing\61dfb69c9ad6ed96809170d54d80b8a6\system.drawing.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.windows.forms\2dc6cfd856864312d563098f9486361c\system.windows.forms.ni.dll
c:\windows\microsoft.net\framework\v4.0.30319\diasymreader.dll

PID
2988
CMD
"C:\Program Files\WashAndGo\AbLauncher.exe"
Path
C:\Program Files\WashAndGo\AbLauncher.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
ConsoleApplication1
Version
1.0.0.0
Modules
Image
c:\program files\washandgo\ablauncher.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\system32\psapi.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\mscorlib\97e047cf68e9a7d90e196d072cd49cac\mscorlib.ni.dll
c:\windows\system32\cryptbase.dll
c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll
c:\program files\washandgo\ablauncher.updateroutines.plugin.base.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system\e071297bb06faa961bef045ae5f25fdc\system.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.core\21a1606b6c00f9abe7db55c02e0f87c9\system.core.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xml\7c8f75f367134a030cba4a127dc62a2f\system.xml.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.configuration\cd03f9386e02f56502e01a25ddd7e0a7\system.configuration.ni.dll
c:\windows\microsoft.net\framework\v4.0.30319\nlssorting.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\propsys.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\programdata\abelssoft\washandgo\program\washandgo.exe

PID
3036
CMD
"C:\ProgramData\Abelssoft\WashAndGo\Program\WashAndGo.exe"
Path
C:\ProgramData\Abelssoft\WashAndGo\Program\WashAndGo.exe
Indicators
No indicators
Parent process
AbLauncher.exe
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
Microsoft
Description
WashAndGo
Version
24.7.0.0
Modules
Image
c:\programdata\abelssoft\washandgo\program\washandgo.exe
c:\systemroot\system32\ntdll.dll

PID
2424
CMD
"C:\ProgramData\Abelssoft\WashAndGo\Program\WashAndGo.exe"
Path
C:\ProgramData\Abelssoft\WashAndGo\Program\WashAndGo.exe
Indicators
Parent process
AbLauncher.exe
User
admin
Integrity Level
HIGH
Exit code
3762504530
Version:
Company
Microsoft
Description
WashAndGo
Version
24.7.0.0
Modules
Image
c:\programdata\abelssoft\washandgo\program\washandgo.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\system32\psapi.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\mscorlib\97e047cf68e9a7d90e196d072cd49cac\mscorlib.ni.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll
c:\programdata\abelssoft\washandgo\program\abdefault.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system\e071297bb06faa961bef045ae5f25fdc\system.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.core\21a1606b6c00f9abe7db55c02e0f87c9\system.core.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\windowsbase\0d5a8e6f89227cc5d954e65856f9cf1a\windowsbase.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\presentationcore\e7873d3bd71f6122c2a954be1bb5bb28\presentationcore.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\presentatio5ae0f00f#\b34cda03a984c515b31faf410e5b7e39\presentationframework.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xaml\4d290752f65a065fcde70178562c3383\system.xaml.ni.dll
c:\programdata\abelssoft\washandgo\program\abcommons.dll
c:\windows\system32\dwrite.dll
c:\windows\microsoft.net\framework\v4.0.30319\wpf\wpfgfx_v0400.dll
c:\windows\system32\msvcp120_clr0400.dll
c:\windows\system32\oleaut32.dll
c:\windows\microsoft.net\framework\v4.0.30319\wpf\presentationnative_v0400.dll
c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll
c:\programdata\abelssoft\washandgo\program\guiutils.dll
c:\windows\microsoft.net\framework\v4.0.30319\nlssorting.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.configuration\cd03f9386e02f56502e01a25ddd7e0a7\system.configuration.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xml\7c8f75f367134a030cba4a127dc62a2f\system.xml.ni.dll
c:\windows\system32\shell32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\uxtheme.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\presentatiod51afaa5#\867cbe7462b04e2cf1ae39abb576ae2a\presentationframework.classic.ni.dll
c:\programdata\abelssoft\washandgo\program\ablanguage.dll
c:\programdata\abelssoft\washandgo\program\abregistration.dll
c:\programdata\abelssoft\washandgo\program\abbugreporter.dll
c:\programdata\abelssoft\washandgo\program\abgui.dll
c:\programdata\abelssoft\washandgo\program\nmgui.exe
c:\programdata\abelssoft\washandgo\program\washfusion.exe
c:\programdata\abelssoft\washandgo\program\ablog.commons.dll
c:\programdata\abelssoft\washandgo\program\abloginstance.dll
c:\programdata\abelssoft\washandgo\program\shredder.dll
c:\programdata\abelssoft\washandgo\program\washandgo.api.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.drawing\61dfb69c9ad6ed96809170d54d80b8a6\system.drawing.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.windows.forms\2dc6cfd856864312d563098f9486361c\system.windows.forms.ni.dll
c:\windows\microsoft.net\framework\v4.0.30319\diasymreader.dll

PID
3868
CMD
"C:\Program Files\WashAndGo\AbLauncher.exe"
Path
C:\Program Files\WashAndGo\AbLauncher.exe
Indicators
Parent process
––
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
ConsoleApplication1
Version
1.0.0.0
Modules
Image
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\clbcatq.dll
c:\programdata\abelssoft\washandgo\program\washandgo.exe
c:\windows\system32\wldap32.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msutb.dll
c:\windows\system32\msctf.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\winsta.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\user32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\kernelbase.dll
c:\systemroot\system32\ntdll.dll
c:\program files\washandgo\ablauncher.exe
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\system32\psapi.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\mscorlib\97e047cf68e9a7d90e196d072cd49cac\mscorlib.ni.dll
c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll
c:\program files\washandgo\ablauncher.updateroutines.plugin.base.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system\e071297bb06faa961bef045ae5f25fdc\system.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.core\21a1606b6c00f9abe7db55c02e0f87c9\system.core.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xml\7c8f75f367134a030cba4a127dc62a2f\system.xml.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.configuration\cd03f9386e02f56502e01a25ddd7e0a7\system.configuration.ni.dll
c:\windows\microsoft.net\framework\v4.0.30319\nlssorting.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\propsys.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll

PID
2984
CMD
"C:\ProgramData\Abelssoft\WashAndGo\Program\WashAndGo.exe"
Path
C:\ProgramData\Abelssoft\WashAndGo\Program\WashAndGo.exe
Indicators
Parent process
AbLauncher.exe
User
admin
Integrity Level
HIGH
Exit code
3762504530
Version:
Company
Microsoft
Description
WashAndGo
Version
24.7.0.0
Modules
Image
c:\programdata\abelssoft\washandgo\program\washandgo.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\system32\psapi.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\mscorlib\97e047cf68e9a7d90e196d072cd49cac\mscorlib.ni.dll
c:\windows\system32\cryptbase.dll
c:\programdata\abelssoft\washandgo\program\abdefault.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system\e071297bb06faa961bef045ae5f25fdc\system.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.core\21a1606b6c00f9abe7db55c02e0f87c9\system.core.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\windowsbase\0d5a8e6f89227cc5d954e65856f9cf1a\windowsbase.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\presentationcore\e7873d3bd71f6122c2a954be1bb5bb28\presentationcore.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\presentatio5ae0f00f#\b34cda03a984c515b31faf410e5b7e39\presentationframework.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xaml\4d290752f65a065fcde70178562c3383\system.xaml.ni.dll
c:\programdata\abelssoft\washandgo\program\abcommons.dll
c:\windows\system32\dwrite.dll
c:\windows\microsoft.net\framework\v4.0.30319\wpf\wpfgfx_v0400.dll
c:\windows\system32\msvcp120_clr0400.dll
c:\windows\microsoft.net\framework\v4.0.30319\wpf\presentationnative_v0400.dll
c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll
c:\programdata\abelssoft\washandgo\program\guiutils.dll
c:\windows\microsoft.net\framework\v4.0.30319\nlssorting.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.configuration\cd03f9386e02f56502e01a25ddd7e0a7\system.configuration.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xml\7c8f75f367134a030cba4a127dc62a2f\system.xml.ni.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\uxtheme.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\presentatiod51afaa5#\867cbe7462b04e2cf1ae39abb576ae2a\presentationframework.classic.ni.dll
c:\programdata\abelssoft\washandgo\program\ablanguage.dll
c:\programdata\abelssoft\washandgo\program\abregistration.dll
c:\programdata\abelssoft\washandgo\program\abbugreporter.dll
c:\programdata\abelssoft\washandgo\program\abgui.dll
c:\programdata\abelssoft\washandgo\program\nmgui.exe
c:\programdata\abelssoft\washandgo\program\washfusion.exe
c:\programdata\abelssoft\washandgo\program\ablog.commons.dll
c:\programdata\abelssoft\washandgo\program\abloginstance.dll
c:\programdata\abelssoft\washandgo\program\shredder.dll
c:\programdata\abelssoft\washandgo\program\washandgo.api.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.drawing\61dfb69c9ad6ed96809170d54d80b8a6\system.drawing.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.windows.forms\2dc6cfd856864312d563098f9486361c\system.windows.forms.ni.dll
c:\windows\microsoft.net\framework\v4.0.30319\diasymreader.dll

PID
2184
CMD
"C:\Users\admin\Desktop\washandgo.exe"
Path
C:\Users\admin\Desktop\washandgo.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Abelssoft
Description
WashAndGo 20
Version
1.0.0.0
Modules
Image
c:\users\admin\desktop\washandgo.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\version.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shell32.dll
c:\users\admin\appdata\local\temp\is-8d5gt.tmp\washandgo.tmp

PID
2336
CMD
"C:\Users\admin\AppData\Local\Temp\is-8D5GT.tmp\washandgo.tmp" /SL5="$901A6,27247777,294912,C:\Users\admin\Desktop\washandgo.exe"
Path
C:\Users\admin\AppData\Local\Temp\is-8D5GT.tmp\washandgo.tmp
Indicators
No indicators
Parent process
washandgo.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\users\admin\appdata\local\temp\is-8d5gt.tmp\washandgo.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll

PID
3172
CMD
"C:\Users\admin\Desktop\washandgo.exe" /SPAWNWND=$B0138 /NOTIFYWND=$901A6
Path
C:\Users\admin\Desktop\washandgo.exe
Indicators
Parent process
washandgo.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Abelssoft
Description
WashAndGo 20
Version
1.0.0.0
Modules
Image
c:\users\admin\desktop\washandgo.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\version.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shell32.dll
c:\users\admin\appdata\local\temp\is-kigvf.tmp\washandgo.tmp

PID
3056
CMD
"C:\Users\admin\AppData\Local\Temp\is-KIGVF.tmp\washandgo.tmp" /SL5="$90182,27247777,294912,C:\Users\admin\Desktop\washandgo.exe" /SPAWNWND=$B0138 /NOTIFYWND=$901A6
Path
C:\Users\admin\AppData\Local\Temp\is-KIGVF.tmp\washandgo.tmp
Indicators
Parent process
washandgo.exe
User
admin
Integrity Level
HIGH
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\users\admin\appdata\local\temp\is-kigvf.tmp\washandgo.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\bcryptprimitives.dll
c:\users\admin\appdata\local\temp\is-jh3cs.tmp\isxdl.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\msi.dll
c:\users\admin\appdata\local\temp\is-jh3cs.tmp\closeapp.exe
c:\windows\system32\imageres.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\program files\washandgo\unins000.exe

PID
3828
CMD
"C:\Users\admin\AppData\Local\Temp\is-JH3CS.tmp\closeapp.exe" WashAndGo
Path
C:\Users\admin\AppData\Local\Temp\is-JH3CS.tmp\closeapp.exe
Indicators
No indicators
Parent process
washandgo.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\is-jh3cs.tmp\closeapp.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
292
CMD
"C:\Users\admin\AppData\Local\Temp\is-JH3CS.tmp\closeapp.exe" AbelssoftPreloader
Path
C:\Users\admin\AppData\Local\Temp\is-JH3CS.tmp\closeapp.exe
Indicators
No indicators
Parent process
washandgo.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\is-jh3cs.tmp\closeapp.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
4068
CMD
"C:\Program Files\WashAndGo\unins000.exe" /SILENT /NORESTART /SUPPRESSMSGBOXES
Path
C:\Program Files\WashAndGo\unins000.exe
Indicators
Parent process
washandgo.tmp
User
admin
Integrity Level
HIGH
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\program files\washandgo\unins000.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\users\admin\appdata\local\temp\_iu14d2n.tmp

PID
2676
CMD
"C:\Users\admin\AppData\Local\Temp\_iu14D2N.tmp" /SECONDPHASE="C:\Program Files\WashAndGo\unins000.exe" /FIRSTPHASEWND=$4018A /SILENT /NORESTART /SUPPRESSMSGBOXES
Path
C:\Users\admin\AppData\Local\Temp\_iu14D2N.tmp
Indicators
No indicators
Parent process
unins000.exe
User
admin
Integrity Level
HIGH
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\users\admin\appdata\local\temp\_iu14d2n.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\comres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\msi.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\program files\washandgo\closeapp.exe

PID
1820
CMD
"C:\Program Files\WashAndGo\closeapp.exe" WashAndGo
Path
C:\Program Files\WashAndGo\closeapp.exe
Indicators
No indicators
Parent process
_iu14D2N.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\program files\washandgo\closeapp.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
1752
CMD
"C:\ProgramData\Abelssoft\WashAndGo\Program\WashAndGo.exe" -uninstall
Path
C:\ProgramData\Abelssoft\WashAndGo\Program\WashAndGo.exe
Indicators
Parent process
_iu14D2N.tmp
User
admin
Integrity Level
HIGH
Version:
Company
Microsoft
Description
WashAndGo
Version
24.7.0.0
Modules
Image
c:\programdata\abelssoft\washandgo\program\washandgo.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\system32\psapi.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\mscorlib\97e047cf68e9a7d90e196d072cd49cac\mscorlib.ni.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll
c:\programdata\abelssoft\washandgo\program\abdefault.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system\e071297bb06faa961bef045ae5f25fdc\system.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.core\21a1606b6c00f9abe7db55c02e0f87c9\system.core.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\windowsbase\0d5a8e6f89227cc5d954e65856f9cf1a\windowsbase.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\presentationcore\e7873d3bd71f6122c2a954be1bb5bb28\presentationcore.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\presentatio5ae0f00f#\b34cda03a984c515b31faf410e5b7e39\presentationframework.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xaml\4d290752f65a065fcde70178562c3383\system.xaml.ni.dll
c:\programdata\abelssoft\washandgo\program\abcommons.dll
c:\windows\system32\dwrite.dll
c:\windows\microsoft.net\framework\v4.0.30319\wpf\wpfgfx_v0400.dll
c:\windows\system32\msvcp120_clr0400.dll
c:\windows\system32\oleaut32.dll
c:\windows\microsoft.net\framework\v4.0.30319\wpf\presentationnative_v0400.dll
c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll
c:\programdata\abelssoft\washandgo\program\guiutils.dll
c:\windows\microsoft.net\framework\v4.0.30319\nlssorting.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.configuration\cd03f9386e02f56502e01a25ddd7e0a7\system.configuration.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xml\7c8f75f367134a030cba4a127dc62a2f\system.xml.ni.dll
c:\windows\system32\shell32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\uxtheme.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\presentatiod51afaa5#\867cbe7462b04e2cf1ae39abb576ae2a\presentationframework.classic.ni.dll
c:\programdata\abelssoft\washandgo\program\ablanguage.dll
c:\programdata\abelssoft\washandgo\program\abregistration.dll
c:\programdata\abelssoft\washandgo\program\abbugreporter.dll
c:\programdata\abelssoft\washandgo\program\abgui.dll
c:\programdata\abelssoft\washandgo\program\nmgui.exe
c:\programdata\abelssoft\washandgo\program\washfusion.exe
c:\programdata\abelssoft\washandgo\program\ablog.commons.dll
c:\programdata\abelssoft\washandgo\program\abloginstance.dll
c:\programdata\abelssoft\washandgo\program\shredder.dll
c:\programdata\abelssoft\washandgo\program\washandgo.api.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.drawing\61dfb69c9ad6ed96809170d54d80b8a6\system.drawing.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.windows.forms\2dc6cfd856864312d563098f9486361c\system.windows.forms.ni.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wintrust.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscorsecimpl.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\riched20.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\userenv.dll
c:\windows\system32\gpapi.dll
c:\programdata\abelssoft\washandgo\program\ablog.dll
c:\programdata\abelssoft\washandgo\program\dll\log4net.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.management\e588691224a17737f3a164cc2d46c156\system.management.ni.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\wbem\wmiutils.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\microsoft.net\framework\v4.0.30319\wminet_utils.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\microsoft.net\framework\v4.0.30319\diasymreader.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\napinsp.dll
c:\windows\system32\pnrpnsp.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\winrnr.dll
c:\programdata\abelssoft\washandgo\program\abtelemetry.dll
c:\programdata\abelssoft\washandgo\program\icsharpcode.sharpziplib.dll
c:\programdata\abelssoft\washandgo\program\newtonsoft.json.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.numerics\5ac17cc5b92efda83e2925857f4fa655\system.numerics.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.runteb92aa12#\62a6b39f4f68c25dfd2f6308d7541401\system.runtime.serialization.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.data\1288d7e030bc0c5d8b2cbe5f33aeed7f\system.data.ni.dll
c:\windows\microsoft.net\assembly\gac_32\system.data\v4.0_4.0.0.0__b77a5c561934e089\system.data.dll
c:\programdata\abelssoft\washandgo\program\restsharp.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\credssp.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\secur32.dll
c:\windows\system32\schannel.dll

Registry activity

Total events
834
Read events
691
Write events
142
Delete events
1

Modification events

PID
Process
Operation
Key
Name
Value
1752
WashAndGo.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
1752
WashAndGo.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
1752
WashAndGo.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
LanguageList
en-US
3152
AbLauncher.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3152
AbLauncher.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3024
AbLauncher.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3024
AbLauncher.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2400
WashAndGo.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2400
WashAndGo.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2400
WashAndGo.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
LanguageList
en-US
2400
WashAndGo.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Name
WashAndGo.exe
2820
AbLauncher.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2820
AbLauncher.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3912
WashAndGo.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3912
WashAndGo.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3912
WashAndGo.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
LanguageList
en-US
3912
WashAndGo.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD
Blob
040000000100000010000000C5DFB849CA051355EE2DBA1AC33EB0280F00000001000000200000005229BA15B31B0C6F4CCA89C2985177974327D1B689A3B935A0BD975532AF22AB090000000100000054000000305206082B0601050507030106082B0601050507030206082B0601050507030306082B0601050507030406082B06010505070308060A2B0601040182370A030406082B0601050507030606082B060105050703070B000000010000003000000047006C006F00620061006C005300690067006E00200052006F006F00740020004300410020002D0020005200330000005300000001000000230000003021301F06092B06010401A032010130123010060A2B0601040182373C0101030200C0620000000100000020000000CBB522D7B7F127AD6A0113865BDF1CD4102E7D0759AF635A7CF4720DC963C53B1400000001000000140000008FF04B7FA82E4524AE4D50FA639A8BDEE2DD1BBC1D000000010000001000000001728E1ECF7A9D86FB3CEC8948ABA953030000000100000014000000D69B561148F01C77C54578C10926DF5B856976AD190000000100000010000000D0FD3C9C380D7B65E26B9A3FEDD39B8F2000000001000000630300003082035F30820247A003020102020B04000000000121585308A2300D06092A864886F70D01010B0500304C3120301E060355040B1317476C6F62616C5369676E20526F6F74204341202D20523331133011060355040A130A476C6F62616C5369676E311330110603550403130A476C6F62616C5369676E301E170D3039303331383130303030305A170D3239303331383130303030305A304C3120301E060355040B1317476C6F62616C5369676E20526F6F74204341202D20523331133011060355040A130A476C6F62616C5369676E311330110603550403130A476C6F62616C5369676E30820122300D06092A864886F70D01010105000382010F003082010A0282010100CC2576907906782216F5C083B684CA289EFD057611C5AD8872FC460243C7B28A9D045F24CB2E4BE1608246E152AB0C8147706CDD64D1EBF52CA30F823D0C2BAE97D7B614861079BB3B1380778C08E149D26A622F1F5EFA9668DF892795389F06D73EC9CB26590D73DEB0C8E9260E8315C6EF5B8BD20460CA49A628F6693BF6CBC82891E59D8A615737AC7414DC74E03AEE722F2E9CFBD0BBBFF53D00E10633E8822BAE53A63A16738CDD410E203AC0B4A7A1E9B24F902E3260E957CBB904926868E538266075B29F77FF9114EFAE2049FCAD401548D1023161195EB897EFAD77B7649A7ABF5FC113EF9B62FB0D6CE0546916A903DA6EE983937176C6698582170203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E041604148FF04B7FA82E4524AE4D50FA639A8BDEE2DD1BBC300D06092A864886F70D01010B050003820101004B40DBC050AAFEC80CEFF796544549BB96000941ACB3138686280733CA6BE674B9BA002DAEA40AD3F5F1F10F8ABF73674A83C7447B78E0AF6E6C6F03298E333945C38EE4B9576CAAFC1296EC53C62DE4246CB99463FBDC536867563E83B8CF3521C3C968FECEDAC253AACC908AE9F05D468C95DD7A58281A2F1DDECD0037418FED446DD75328977EF367041E15D78A96B4D3DE4C27A44C1B737376F41799C21F7A0EE32D08AD0A1C2CFF3CAB550E0F917E36EBC35749BEE12E2D7C608BC3415113239DCEF7326B9401A899E72C331F3A3B25D28640CE3B2C8678C9612F14BAEEDB556FDF84EE05094DBD28D872CED36250651EEB92978331D9B3B5CA47583F5F
3912
WashAndGo.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WashAndGo_RASAPI32
EnableFileTracing
0
3912
WashAndGo.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WashAndGo_RASAPI32
EnableConsoleTracing
0
3912
WashAndGo.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WashAndGo_RASAPI32
FileTracingMask
4294901760
3912
WashAndGo.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WashAndGo_RASAPI32
ConsoleTracingMask
4294901760
3912
WashAndGo.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WashAndGo_RASAPI32
MaxFileSize
1048576
3912
WashAndGo.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WashAndGo_RASAPI32
FileDirectory
%windir%\tracing
3912
WashAndGo.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WashAndGo_RASMANCS
EnableFileTracing
0
3912
WashAndGo.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WashAndGo_RASMANCS
EnableConsoleTracing
0
3912
WashAndGo.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WashAndGo_RASMANCS
FileTracingMask
4294901760
3912
WashAndGo.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WashAndGo_RASMANCS
ConsoleTracingMask
4294901760
3912
WashAndGo.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WashAndGo_RASMANCS
MaxFileSize
1048576
3912
WashAndGo.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WashAndGo_RASMANCS
FileDirectory
%windir%\tracing
3912
WashAndGo.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474
Blob
040000000100000010000000ACB694A59C17E0D791529BB19706A6E40B0000000100000030000000440069006700690043006500720074002000420061006C00740069006D006F0072006500200052006F006F007400000053000000010000006200000030603020060A2B06010401B13E01640130123010060A2B0601040182373C0101030200C0301F06096086480186FD6C020130123010060A2B0601040182373C0101030200C0301B060567810C010130123010060A2B0601040182373C0101030200C00F0000000100000014000000CE0E658AA3E847E467A147B3049191093D055E6F140000000100000014000000E59D5930824758CCACFA085436867B3AB5044DF01D0000000100000010000000918AD43A9475F78BB5243DE886D8103C030000000100000014000000D4DE20D05E66FC53FE1A50882C78DB2852CAE47419000000010000001000000068CB42B035EA773E52EF50ECF50EC52909000000010000003E000000303C06082B0601050507030106082B0601050507030406082B0601050507030206082B0601050507030306082B0601050507030906082B0601050507030862000000010000002000000016AF57A9F676B0AB126095AA5EBADEF22AB31119D644AC95CD4B93DBF3F26AEB20000000010000007B030000308203773082025FA0030201020204020000B9300D06092A864886F70D0101050500305A310B300906035504061302494531123010060355040A130942616C74696D6F726531133011060355040B130A43796265725472757374312230200603550403131942616C74696D6F7265204379626572547275737420526F6F74301E170D3030303531323138343630305A170D3235303531323233353930305A305A310B300906035504061302494531123010060355040A130942616C74696D6F726531133011060355040B130A43796265725472757374312230200603550403131942616C74696D6F7265204379626572547275737420526F6F7430820122300D06092A864886F70D01010105000382010F003082010A0282010100A304BB22AB983D57E826729AB579D429E2E1E89580B1B0E35B8E2B299A64DFA15DEDB009056DDB282ECE62A262FEB488DA12EB38EB219DC0412B01527B8877D31C8FC7BAB988B56A09E773E81140A7D1CCCA628D2DE58F0BA650D2A850C328EAF5AB25878A9A961CA967B83F0CD5F7F952132FC21BD57070F08FC012CA06CB9AE1D9CA337A77D6F8ECB9F16844424813D2C0C2A4AE5E60FEB6A605FCB4DD075902D459189863F5A563E0900C7D5DB2067AF385EAEBD403AE5E843E5FFF15ED69BCF939367275CF77524DF3C9902CB93DE5C923533F1F2498215C079929BDC63AECE76E863A6B97746333BD681831F0788D76BFFC9E8E5D2A86A74D90DC271A390203010001A3453043301D0603551D0E04160414E59D5930824758CCACFA085436867B3AB5044DF030120603551D130101FF040830060101FF020103300E0603551D0F0101FF040403020106300D06092A864886F70D01010505000382010100850C5D8EE46F51684205A0DDBB4F27258403BDF764FD2DD730E3A41017EBDA2929B6793F76F6191323B8100AF958A4D46170BD04616A128A17D50ABDC5BC307CD6E90C258D86404FECCCA37E38C637114FEDDD68318E4CD2B30174EEBE755E07481A7F70FF165C84C07985B805FD7FBE6511A30FC002B4F852373904D5A9317A18BFA02AF41299F7A34582E33C5EF59D9EB5C89E7C2EC8A49E4E08144B6DFD706D6B1A63BD64E61FB7CEF0F29F2EBB1BB7F250887392C2E2E3168D9A3202AB8E18DDE91011EE7E35AB90AF3E30947AD0333DA7650FF5FC8E9E62CF47442C015DBB1DB532D247D2382ED0FE81DC326A1EB5EE3CD5FCE7811D19C32442EA6339A9
2532
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{58968145-CF05-4341-995F-2EE093F6ABA3}
DSOFile OleDocumentProperties
2532
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{58968145-CF05-4341-995F-2EE093F6ABA3}\InprocServer32
ThreadingModel
Apartment
2532
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{58968145-CF05-4341-995F-2EE093F6ABA3}\InprocServer32
C:\ProgramData\Abelssoft\WashAndGo\Program\dsofile.dll
2532
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{58968145-CF05-4341-995F-2EE093F6ABA3}\ProgID
DSOFile.OleDocumentProperties
2532
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DSOFile.OleDocumentProperties
DSO OLE Document Properties Reader 2.1
2532
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\DSOFile.OleDocumentProperties\CLSID
{58968145-CF05-4341-995F-2EE093F6ABA3}
2532
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{58968145-CF00-4341-995F-2EE093F6ABA3}\2.1
DSO OLE Document Properties Reader 2.1
2532
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{58968145-CF00-4341-995F-2EE093F6ABA3}\2.1\FLAGS
0
2532
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{58968145-CF00-4341-995F-2EE093F6ABA3}\2.1\0\win32
C:\ProgramData\Abelssoft\WashAndGo\Program\dsofile.dll
2532
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{58968145-CF00-4341-995F-2EE093F6ABA3}\2.1\HELPDIR
C:\ProgramData\Abelssoft\WashAndGo\Program
2532
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{58968145-CF03-4341-995F-2EE093F6ABA3}
CustomProperty
2532
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{58968145-CF03-4341-995F-2EE093F6ABA3}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
2532
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{58968145-CF03-4341-995F-2EE093F6ABA3}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
2532
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{58968145-CF03-4341-995F-2EE093F6ABA3}\TypeLib
{58968145-CF00-4341-995F-2EE093F6ABA3}
2532
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{58968145-CF03-4341-995F-2EE093F6ABA3}\TypeLib
Version
2.1
2532
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{58968145-CF04-4341-995F-2EE093F6ABA3}
CustomProperties
2532
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{58968145-CF04-4341-995F-2EE093F6ABA3}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
2532
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{58968145-CF04-4341-995F-2EE093F6ABA3}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
2532
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{58968145-CF04-4341-995F-2EE093F6ABA3}\TypeLib
{58968145-CF00-4341-995F-2EE093F6ABA3}
2532
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{58968145-CF04-4341-995F-2EE093F6ABA3}\TypeLib
Version
2.1
2532
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{58968145-CF02-4341-995F-2EE093F6ABA3}
SummaryProperties
2532
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{58968145-CF02-4341-995F-2EE093F6ABA3}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
2532
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{58968145-CF02-4341-995F-2EE093F6ABA3}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
2532
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{58968145-CF02-4341-995F-2EE093F6ABA3}\TypeLib
{58968145-CF00-4341-995F-2EE093F6ABA3}
2532
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{58968145-CF02-4341-995F-2EE093F6ABA3}\TypeLib
Version
2.1
2532
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{58968145-CF01-4341-995F-2EE093F6ABA3}
_OleDocumentProperties
2532
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{58968145-CF01-4341-995F-2EE093F6ABA3}\ProxyStubClsid
{00020424-0000-0000-C000-000000000046}
2532
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{58968145-CF01-4341-995F-2EE093F6ABA3}\ProxyStubClsid32
{00020424-0000-0000-C000-000000000046}
2532
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{58968145-CF01-4341-995F-2EE093F6ABA3}\TypeLib
{58968145-CF00-4341-995F-2EE093F6ABA3}
2532
regsvr32.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{58968145-CF01-4341-995F-2EE093F6ABA3}\TypeLib
Version
2.1
1636
washandgo.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Owner
640600004E45B0E76CA9D501
1636
washandgo.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
SessionHash
1B1B90859CF4140B04A7AF7AA7B9CD1495D79A2D3C7CBA46B7206DA19295DF5E
1636
washandgo.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Sequence
1
1636
washandgo.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
RegFilesHash
649601B582E90ABFF024BFE6E5A896D68E7495C982FFB05FFB8E52D0888605A3
1636
washandgo.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8FFF2B94-7E68-4C49-8CF8-46C7AC3033A1}_is1
Inno Setup: Setup Version
5.6.1 (u)
1636
washandgo.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8FFF2B94-7E68-4C49-8CF8-46C7AC3033A1}_is1
Inno Setup: App Path
C:\Program Files\WashAndGo
1636
washandgo.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8FFF2B94-7E68-4C49-8CF8-46C7AC3033A1}_is1
InstallLocation
C:\Program Files\WashAndGo\
1636
washandgo.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8FFF2B94-7E68-4C49-8CF8-46C7AC3033A1}_is1
Inno Setup: Icon Group
WashAndGo
1636
washandgo.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8FFF2B94-7E68-4C49-8CF8-46C7AC3033A1}_is1
Inno Setup: User
admin
1636
washandgo.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8FFF2B94-7E68-4C49-8CF8-46C7AC3033A1}_is1
Inno Setup: Selected Tasks
desktopicon
1636
washandgo.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8FFF2B94-7E68-4C49-8CF8-46C7AC3033A1}_is1
Inno Setup: Deselected Tasks
quicklaunchicon
1636
washandgo.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8FFF2B94-7E68-4C49-8CF8-46C7AC3033A1}_is1
Inno Setup: Language
en
1636
washandgo.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8FFF2B94-7E68-4C49-8CF8-46C7AC3033A1}_is1
DisplayName
WashAndGo
1636
washandgo.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8FFF2B94-7E68-4C49-8CF8-46C7AC3033A1}_is1
DisplayIcon
C:\ProgramData\Abelssoft\WashAndGo\Program\WashAndGo.exe
1636
washandgo.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8FFF2B94-7E68-4C49-8CF8-46C7AC3033A1}_is1
UninstallString
"C:\Program Files\WashAndGo\unins000.exe"
1636
washandgo.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8FFF2B94-7E68-4C49-8CF8-46C7AC3033A1}_is1
QuietUninstallString
"C:\Program Files\WashAndGo\unins000.exe" /SILENT
1636
washandgo.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8FFF2B94-7E68-4C49-8CF8-46C7AC3033A1}_is1
DisplayVersion
24.8
1636
washandgo.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8FFF2B94-7E68-4C49-8CF8-46C7AC3033A1}_is1
Publisher
Abelssoft
1636
washandgo.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8FFF2B94-7E68-4C49-8CF8-46C7AC3033A1}_is1
URLInfoAbout
http://www.abelssoft.de
1636
washandgo.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8FFF2B94-7E68-4C49-8CF8-46C7AC3033A1}_is1
HelpLink
http://www.abelssoft.de
1636
washandgo.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8FFF2B94-7E68-4C49-8CF8-46C7AC3033A1}_is1
URLUpdateInfo
http://www.abelssoft.de
1636
washandgo.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8FFF2B94-7E68-4C49-8CF8-46C7AC3033A1}_is1
Contact
1636
washandgo.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8FFF2B94-7E68-4C49-8CF8-46C7AC3033A1}_is1
NoModify
1
1636
washandgo.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8FFF2B94-7E68-4C49-8CF8-46C7AC3033A1}_is1
NoRepair
1
1636
washandgo.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8FFF2B94-7E68-4C49-8CF8-46C7AC3033A1}_is1
InstallDate
20191203
1636
washandgo.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8FFF2B94-7E68-4C49-8CF8-46C7AC3033A1}_is1
MajorVersion
24
1636
washandgo.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8FFF2B94-7E68-4C49-8CF8-46C7AC3033A1}_is1
MinorVersion
8
1636
washandgo.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8FFF2B94-7E68-4C49-8CF8-46C7AC3033A1}_is1
VersionMajor
24
1636
washandgo.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8FFF2B94-7E68-4C49-8CF8-46C7AC3033A1}_is1
VersionMinor
8
1636
washandgo.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8FFF2B94-7E68-4C49-8CF8-46C7AC3033A1}_is1
EstimatedSize
57482
1636
washandgo.tmp
delete key
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
2988
AbLauncher.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2988
AbLauncher.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3868
AbLauncher.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3868
AbLauncher.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3056
washandgo.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Owner
F00B000085EB7B1B6DA9D501
3056
washandgo.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
SessionHash
0BE8964BE4CA4F53896E78EE8F63D8D9E90B2EDC946D627845D3AE141CD514D8
3056
washandgo.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Sequence
1
3056
washandgo.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
RegFilesHash
896D05829C714F40B7DF4C2B5C6A8510E3A2B4AD67C645A6618FD9BE91B71C37
4068
unins000.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager
PendingFileRenameOperations
\??\C:\Users\admin\AppData\Local\Temp\_iu14D2N.tmp

Files activity

Executable files
129
Suspicious files
10
Text files
147
Unknown types
3

Dropped files

PID
Process
Filename
Type
4040
washandgo.exe
C:\Users\admin\AppData\Local\Temp\is-13N6L.tmp\washandgo.tmp
executable
MD5: a02d9622855b8c23c07954aa8fd21461
SHA256: 28b0b0410340761591ea5ba1097a4eb59ce2e4d344acbbe7cab9556234c12991
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\SharpDX.DXGI.dll
executable
MD5: fb61d1165a3700269d98f8c386d5f5f6
SHA256: 331d9bb63afcfa73253ee13147119f06420380b4b6f62357616cdb53065a4df4
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\Dll\log4net.dll
executable
MD5: 31e73af0734f4328879c1d96cdc4658c
SHA256: ce6ee4fdc783a5bf905f240178ac96eaeb7ede22ffe06a06ba179cd1a0442bd3
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\SharpDX.dll
executable
MD5: 58391fc37b38ae430038e2291bbfc1b3
SHA256: 57e33bc508e2429742b307843d3d36285b0e79dc9cef3a04e86027d0af9527f0
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\Dll\Compatibility\log4net.dll
executable
MD5: d8bba8e529fa8b26c19ab1456a3d36b2
SHA256: 55ec171867a8867d7587d76e970196cc9adeaebaaaf4ae02db398222007d4281
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\Shredder.dll
executable
MD5: 9caea9675280b1bb5e345b9faadf59f6
SHA256: 2c3d27deeedbbdaf88d00a36cdc48113468bcb6d0c6495b98bda4cc451af5899
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\FolderVisualizer\XDMessaging.dll
executable
MD5: 3c53e5870db6806b58340fcda83f9182
SHA256: f2d1c392597ffb01d472bfff6f53a2db48f0a9d7857aefc06a1876bb26041be9
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\SharpDX.Mathematics.dll
executable
MD5: b635dcd3a3035b74ba6a58f2609e2008
SHA256: 13bc2763f3f7e259dde4e95ced8a467fa6ecf3febe93430cb5b29039644dd2a4
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\FolderVisualizer\Newtonsoft.Json.dll
executable
MD5: 9fbcf62da3f8c85b92d0f182b42ad015
SHA256: 8e655c6fdbebdb59cfdf9315e3a1916108ecd6c9d3596aa5d533580cf27d8f23
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\ShredderVolume.dll
executable
MD5: a43c23f47c7d9e3344f4aefc60dd2c02
SHA256: b8b18c29ef640297e193354a7a4c8a3db4b7f301faf8514bd82e32c0a0c9dfaa
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\SharpDX.Direct3D9.dll
executable
MD5: b92d4f0d8d0d2da5d5c1da6784f92a93
SHA256: 69bbbd514d2f5a1220948ebbb64cc829312857095904ea7b9237160bb533d2d3
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\FolderVisualizer\Microsoft.Windows.Shell.dll
executable
MD5: 36f04f436ef7c451a6a932780ca0c3db
SHA256: d3b79c66b6b656e2da7633cf25c357db63d454d1fadf4927a141ec3bab80a559
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\7z.dll
executable
MD5: f32a74c98f76b90dcf2264f4ec289211
SHA256: 99f61cc4ddf395e87b00150beadb633203901167ca8b619a6a00f0ba513baa1c
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\ShredderVolume64.dll
executable
MD5: 8851201e3091e71e995730ef9a593069
SHA256: 94ecdfa856e3c4c52469aa1b7170dd9c1b1ad47955d870a6d1ffbfad13defc1a
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\SharpDX.Direct3D11.dll
executable
MD5: 78148357fffc60f6ef6902d11637e949
SHA256: a344bc99a6dcafdf8785cade19986dc030c272a67ae5c2d614db1697ebeca74c
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\FolderVisualizer\log4net.dll
executable
MD5: d8bba8e529fa8b26c19ab1456a3d36b2
SHA256: 55ec171867a8867d7587d76e970196cc9adeaebaaaf4ae02db398222007d4281
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\7z64.dll
executable
MD5: 3b882585549c25f48d7821cbc770876b
SHA256: 11be4067b0ddea23d0f483581a5c46a789fc041589623d7bd6b87c51a6a6d409
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\System.Collections.Immutable.dll
executable
MD5: 18966a2c83aa102adb765d00aa089898
SHA256: cd7222a8a335cc3d889cffd05172ad5f9acda68bc2309da27a3dbe7fa1e0e4b0
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\SharpDX.Direct2D1.dll
executable
MD5: b17075c9feea546f9909f5e7ecdc5bca
SHA256: d6fd554c962d841af90d26b0457ea66d04a5bf7d452484e6eb597cdbe08a522b
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\FolderVisualizer\Hardcodet.Wpf.TaskbarNotification.dll
executable
MD5: b2417bede5314ef45c6d175857cec93e
SHA256: 6c5198d71e12cf6d255f6eeb7ab978725abb379f8657ae7ae7696cd6ddbad20e
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\AbCommons.dll
executable
MD5: e22030261299908e935954bb34891c38
SHA256: 9aa7ededd6e0c3f26f6504c2e91b2eb68ec2fdc895d17ed9de4797c64a29c1f6
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\sqlite3.dll
executable
MD5: 8774f2d11075f403407830d4cc6ea425
SHA256: 13dae15471cd0aa6c59b5d3362f79a45c2f3cff84bf0787cf11de990b0e4249d
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\SevenZipSharp.dll
executable
MD5: 665dcdcf9632a7761c49193cb889f765
SHA256: 3f3dc4297713c90df14bfc76fec2a6fe1e079201328a38d0d7d52a7f4827bb5e
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\FolderVisualizer\ICSharpCode.SharpZipLib.dll
executable
MD5: c8164876b6f66616d68387443621510c
SHA256: 40b3d590f95191f3e33e5d00e534fa40f823d9b1bb2a9afe05f139c4e0a3af8d
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\AbApi.dll
executable
MD5: 4dbc39a6f94f953a54707ec04049c9a5
SHA256: 39a6f2edc68690f8bd219111d5fe689582822ccfc6ca38ffdca6caf10c4ae847
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\System.Data.SQLite.DLL
executable
MD5: fd76b931c9009ee206f69043d2be2836
SHA256: eeac7b7a362d550596f67cb32ef0f930b6936d08cb2700564a41bcece3efc7eb
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\RestSharp.dll
executable
MD5: 596bf5644b3fe28d7e9fd2f2aa3dcefa
SHA256: 0719b659263a03084eec0938bf291bbc7b82fe3bb1d7b4421dc66f234f472167
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\FolderVisualizer\FolderEngine.dll
executable
MD5: 07e2659033b7eefdd1af419e26f472f1
SHA256: 4470566476f99449e0970e360df11cc60253b542349c980d6dfc07673184d408
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\AbBugReporter.dll
executable
MD5: daa00ab68a30ee55c8bd46a8e74e43b5
SHA256: 5809c58ff09574f88168e77a3e50102093b2d6f3728fb22d2769bdc066ac9523
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\System.Windows.Interactivity.dll
executable
MD5: ecb59e384f61d60c9063ac7b646fb0b6
SHA256: a51fdefff855d93d6189faf84a43f4884903d9c07ecf67f5e7046c914bb89d6b
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\ScheduleTasks.dll
executable
MD5: dbce5339c1617358a0d8c4ea0667a237
SHA256: 44d80e9c802d8b3a960731c8ba418a17c940a7933b1b7339334426880abd41cf
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\FolderVisualizer\AbWpfRegistration.dll
executable
MD5: 2dee566e6515de0b62226e9112e8693a
SHA256: 4d7fe29c0bbd43b61a71de1d1a0f2245e409ddb6aaf806dd4f33830c5abea04b
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\AbAnalytics.dll
executable
MD5: 46216b9fb8c4ac923e3b1156bb498fea
SHA256: 2e7a7202aebf2a119f19cd781be8d60f736dbb370f9e45fdb39c3ff47b1dd796
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\TaskScheduler.dll
executable
MD5: eab6035a0bc63c96abb3ea0322c5b081
SHA256: 7c9a868eea17da8d48f8505c9e60fc72e39ca941b0b8e8a7ff7af3076c6647b5
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\RegCleaner.dll
executable
MD5: c9ee2ea08a782cec29f78f1aef962036
SHA256: 029fff95d2bb4c2c4da0c63c947eaeecdf2b27548dc088c26e919e4b630351ab
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\FolderVisualizer\AbUpdater.dll
executable
MD5: f25df26b1f67339fa571c4950da0cb05
SHA256: c2d266759d0f4e834dcfc36deeacacbb668b998679f2e0b3e89a722892b2cd84
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\AbDefault.dll
executable
MD5: 05aa36fa7efbc832ce0ec4d93f1ca267
SHA256: e2b9535ed443220c3373776738c9a09379e63f65bbda74ffc09d81642efefeb0
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\System.Reflection.Metadata.dll
executable
MD5: c36c6be18e020d2b206c5f7da65233ca
SHA256: 62b9dd5e0f47723c0178694b96a93d63c42d2e48bd68eefb300c05956ca9e8d5
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\PdfSharp-WPF.dll
executable
MD5: eda52321fea039c52163bfc63bcd15a0
SHA256: 36f3753cf09a6acbafb13a81ae03625104c7c45ac216970704508fe34edf68e9
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\FolderVisualizer\AbSettingsKeeper.dll
executable
MD5: a73779c8335e6ff3896ae0b22a0ac05e
SHA256: 7fad2da5fd61f562ccec8fd9b2e236a8a1d1cf35c825173840b398a58de92169
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\AbDriveScan.dll
executable
MD5: d58ca84b5c869c9a6d1616b354eb591d
SHA256: 7c32c90704519660b90deca0e62353ba1dc11819719ea72a6400c3545bcc7229
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\WashAndGo.Api.dll
executable
MD5: 996da0d76051525e8971d7708b41632a
SHA256: 4821b6d36bd6c06cdc1f88f07d1bfeb7a9aa2a9b6779e8c6883ec291ed24e177
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\OutlookCleaner.dll
executable
MD5: ce453e3d86630b71d6200903ff98107e
SHA256: c7bfd3d5a43f76f16f60c942698b38a64907163bfde4948a64a58c185fe45973
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\FolderVisualizer\AbSettings.dll
executable
MD5: 694856845cc1e3abd1a4d02ee4bbe487
SHA256: 7487a6e08c2c3066be80b762c846c987322ea1ce5c706092b0f3c433ee3ea7e1
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\AbDownloader.dll
executable
MD5: 467776a9246fbcef132b5da6133b8760
SHA256: c8fb6975463058cb45c1e2df4346ab682eb80c54d86edba92ca727e071ce67c3
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\ZetaLongPaths.dll
executable
MD5: ee1b04dea87bda7177c0db8e0397c819
SHA256: c4d8a95baa45680ed7f74a836271e7af340d1c5962e14b3f64f0e239e82af06e
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\Ookii.Dialogs.Wpf.dll
executable
MD5: 24e228df69e919d073527d782200a50f
SHA256: 059e24da194700ed94655760dfeac96c169c3401898f280fa1377dfbb3e9cf94
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\FolderVisualizer\AbLiteRegistration.dll
executable
MD5: 5555f3ee017ec3fc54a7de1b79a5a43b
SHA256: c76be610bc1afe7e96dc859a176f7e1de52cf5cbee890fa4556499f3d9696b06
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\AbelssoftPDF.dll
executable
MD5: 824f513a7ffba197c98ea060be470be8
SHA256: 76a3add14a25f0ab37aee579301019ce46da051b39517f6a0b07656693ba4d22
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\WashAndGoLegacyUninstaller.exe
executable
MD5: 298d80725a3e4e3fa52d00ca6aea7d81
SHA256: d23f6cd9e643f8f39cdfc27649978628e79cc54d09f08938b67ffc3f823edf08
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\OWL.dll
executable
MD5: ccb7bc8d3b0f7ccb13531cb7998e983a
SHA256: d22a81c48cdc5ac4970c4876bb885ccc4bf77548ede9d54d656a46d23b46279a
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\FolderVisualizer\AbGui.dll
executable
MD5: 89aa7add9067a7852777d616d76118a3
SHA256: dbe51142ffe3ec1cc4fb9a483ecd69c17029ea432be05ab0a142f313ff196076
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\AbFlexTrans.dll
executable
MD5: 9c217b76b723941bb840b1862e86dc68
SHA256: 43eaf78d354801dcf1748ae292c139de37ec7668bb2003d3e9121badc3b417bf
4068
unins000.exe
C:\Users\admin\AppData\Local\Temp\_iu14D2N.tmp
executable
MD5: ac59ffe0b2a0ba58446541e7c1cf7ed9
SHA256: 5f1b5e5892387db0a9afc58f7d596d5c4401a938500a47b5543026b9e2a78500
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\Newtonsoft.Json.dll
executable
MD5: 0bf4075f2b7cf44336bb240dc0547fd5
SHA256: e4530ca6bf49e829ccc98f4ad4aae759d193d28fea17de3b1678c3b5741684ec
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\FolderVisualizer\AbFlexTrans.dll
executable
MD5: 28d2b341d66b93a20b1173a51012acda
SHA256: 3ac03b92285f9ec02a0c48477081cc7dd1b3af63652c2da8ddfbcf069d6717f8
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\AbGui.dll
executable
MD5: 0a47c4f755499fe500f4229a0caa820e
SHA256: 1f8589c3e66a7afd77c7ba689983796004af9b04b8efe52e82626286433b90b3
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\Interop.DSOFile.dll
executable
MD5: c4fb30ab6e6def700d98072ceb059d54
SHA256: dea1b85669e7b3c116e04955797f6e646c30b562df40f4e59c399bf05365956e
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\MsOfficeFileCleaner.dll
executable
MD5: be24799b170943f9dc6a7a75dd74f458
SHA256: a64504401ce59822b74dc636d8284f678c1ff503edec80845a872ff0024685f7
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\FolderVisualizer\AbCommons.dll
executable
MD5: d66cee45a23162eaf0e6ed8a4e201869
SHA256: deb7358f7f02898084719b6251c6e05e4de49ded45b98c23232be85a2469021d
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\AbLanguage.dll
executable
MD5: 382cca13e11fe46650b0271f97126851
SHA256: d4ddc86f1dfbf68f1ecf85498744d5d81c07c261c67d40c6394ec992197a3aa5
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\dsofile.dll
executable
MD5: 7d80167166c46b370e3a0f90b650a5e3
SHA256: 105995da97b2893f6f4fcdefc0c4fd39f0a1774aa772deb43e6ec2756f860d3e
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\Microsoft.Windows.Shell.dll
executable
MD5: 766310404050fd0fbf10a581550ab99b
SHA256: 9a02dd969277e635a56633273d959a2498a0f5a83cb86434e80858486f979c8c
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\FolderVisualizer\AbBugReporter.dll
executable
MD5: 4e756babee8d7fc44e221e6332f77101
SHA256: 654649a7d697a540a80c5183bacb7e26df07d1072ba9fbe9849ddbfe0b0a0057
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\AbLauncher.UpdateRoutines.dll
executable
MD5: 8e0c7ed92d15e7041a0543e70ba551b5
SHA256: 4d24aa0bd690f43b3f4f70d33fb69fb2e86c0fd180f95963a71e9aa89b203d2a
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\System.Data.SQLite.DLL
executable
MD5: 2cdb00b64b0e4b6b6153b628afca940f
SHA256: 122c7779fd7bce6e29c4614ba566bfb995b75b339aa7c022d2fd2e99e62e79c2
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\MahApps.Metro.dll
executable
MD5: 8f4e875f97bc7de877467b1580af47fa
SHA256: 3438605cc25e546df21b6efca9b7627ed15eb076814f732086fdfc710082bc7c
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\FolderVisualizer\AbApi.dll
executable
MD5: 5c53caf2a7f1e7a9e3136e1c2547e89c
SHA256: 7dac0b782159420a129ae9959d76dc1e71834c554668663b5a49a264e383fc29
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\AbLauncher.UpdateRoutines.Plugin.Base.dll
executable
MD5: 0afce2f4cbcfa7e2a11aa42a046764af
SHA256: 7f86297d22f7dc59ebdb7e28c2a3793a920516e555f8831f67bddf58ac9b5e57
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\Dll\x86\SQLite3.DLL
executable
MD5: a00f7a0d92e7baad9756bf87afdcd378
SHA256: 3159e0293a36e76591585512ac450db9b420d8229ef5c1ff845e7d00ccbfbf33
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\Microsoft.Expression.Drawing.dll
executable
MD5: 12ac88f0d7ba24e391246955f7d78923
SHA256: 6e61bb8ce9566d13f4bb7d80ae3e6c923e088087210f61982d67b1aeb0df316d
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\FolderVisualizer\FolderVisualizer.exe
executable
MD5: c7254c03b3fe638744cf98fec00cdef0
SHA256: f99f603fffb064a3313a1bd7daf6f9efbf0754d145a44698065088acb4a55bb8
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\AbLiteRegistration.dll
executable
MD5: eb380fd44bbd363b60654e6f4ca4feb2
SHA256: 589ee5010fd027f6c8ab7c0aacb64b95614974aa1b343399ca78ffd782fb2e4e
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\Dll\x86\System.Data.SQLite.DLL
executable
MD5: 2cdb00b64b0e4b6b6153b628afca940f
SHA256: 122c7779fd7bce6e29c4614ba566bfb995b75b339aa7c022d2fd2e99e62e79c2
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\LottieSharp.dll
executable
MD5: 0a6e82cb711a7e2f7d75675f131d34a7
SHA256: 392529d64ae27edfc2f111934494ae0fe7c94be34a09d8d3dc51722020ae7e76
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\AbelssoftPreloader.exe
executable
MD5: 95076262d3aa190b4a2bad7c69bf96c8
SHA256: 1ce3fa6ee13c266ad87edaeb04cc4aa0336686c21c00db4530f9c22b70623568
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\AbLog.dll
executable
MD5: fc8104b5c0178b6725a08e2d039ede06
SHA256: ef8993a0ee32d9617a04a6bade51fdf0a01004b0640d87b40b5fd1fdda12118d
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\SQLite3.DLL
executable
MD5: a00f7a0d92e7baad9756bf87afdcd378
SHA256: 3159e0293a36e76591585512ac450db9b420d8229ef5c1ff845e7d00ccbfbf33
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\log4net.dll
executable
MD5: f422583d1d35577ac63225cca5eb29d5
SHA256: c95f93113214c19a4e4fc74f38f5a2c962fce796d701817b141684f910a88acb
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\OutlookExpressWrapper.exe
executable
MD5: 77f8df764cb2d63aa34da7f611a56885
SHA256: 81316caafdea918313a934436ad95f3eaa7140e23127d54a0c4295ae492b5805
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\AbLog.Commons.dll
executable
MD5: fa4d5db3b2f3d47dd55472dacece2863
SHA256: 52f501c7e84c11c3685621bc4adf27fc3b84767a95c3ca69c48f2cb53c9fd56c
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\Dll\x86\Interop.DSOFile.dll
executable
MD5: c4fb30ab6e6def700d98072ceb059d54
SHA256: dea1b85669e7b3c116e04955797f6e646c30b562df40f4e59c399bf05365956e
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\Ionic.Zip.dll
executable
MD5: 1bf4712d293bfae67b55e3c657957d00
SHA256: 9cf4b95314eaf222ba79e8cfdb70fa6605b803884ae908605e96506f168ba305
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\OutlookExpressWrapper64.exe
executable
MD5: 4993c89b11e962357b4b3587271a83b1
SHA256: 5ddfa6ebb4d08c36de08c25d60f472e4506b22a2755c25cf59dc2a6f273008b3
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\AbLogger.dll
executable
MD5: 6972135ebb61d2dfce62ad09b60a7f5b
SHA256: a3ee101a1e460087247d75c058cdaaeaccc5f6cbe4c2ab776f4aa8cae26bb872
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\Dll\x64\System.Data.SQLite.DLL
executable
MD5: c074b9a71419ef22f724cffda7783b78
SHA256: 717e8e6fe3df87abcfab9937519f5f5b3b7ed669ee8c246e945b852c1014ec2e
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\JumpListCleaner.dll
executable
MD5: f63f9146a8b8380c362f5cebe9cccb47
SHA256: f3fb73b14b03d8330b5017e56fd2cb95e8fb032573a8fb5f5c7f8c2f81684bd7
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\WashFusion.exe
executable
MD5: 3b574dd58d5054941181bd62e6af5d44
SHA256: 239ac5d55fa6ab3c093bcb67d2c171a2b40786b4b9a761d955983e3473ebb39a
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\AbLogInstance.dll
executable
MD5: 19ac56dd96e7ddb616e700ea26e47b02
SHA256: 6489d9b4b528cda2a6ddfc72d01df1e74b7f432cfb34ec6d2022a02765e107a5
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\Dll\x64\SQLite3.DLL
executable
MD5: 44ad3590de5f7d22f98ee33dd7250591
SHA256: 3b84f8f751eca6ca90d62dc0a1ca90641ad21905da484aa3d2f78fb2f3e6cffe
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\ICSharpCode.SharpZipLib.dll
executable
MD5: e1967a48330dfbf1d0b501ea57b8de1f
SHA256: 47a258517caa8c79974d4c45e6cd8cbd3d7e404f0eb1ae23b94d79ecdc997ba4
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\WashAndGo.exe
executable
MD5: 861b89d76dd049929bc9967b016da49d
SHA256: b5b4c11cdc4cfeee8f6f7ef660abfa076a7c5bc3edd146bfe8c5d325519a2428
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\AbProcessManager.dll
executable
MD5: 01577910b483ae8132c46f4d50af82b4
SHA256: 4dfd2757024c8533c18163f2d2d89f8a8c55ca89b55518d88b4bca631d08e4c1
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\Dll\x64\Interop.DSOFile.dll
executable
MD5: dcda414d04ac013a4b9817d5d3e016bf
SHA256: 118e696a317cbe9a3c6bde6a3f0eeb7aea97ad7b55d587c21be64b6e751e27a5
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\FusionScanner.dll
executable
MD5: 1847f7ca559e2ed8e12884d4aee3fb9a
SHA256: 7d6fac499e973874dd89a73697ac4f0c48a7d53e01282c6b6739a65d9391e61a
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\AbLauncher.exe
executable
MD5: 6baed5f28337aa22934603222e59fdc4
SHA256: 623831440126d8b9cf18c695a2ce108d0e3386c73d501504bda5bec2252d027e
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\AbRegistration.dll
executable
MD5: 0da03a1dca6d2e59d3d2d797d3301929
SHA256: 3a3fe810f24f91105184bd87487ab1af5d06755b5ec23a5a6a64a69843201b89
1636
washandgo.tmp
C:\Program Files\WashAndGo\WashAndGoSetup.exe
executable
MD5: 3e0e6d1fabe1434cab204124e9baaf49
SHA256: cc34f4b540b59f232a1bb5340e7bfa9fe616a1f3a33723d6b7c25e4dca79ae19
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\FusionGlobal.dll
executable
MD5: 62c6ba36921243f0a08b2a8e5392a75c
SHA256: 2851b0f2bf9c7bc9b02dcccb2ee22f644a27e52a6127cc9624867456ed46a739
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\NmGui.exe
executable
MD5: 73fecf8470e9c96bc1a2728e86e24162
SHA256: 284cefb7b26c64abed19feb9e169b7c3214786057d1fbf0c43398271ffccdfc3
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\AbRegistryScanner.dll
executable
MD5: eeca38c96f49dea4eef5dfbeeb88d32a
SHA256: 968da6c159c35ce2713c228c0b1b88fbfa6c097d0f1ea7b30b318871844c16c9
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\AbTranslator.exe
executable
MD5: 965389bd5f166cc066e3927154a9489c
SHA256: a01208d233275b94030fdfa447104597b6a4b30230b33f670f626907e63e7494
1636
washandgo.tmp
C:\ProgramData\Abelssoft\WashAndGo\Program\FusionComparison.dll
executable
MD5: 56a68539d8a6632b72369568886abadf
SHA256: efe9970f261de35cd4c383e8d3ec8f3a5e843285de84c93a72eaa63024837c85
1636
washandgo.tmp
C:\Program Files\WashAndGo\AbLauncher.UpdateRoutines.Plugin.Base.dll