General Info

File name

LockerGoga.exe

Full analysis
https://app.any.run/tasks/d0a37902-ac88-4551-a6dd-dfa43b4095dd
Verdict
Malicious activity
Analysis date
7/11/2019, 21:54:30
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:

ransomware

Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

e11502659f6b5c5bd9f78f534bc38fea

SHA1

b5fd5c913de8cbb8565d3c7c67c0fbaa4090122b

SHA256

c97d9bbc80b573bdeeda3812f4d00e5183493dd0d5805e2508728f65977dda15

SSDEEP

24576:645Rt4El7fc/TFJzjJUgrrCq5sNIwQsUGy1q7a9DlIACTp+kqGslRG:Rjt4El7fc/TFJWstwQsPdSDuACTpqhG

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
300 seconds
Additional time used
240 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (75.0.3770.100)
  • Google Update Helper (1.3.34.7)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.7.2 (4.7.03062)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (14.21.27702.2)
  • Microsoft Visual C++ 2019 X86 Additional Runtime - 14.21.27702 (14.21.27702)
  • Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.21.27702 (14.21.27702)
  • Mozilla Firefox 67.0.4 (x86 en-US) (67.0.4)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • Update for Microsoft .NET Framework 4.7.2 (KB4087364) (1)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB4019990
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Starts NET.EXE to view/add/change user profiles
  • tgytutrc2548.exe (PID: 3396)
Executable content was dropped or overwritten
  • cmd.exe (PID: 2820)
Creates files like Ransomware instruction
  • LockerGoga.exe (PID: 3704)
Starts CMD.EXE for commands execution
  • LockerGoga.exe (PID: 3704)
Application launched itself
  • tgytutrc2548.exe (PID: 3396)
Dropped object may contain Bitcoin addresses
  • tgytutrc2548.exe (PID: 4016)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable (generic) (52.9%)
.exe
|   Generic Win/DOS Executable (23.5%)
.exe
|   DOS Executable Generic (23.5%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2019:03:18 10:07:54+01:00
PEType:
PE32
LinkerVersion:
14.16
CodeSize:
950784
InitializedDataSize:
322048
UninitializedDataSize:
null
EntryPoint:
0x9d54b
OSVersion:
5.1
ImageVersion:
null
SubsystemVersion:
5.1
Subsystem:
Windows GUI
FileVersionNumber:
1.5.1.0
ProductVersionNumber:
1.5.1.0
FileFlagsMask:
0x003f
FileFlags:
(none)
FileOS:
Win32
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
Neutral
CharacterSet:
Unicode
CompanyName:
ALISA LTD
FileDescription:
Background Tasks Host
FileVersion:
1.5.1.0
InternalName:
tgytutrc
LegalCopyright:
Copyright (C) ALISA LTD 2019
OriginalFileName:
tgytutrc
ProductName:
Service tgytutrc
ProductVersion:
1.5.1.0
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
18-Mar-2019 09:07:54
Detected languages
English - United States
CompanyName:
ALISA LTD
FileDescription:
Background Tasks Host
FileVersion:
1.5.1.0
InternalName:
tgytutrc
LegalCopyright:
Copyright (C) ALISA LTD 2019
OriginalFilename:
tgytutrc
ProductName:
Service tgytutrc
ProductVersion:
1.5.1.0
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x00000118
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
5
Time date stamp:
18-Mar-2019 09:07:54
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_NET_RUN_FROM_SWAP
IMAGE_FILE_REMOVABLE_RUN_FROM_SWAP
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x000E8032 0x000E8200 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.65764
.rdata 0x000EA000 0x000346CE 0x00034800 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 5.00574
.data 0x0011F000 0x0000B6FC 0x00009000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 4.906
.rsrc 0x0012B000 0x00000508 0x00000600 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 3.71326
.reloc 0x0012C000 0x0000E228 0x0000E400 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_DISCARDABLE,IMAGE_SCN_MEM_READ 6.55487
Resources
1

Imports
    SHLWAPI.dll

    NETAPI32.dll

    IPHLPAPI.DLL

    Secur32.dll

    KERNEL32.dll

    SHELL32.dll

    ole32.dll

    ADVAPI32.dll

    WS2_32.dll

Exports

    No exports.

Screenshots

Processes

Total processes
74
Monitored processes
29
Malicious processes
2
Suspicious processes
0

Behavior graph

+
start lockergoga.exe no specs lockergoga.exe cmd.exe tgytutrc2548.exe no specs logoff.exe no specs logoff.exe no specs logoff.exe no specs logoff.exe no specs logoff.exe no specs logoff.exe no specs net.exe no specs net1.exe no specs net.exe no specs net1.exe no specs tgytutrc2548.exe tgytutrc2548.exe tgytutrc2548.exe tgytutrc2548.exe tgytutrc2548.exe tgytutrc2548.exe tgytutrc2548.exe tgytutrc2548.exe tgytutrc2548.exe tgytutrc2548.exe tgytutrc2548.exe tgytutrc2548.exe tgytutrc2548.exe no specs tgytutrc2548.exe no specs tgytutrc2548.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3064
CMD
"C:\Users\admin\AppData\Local\Temp\LockerGoga.exe"
Path
C:\Users\admin\AppData\Local\Temp\LockerGoga.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
ALISA LTD
Description
Background Tasks Host
Version
1.5.1.0
Modules
Image
c:\users\admin\appdata\local\temp\lockergoga.exe
c:\systemroot\system32\ntdll.dll

PID
3704
CMD
"C:\Users\admin\AppData\Local\Temp\LockerGoga.exe"
Path
C:\Users\admin\AppData\Local\Temp\LockerGoga.exe
Indicators
Parent process
––
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\lockergoga.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cmd.exe
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\tgytutrc2548.e

PID
2820
CMD
C:\Windows\system32\cmd.exe /c move /y C:\Users\admin\AppData\Local\Temp\LockerGoga.exe C:\Users\admin\AppData\Local\Temp\tgytutrc2548.exe
Path
C:\Windows\system32\cmd.exe
Indicators
Parent process
LockerGoga.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
3396
CMD
C:\Users\admin\AppData\Local\Temp\tgytutrc2548.exe -m
Path
C:\Users\admin\AppData\Local\Temp\tgytutrc2548.exe
Indicators
No indicators
Parent process
LockerGoga.exe
User
admin
Integrity Level
HIGH
Version:
Company
ALISA LTD
Description
Background Tasks Host
Version
1.5.1.0
Modules
Image
c:\users\admin\appdata\local\temp\tgytutrc2548.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\logoff.exe
c:\windows\system32\apphelp.dll
c:\windows\system32\samlib.dll
c:\windows\system32\net.exe
c:\users\admin\appdata\local\temp\tgytutrc2548.e

PID
2740
CMD
C:\Windows\system32\logoff.exe 0
Path
C:\Windows\system32\logoff.exe
Indicators
No indicators
Parent process
tgytutrc2548.exe
User
admin
Integrity Level
HIGH
Exit code
1
Version:
Company
Microsoft Corporation
Description
Session Logoff Utility
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\logoff.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winsta.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\utildll.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\logoncli.dll
c:\windows\system32\browcli.dll
c:\windows\system32\samcli.dll

PID
3040
CMD
C:\Windows\system32\logoff.exe 0
Path
C:\Windows\system32\logoff.exe
Indicators
No indicators
Parent process
tgytutrc2548.exe
User
admin
Integrity Level
HIGH
Exit code
1
Version:
Company
Microsoft Corporation
Description
Session Logoff Utility
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\logoff.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winsta.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\utildll.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\logoncli.dll
c:\windows\system32\browcli.dll
c:\windows\system32\samcli.dll

PID
3444
CMD
C:\Windows\system32\logoff.exe 0
Path
C:\Windows\system32\logoff.exe
Indicators
No indicators
Parent process
tgytutrc2548.exe
User
admin
Integrity Level
HIGH
Exit code
1
Version:
Company
Microsoft Corporation
Description
Session Logoff Utility
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\logoff.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winsta.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\utildll.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\logoncli.dll
c:\windows\system32\browcli.dll
c:\windows\system32\samcli.dll

PID
4056
CMD
C:\Windows\system32\logoff.exe 0
Path
C:\Windows\system32\logoff.exe
Indicators
No indicators
Parent process
tgytutrc2548.exe
User
admin
Integrity Level
HIGH
Exit code
1
Version:
Company
Microsoft Corporation
Description
Session Logoff Utility
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\logoff.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winsta.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\utildll.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\logoncli.dll
c:\windows\system32\browcli.dll
c:\windows\system32\samcli.dll

PID
2448
CMD
C:\Windows\system32\logoff.exe 0
Path
C:\Windows\system32\logoff.exe
Indicators
No indicators
Parent process
tgytutrc2548.exe
User
admin
Integrity Level
HIGH
Exit code
1
Version:
Company
Microsoft Corporation
Description
Session Logoff Utility
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\logoff.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winsta.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\utildll.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\logoncli.dll
c:\windows\system32\browcli.dll
c:\windows\system32\samcli.dll

PID
2908
CMD
C:\Windows\system32\logoff.exe 0
Path
C:\Windows\system32\logoff.exe
Indicators
No indicators
Parent process
tgytutrc2548.exe
User
admin
Integrity Level
HIGH
Exit code
1
Version:
Company
Microsoft Corporation
Description
Session Logoff Utility
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\logoff.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winsta.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\utildll.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\logoncli.dll
c:\windows\system32\browcli.dll
c:\windows\system32\samcli.dll

PID
3780
CMD
C:\Windows\system32\net.exe user admin [email protected]
Path
C:\Windows\system32\net.exe
Indicators
No indicators
Parent process
tgytutrc2548.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Net Command
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\net.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\netutils.dll
c:\windows\system32\browcli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\mpr.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\net1.exe

PID
2268
CMD
C:\Windows\system32\net1 user admin [email protected]
Path
C:\Windows\system32\net1.exe
Indicators
No indicators
Parent process
net.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Net Command
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\net1.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\netutils.dll
c:\windows\system32\logoncli.dll
c:\windows\system32\browcli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\samlib.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\netmsg.dll

PID
3968
CMD
C:\Windows\system32\net.exe user Administrator [email protected]
Path
C:\Windows\system32\net.exe
Indicators
No indicators
Parent process
tgytutrc2548.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Net Command
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\net.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\netutils.dll
c:\windows\system32\browcli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\mpr.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\apphelp.dll

PID
2936
CMD
C:\Windows\system32\net1 user Administrator [email protected]
Path
C:\Windows\system32\net1.exe
Indicators
No indicators
Parent process
net.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Net Command
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\net1.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\netutils.dll
c:\windows\system32\logoncli.dll
c:\windows\system32\browcli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\samlib.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\netmsg.dll

PID
3860
CMD
C:\Users\admin\AppData\Local\Temp\tgytutrc2548.exe -i SM-tgytutrc -s
Path
C:\Users\admin\AppData\Local\Temp\tgytutrc2548.exe
Indicators
Parent process
tgytutrc2548.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
ALISA LTD
Description
Background Tasks Host
Version
1.5.1.0
Modules
Image
c:\users\admin\appdata\local\temp\tgytutrc2548.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\bcryptprimitives.dll

PID
3932
CMD
C:\Users\admin\AppData\Local\Temp\tgytutrc2548.exe -i SM-tgytutrc -s
Path
C:\Users\admin\AppData\Local\Temp\tgytutrc2548.exe
Indicators
Parent process
tgytutrc2548.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
ALISA LTD
Description
Background Tasks Host
Version
1.5.1.0
Modules
Image
c:\users\admin\appdata\local\temp\tgytutrc2548.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\bcryptprimitives.dll

PID
4016
CMD
C:\Users\admin\AppData\Local\Temp\tgytutrc2548.exe -i SM-tgytutrc -s
Path
C:\Users\admin\AppData\Local\Temp\tgytutrc2548.exe
Indicators
Parent process
tgytutrc2548.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
ALISA LTD
Description
Background Tasks Host
Version
1.5.1.0
Modules
Image
c:\users\admin\appdata\local\temp\tgytutrc2548.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\bcryptprimitives.dll

PID
252
CMD
C:\Users\admin\AppData\Local\Temp\tgytutrc2548.exe -i SM-tgytutrc -s
Path
C:\Users\admin\AppData\Local\Temp\tgytutrc2548.exe
Indicators
Parent process
tgytutrc2548.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
ALISA LTD
Description
Background Tasks Host
Version
1.5.1.0
Modules
Image
c:\users\admin\appdata\local\temp\tgytutrc2548.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\bcryptprimitives.dll

PID
2468
CMD
C:\Users\admin\AppData\Local\Temp\tgytutrc2548.exe -i SM-tgytutrc -s
Path
C:\Users\admin\AppData\Local\Temp\tgytutrc2548.exe
Indicators
Parent process
tgytutrc2548.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
ALISA LTD
Description
Background Tasks Host
Version
1.5.1.0
Modules
Image
c:\users\admin\appdata\local\temp\tgytutrc2548.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\bcryptprimitives.dll

PID
3716
CMD
C:\Users\admin\AppData\Local\Temp\tgytutrc2548.exe -i SM-tgytutrc -s
Path
C:\Users\admin\AppData\Local\Temp\tgytutrc2548.exe
Indicators
Parent process
tgytutrc2548.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
ALISA LTD
Description
Background Tasks Host
Version
1.5.1.0
Modules
Image
c:\users\admin\appdata\local\temp\tgytutrc2548.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\bcryptprimitives.dll

PID
2992
CMD
C:\Users\admin\AppData\Local\Temp\tgytutrc2548.exe -i SM-tgytutrc -s
Path
C:\Users\admin\AppData\Local\Temp\tgytutrc2548.exe
Indicators
Parent process
tgytutrc2548.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
ALISA LTD
Description
Background Tasks Host
Version
1.5.1.0
Modules
Image
c:\users\admin\appdata\local\temp\tgytutrc2548.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\bcryptprimitives.dll

PID
2684
CMD
C:\Users\admin\AppData\Local\Temp\tgytutrc2548.exe -i SM-tgytutrc -s
Path
C:\Users\admin\AppData\Local\Temp\tgytutrc2548.exe
Indicators
Parent process
tgytutrc2548.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
ALISA LTD
Description
Background Tasks Host
Version
1.5.1.0
Modules
Image
c:\users\admin\appdata\local\temp\tgytutrc2548.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\bcryptprimitives.dll

PID
3440
CMD
C:\Users\admin\AppData\Local\Temp\tgytutrc2548.exe -i SM-tgytutrc -s
Path
C:\Users\admin\AppData\Local\Temp\tgytutrc2548.exe
Indicators
Parent process
tgytutrc2548.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
ALISA LTD
Description
Background Tasks Host
Version
1.5.1.0
Modules
Image
c:\users\admin\appdata\local\temp\tgytutrc2548.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\bcryptprimitives.dll

PID
3892
CMD
C:\Users\admin\AppData\Local\Temp\tgytutrc2548.exe -i SM-tgytutrc -s
Path
C:\Users\admin\AppData\Local\Temp\tgytutrc2548.exe
Indicators
Parent process
tgytutrc2548.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
ALISA LTD
Description
Background Tasks Host
Version
1.5.1.0
Modules
Image
c:\users\admin\appdata\local\temp\tgytutrc2548.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\bcryptprimitives.dll

PID
4008
CMD
C:\Users\admin\AppData\Local\Temp\tgytutrc2548.exe -i SM-tgytutrc -s
Path
C:\Users\admin\AppData\Local\Temp\tgytutrc2548.exe
Indicators
Parent process
tgytutrc2548.exe
User
admin
Integrity Level
HIGH
Version:
Company
ALISA LTD
Description
Background Tasks Host
Version
1.5.1.0
Modules
Image
c:\users\admin\appdata\local\temp\tgytutrc2548.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\bcryptprimitives.dll

PID
2796
CMD
C:\Users\admin\AppData\Local\Temp\tgytutrc2548.exe -i SM-tgytutrc -s
Path
C:\Users\admin\AppData\Local\Temp\tgytutrc2548.exe
Indicators
Parent process
tgytutrc2548.exe
User
admin
Integrity Level
HIGH
Version:
Company
ALISA LTD
Description
Background Tasks Host
Version
1.5.1.0
Modules
Image
c:\users\admin\appdata\local\temp\tgytutrc2548.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rstrtmgr.dll

PID
2420
CMD
C:\Users\admin\AppData\Local\Temp\tgytutrc2548.exe -i SM-tgytutrc -s
Path
C:\Users\admin\AppData\Local\Temp\tgytutrc2548.exe
Indicators
No indicators
Parent process
tgytutrc2548.exe
User
admin
Integrity Level
HIGH
Version:
Company
ALISA LTD
Description
Background Tasks Host
Version
1.5.1.0
Modules
Image
c:\users\admin\appdata\local\temp\tgytutrc2548.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\secur32.dll

PID
3728
CMD
C:\Users\admin\AppData\Local\Temp\tgytutrc2548.exe -i SM-tgytutrc -s
Path
C:\Users\admin\AppData\Local\Temp\tgytutrc2548.exe
Indicators
No indicators
Parent process
tgytutrc2548.exe
User
admin
Integrity Level
HIGH
Version:
Company
ALISA LTD
Description
Background Tasks Host
Version
1.5.1.0
Modules
Image
c:\users\admin\appdata\local\temp\tgytutrc2548.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll

PID
3044
CMD
C:\Users\admin\AppData\Local\Temp\tgytutrc2548.exe -i SM-tgytutrc -s
Path
C:\Users\admin\AppData\Local\Temp\tgytutrc2548.exe
Indicators
No indicators
Parent process
tgytutrc2548.exe
User
admin
Integrity Level
HIGH
Version:
Company
ALISA LTD
Description
Background Tasks Host
Version
1.5.1.0
Modules
Image

Registry activity

Total events
952
Read events
387
Write events
565
Delete events
0

Modification events

PID
Process
Operation
Key
Name
Value
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0002
Owner
140F0000022D76832238D501
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0002
SessionHash
02043B3558A2613FF56EA4232750DFBA86F537B348FCE5BA4BA6D93E290A3020
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0002
Sequence
1
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0002
RegFiles0000
C:\MSOCache\All Users\{90140000-002C-0409-0000-0000000FF1CE}-C\Proofing.xml
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0002
RegFilesHash
4AD3A97E7FC18F2A5702238225DCF3667E802B75134F97ADF069A0A2F06915A2
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0007
Owner
140F0000022D76832238D501
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0007
SessionHash
266A08084451578BEEF37E0A64B9603C7D7362A1D9FDAB88B2253B9FA216DAE2
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0007
Sequence
1
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0007
RegFiles0000
C:\MSOCache\All Users\{90140000-0019-0409-0000-0000000FF1CE}-C\Setup.xml
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0007
RegFilesHash
EB4B32E856466AF057895682B8228E69E5DF303A4C4F5F43521E1F12A633B248
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0011
Owner
140F0000022D76832238D501
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0011
SessionHash
2544264B33405567D31DDAC50A716A10BD15E82285DB79DC1FBADBEBDE4C3471
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0011
Sequence
1
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0011
RegFiles0000
C:\MSOCache\All Users\{90140000-0016-0409-0000-0000000FF1CE}-C\Setup.xml
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0011
RegFilesHash
E2755DA4BC839A84E0C23DB5ABC411C5DFE68F073921AB858A25E07758F56F8D
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0015
Owner
140F0000022D76832238D501
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0015
SessionHash
37409C7EF6E354AC1564711E41E7BD8A6C92B5815EC46DAD32CE5A9258262A22
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0015
Sequence
1
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0015
RegFiles0000
C:\MSOCache\All Users\{90140000-001B-0409-0000-0000000FF1CE}-C\WordMUI.xml
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0015
RegFilesHash
70AFADCEC276690CDD0382153DBF99B35DEA23A79B96E61805325293E0E4921C
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0020
Owner
140F0000022D76832238D501
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0020
SessionHash
7A86377472054FC1BDCDEC57BDFDB8818AC11DDDEC23CAAE3064F4FFA5F14AAC
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0020
Sequence
1
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0020
RegFiles0000
C:\MSOCache\All Users\{90140000-0117-0409-0000-0000000FF1CE}-C\Setup.xml
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0020
RegFilesHash
7EA3335E528536A8F5F19C30FF2DEDF59108438CE2924BD1B8588997BFABBC5E
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0024
Owner
140F0000022D76832238D501
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0024
SessionHash
F9229CFD74FFA4F83BC3B2FFAD7B5AF3DD37A9FD717D00E3812E2A7A9F9781AB
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0024
Sequence
1
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0024
RegFiles0000
C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\Office64WW.xml
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0024
RegFilesHash
F47FD9C1B6746E35CF395312C7794FC73BF77D7DFF4A77C3AEBD11584751B1EE
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0029
Owner
140F0000022D76832238D501
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0029
SessionHash
0072B8D45288DDDCE41DB7D88CDA5B8122883DA6501A54D4E67CAD4F1D83D26A
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0029
Sequence
1
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0029
RegFiles0000
C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\SIWW.cab
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0029
RegFilesHash
6D37452D2C1ADC514E8BEB32697AA78577AEEDBC68E04243A8D0D25438501291
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0039
Owner
140F0000022D76832238D501
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0039
SessionHash
CE3F9B134F8742AF257EDD2259984179F2E4F4345753F913B6D967933FBC4208
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0039
Sequence
1
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0039
RegFiles0000
C:\MSOCache\All Users\{90140000-0115-0409-0000-0000000FF1CE}-C\OfficeLR.cab
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0039
RegFilesHash
5BA575684BF3CAA73436A523F2D57C98514A5D3A8F308BF1680E0C05194A0467
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0045
Owner
140F0000022D76832238D501
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0045
SessionHash
8EF3AE2FF9B2528DA69540936A697F81A6C9290B7C0773E50C58B255730907EC
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0045
Sequence
1
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0045
RegFiles0000
C:\MSOCache\All Users\{90140000-0115-0409-0000-0000000FF1CE}-C\OfficeMUI.msi
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0045
RegFilesHash
81B2232D32011B02EDE74A837B786D0C74105F63037927D2F6FF749B042069ED
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0049
Owner
140F0000022D76832238D501
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0049
SessionHash
3C0C9D02EB2A3331E7EA35791CE6D875E453FA9853B159CB432E6B6BB0B7ECDE
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0049
Sequence
1
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0049
RegFiles0000
C:\MSOCache\All Users\{90140000-0019-0409-0000-0000000FF1CE}-C\PublisherMUI.msi
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0049
RegFilesHash
9E938952D4E710B43E24B02C5739DB94C622A27D5750F557D17D66BFE1AA5F82
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0005
Owner
140F0000022D76832238D501
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0005
SessionHash
F34659AE7191190C2899C607D66ACD84D812BA1F1911DB8ABA5CF65AC8BD18D4
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0005
Sequence
1
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0005
RegFiles0000
C:\MSOCache\All Users\{90140000-00A1-0409-0000-0000000FF1CE}-C\OneNoteMUI.msi
3860
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0005
RegFilesHash
E68244F9212FBDD72469FCF01D6DB22B4E3E55675625367BF8E167B07C6BE4C5
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0003
Owner
5C0F0000022D76832238D501
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0003
SessionHash
33AF27DB184B90C0D84C73FF55137B47A722CA843D8A94306BCBB5AA16BB373E
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0003
Sequence
1
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0003
RegFiles0000
C:\MSOCache\All Users\{90140000-0016-0409-0000-0000000FF1CE}-C\ExcelMUI.xml
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0003
RegFilesHash
B07B2FC40FC40DAAC4DABD3BBC60B0BE08D894892B63929689880D797657FACA
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0008
Owner
5C0F0000022D76832238D501
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0008
SessionHash
C3C7E771DF0F69A326E2399BB40D7F61BA8822FA4C857DE99FE46481280B2870
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0008
Sequence
1
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0008
RegFiles0000
C:\MSOCache\All Users\{90140000-002C-0409-0000-0000000FF1CE}-C\Proof.es\Proof.xml
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0008
RegFilesHash
59D009CE1BA2EA09D710D3656D82174775ABF87007C37E9D655F325DDB20AC16
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0013
Owner
5C0F0000022D76832238D501
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0013
SessionHash
6A61C0DC694CE0402241753B79DEFF00E57F7355BD4B79AA551EF36D188BED16
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0013
Sequence
1
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0013
RegFiles0000
C:\MSOCache\All Users\{90140000-002C-0409-0000-0000000FF1CE}-C\Proof.en\Proof.xml
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0013
RegFilesHash
F092B28720DCF4DAFB8771AFA14236EE996A4896058FE52D83D1ADFDB9C5D18F
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0018
Owner
5C0F0000022D76832238D501
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0018
SessionHash
A8F61151AF864BBA49D86D0C5F73C1A893C4BD6DF88CB42D516B481BB2B90DD1
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0018
Sequence
1
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0018
RegFiles0000
C:\MSOCache\All Users\{90140000-0018-0409-0000-0000000FF1CE}-C\Setup.xml
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0018
RegFilesHash
016BABF19AE8DB4B863F7A506CF649F7093D600083839AC85FED8CC7B89F2873
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0023
Owner
5C0F0000022D76832238D501
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0023
SessionHash
4AD8257571F1A02AB97697ACFBB887BB0EB448BE820F48E3E874F2AA77D3D207
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0023
Sequence
1
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0023
RegFiles0000
C:\MSOCache\All Users\{90140000-0117-0409-0000-0000000FF1CE}-C\Access.en-us\branding.xml
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0023
RegFilesHash
587F7A8D043DAFA21406A89B84C79D93A14DDAEEF1BDA649950CA890B24E3458
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0028
Owner
5C0F0000022D76832238D501
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0028
SessionHash
2EE770CF331859556C3E042328BF47E02AAA3205934F53C67A9E3AED6440DB74
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0028
Sequence
1
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0028
RegFiles0000
C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\SIWW2.cab
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0028
RegFilesHash
32D046D810572C6EF4C2BE3ABB0E846852109A02B8AFE8A60D3CEA59A9401E2C
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0042
Owner
5C0F0000022D76832238D501
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0042
SessionHash
2B662D0DB9F693EB0065EFCB5436D39733F518C162C772FB4D5721E22AC0FD5F
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0042
Sequence
1
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0042
RegFiles0000
C:\MSOCache\All Users\{90140000-0019-0409-0000-0000000FF1CE}-C\PubLR.cab
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0042
RegFilesHash
125E130185CB85A73466096E347B59E6F24568CDCBC4581FE6D14981AB0F8838
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0048
Owner
5C0F0000022D76832238D501
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0048
SessionHash
096670E1F3B784E7A00813228EC355ED714C73236923EB04BDCDB459792A8FAA
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0048
Sequence
1
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0048
RegFiles0000
C:\MSOCache\All Users\{90140000-0117-0409-0000-0000000FF1CE}-C\Access.en-us\AccessMUI.msi
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0048
RegFilesHash
A4EAEE3EF343C8DD207647E0E46E7829775054B123021C0F53D7FFCDC2DE8D40
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
Owner
5C0F0000022D76832238D501
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
SessionHash
88B419A70EF6186210F8F8A2529F1501B9D7A64CB74A2F7ED3C24E5F0F4112A5
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
Sequence
1
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
RegFiles0000
C:\MSOCache\All Users\{90140000-0018-0409-0000-0000000FF1CE}-C\PowerPointMUI.msi
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
RegFilesHash
0FCDE09AB4844A2144FFADCEE8848B959DE2DF2E0CD1E5F566BA0C609C73047F
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Owner
5C0F0000022D76832238D501
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
SessionHash
0E005359A801ACF42CA3590517A84319AF35B2D5129BD2D7A5FF3132A878983C
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Sequence
1
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
RegFiles0000
C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\setup.exe
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
RegFilesHash
5AFD75AB9B194B1E12397F1ED4C023578BC57C34082756D7086F4EB431F7CC26
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0004
Owner
5C0F0000022D76832238D501
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0004
SessionHash
0D6B1ED917ECFC3DEAE201E43D8FCB2964BEBF55858EDCF83DD3F6C1B6C28D3B
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0004
Sequence
1
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0004
RegFiles0000
C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\pkeyconfig-office.xrm-ms
3932
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0004
RegFilesHash
0C2D8C033345D36F0A973EAAEE562BB86C09C30BE09BD547106E0F2BEA865AB0
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Owner
B00F0000B6F17A832238D501
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
SessionHash
03C2B3229BB1310239F0388B92DA6EA0ED615B49B20F3463BCB2E548E2955FE5
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Sequence
1
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
RegFiles0000
C:\MSOCache\All Users\{90140000-0018-0409-0000-0000000FF1CE}-C\PowerPointMUI.xml
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
RegFilesHash
A8F25809D641C093C0955BF6FA5A2D91C1EE47A24E292F4773E88E5AC3BF1065
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0005
Owner
B00F0000B6F17A832238D501
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0005
SessionHash
7D92209378EFB5A52DFC159EED731B578801FD7D4DDAEC82EECA0106C8C00679
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0005
Sequence
1
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0005
RegFiles0000
C:\MSOCache\All Users\{90140000-002C-0409-0000-0000000FF1CE}-C\Proof.fr\Proof.xml
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0005
RegFilesHash
6DAC0F439F1A34C8F72DC877E8DD0EECF15F498CCA5A5B05E1CB465FFB008865
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0009
Owner
B00F0000B6F17A832238D501
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0009
SessionHash
B94797993E6A69D62DD1D83EF512F73F6E17EAE424A458CBA8097FCEE5FBDACF
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0009
Sequence
1
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0009
RegFiles0000
C:\MSOCache\All Users\{90140000-00A1-0409-0000-0000000FF1CE}-C\Setup.xml
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0009
RegFilesHash
6E341882C9B5B511F8757A4D617C1595DFFC6E96CD913E332BA8DA2090AA88DD
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0014
Owner
B00F0000B6F17A832238D501
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0014
SessionHash
E767314B3199F8210E80261A3C7F3407C03329F562771CF7DAA977E8D8A93FA2
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0014
Sequence
1
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0014
RegFiles0000
C:\MSOCache\All Users\{90140000-00A1-0409-0000-0000000FF1CE}-C\OneNoteMUI.xml
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0014
RegFilesHash
D2B7DB0674862C2A138D20DD12726804EA909D2EA8AFBBFFDA21160A21385E45
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0019
Owner
B00F0000B6F17A832238D501
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0019
SessionHash
701717A613D28B091679635BBE6D754834E022698CAD151DA2BF3C4DCEA58B2E
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0019
Sequence
1
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0019
RegFiles0000
C:\MSOCache\All Users\{90140000-0117-0409-0000-0000000FF1CE}-C\AccessMUISet.xml
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0019
RegFilesHash
23AC372A12EDF59E382F7630476EC2FBA99E918B23C167F3CF91C91B40998C5C
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0025
Owner
B00F0000B6F17A832238D501
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0025
SessionHash
2933E32123FDEF667BD066E2448DF5F7695E3FB537BA5F047D96CBB73023CE26
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0025
Sequence
1
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0025
RegFiles0000
C:\MSOCache\All Users\{90140000-0117-0409-0000-0000000FF1CE}-C\Access.en-us\AccessMUI.xml
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0025
RegFilesHash
96E48A8FA173D361E2C6A6B17502C1AD572381D661BCE54D2D219AE714B00C9E
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0032
Owner
B00F0000B6F17A832238D501
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0032
SessionHash
1D28A6027BEBD68C82B342CFA285EAEA08583029020EDF0338A8358D4CF7BC2E
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0032
Sequence
1
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0032
RegFiles0000
C:\MSOCache\All Users\{90140000-0117-0409-0000-0000000FF1CE}-C\Access.en-us\AccLR.cab
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0032
RegFilesHash
A97762E101D86C3EB15D4A93C13BB4064A8B0168A9947B1195CEB3E79DA17A70
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0033
Owner
B00F0000B6F17A832238D501
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0033
SessionHash
1BB949EA3B8722C42908385D84D597F795C80E62E0170ED6301A65721234E5F5
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0033
Sequence
1
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0033
RegFiles0000
C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\SingleImageWW.msi
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0033
RegFilesHash
8CBDAC56418C11C7B20F2995629E02A5CABFBA69AB7BEB9632FD065AB0F438CA
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0036
Owner
B00F0000B6F17A832238D501
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0036
SessionHash
81BDA5DD6A6EA321D76D8131F7FC3400CE2E6F16FE71115E55BD0FABF620D702
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0036
Sequence
1
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0036
RegFiles0000
C:\MSOCache\All Users\{90140000-00A1-0409-0000-0000000FF1CE}-C\OnoteLR.cab
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0036
RegFilesHash
80968B06F77170D8D9FC1BB1151E142154D1DA0DF8DED491DB55AE3B522B09EE
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0040
Owner
B00F0000B6F17A832238D501
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0040
SessionHash
A9D0D6C76B63E1FCF959613D4AF92A8959457D10BBE59877FE3D682362573969
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0040
Sequence
1
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0040
RegFiles0000
C:\MSOCache\All Users\{90140000-002C-0409-0000-0000000FF1CE}-C\Proof.es\Proof.cab
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0040
RegFilesHash
31F3B3EEC76EF7569D9F83744047AC5E2B9915A14A958BF2AE59E23B0B9B05C8
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0044
Owner
B00F0000B6F17A832238D501
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0044
SessionHash
D21637058BE6E32BC11BA6D87F5E9488E706B02EC51573E9B32256917459E898
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0044
Sequence
1
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0044
RegFiles0000
C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\Office64WW.msi
4016
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0044
RegFilesHash
73497879DCC9A4D919D88A0FC82335AEEED102BDD8BD38979C8E16BE18F874F0
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0004
Owner
FC00000010547D832238D501
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0004
SessionHash
90B7B9BB61343D1C933936522452F7734B3A2A67913CAE02B396F54A12F36531
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0004
Sequence
1
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0004
RegFiles0000
C:\MSOCache\All Users\{90140000-0115-0409-0000-0000000FF1CE}-C\OfficeMUISet.xml
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0004
RegFilesHash
270D39C5AE3B9AABB0C7757611AE99346F2302640FE7E293C7F9232473991D69
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0012
Owner
FC00000010547D832238D501
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0012
SessionHash
E0E3C348D43583F67CB88C0E7C8D183EDA30F2D3F83E9BF7987415ED42B8E21C
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0012
Sequence
1
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0012
RegFiles0000
C:\MSOCache\All Users\{90140000-0019-0409-0000-0000000FF1CE}-C\PublisherMUI.xml
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0012
RegFilesHash
3B5B5A195445F612FAC3F28DC9DCF9EA26B38671EF1D0A8D60D8C74F6E514D91
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0016
Owner
FC00000010547D832238D501
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0016
SessionHash
20E3B0FEA046FE2CDCD9BAA350C18DE113FC1EA953975D7FAEB768F826506478
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0016
Sequence
1
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0016
RegFiles0000
C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\SingleImageWW.xml
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0016
RegFilesHash
F968F984ABC48332278362EF05CEEF7BB58CD7D8610633BCAB01A6AFB576972B
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0021
Owner
FC00000010547D832238D501
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0021
SessionHash
91BA34A03864A77DCEDC48C73D5825324A2465D0BB533E220D77A58C0E100880
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0021
Sequence
1
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0021
RegFiles0000
C:\MSOCache\All Users\{90140000-001A-0409-0000-0000000FF1CE}-C\Setup.xml
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0021
RegFilesHash
FCB9AB90D747371009D822D8D6E1C977C7C6190F1C1FD1ED38355EF024C11B9E
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0027
Owner
FC00000010547D832238D501
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0027
SessionHash
2987B3E7B06790C6331421FCCF26FB230D4DA8EE876924AEF7688F826BC5B1B8
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0027
Sequence
1
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0027
RegFiles0000
C:\MSOCache\All Users\{90140000-0115-0409-0000-0000000FF1CE}-C\Setup.xml
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0027
RegFilesHash
357596DC7823BB11B3D96E14F5A167B0044CC2855B118DA607205249FA57C24E
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0030
Owner
FC00000010547D832238D501
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0030
SessionHash
CCFE94A8CABB166D677F60325BC6A24908D6D9963444142E80FD083E9363543C
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0030
Sequence
1
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0030
RegFiles0000
C:\MSOCache\All Users\{90140000-0018-0409-0000-0000000FF1CE}-C\PptLR.cab
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0030
RegFilesHash
AAEE2F26F6E5969303CA102C4494D3285104C5563C67462CECF6D9F4FF2295A6
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0035
Owner
FC00000010547D832238D501
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0035
SessionHash
1B05C4BD9DA8735CBBE2F5D68461FA3D4E5E4EA275677D9131868876B09D42D4
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0035
Sequence
1
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0035
RegFiles0000
C:\MSOCache\All Users\{90140000-002C-0409-0000-0000000FF1CE}-C\Proof.fr\Proof.cab
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0035
RegFilesHash
37643B88E14E8B427B062F57934424BD4F3955A18A4DF4A5C85B43C9244010B5
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0038
Owner
FC00000010547D832238D501
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0038
SessionHash
6297DECAD91F53910609A1A716D7F581D4D675AE56E1F54EAF801ED9A95A66E2
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0038
Sequence
1
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0038
RegFiles0000
C:\MSOCache\All Users\{90140000-001A-0409-0000-0000000FF1CE}-C\OutlkLR.cab
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0038
RegFilesHash
D939E3C46B67A0E14F69B3F86FA988FBD824A90561EAF4B181E44C036299C6C9
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0043
Owner
FC00000010547D832238D501
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0043
SessionHash
49195775BD73A2652A78905E9D79F0B723C8532E401EAB0F8EB73D962C8856C5
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0043
Sequence
1
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0043
RegFiles0000
C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\osetup.dll
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0043
RegFilesHash
D8DED709A632C9198B2164B403C261482496C0090E496AEE0BAA2E135DE6A4C2
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0047
Owner
FC00000010547D832238D501
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0047
SessionHash
43B307FE631965C1C885B055E8EB4E1D39FEDB0E1A147A99E0F1D7DD47337616
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0047
Sequence
1
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0047
RegFiles0000
C:\MSOCache\All Users\{90140000-001B-0409-0000-0000000FF1CE}-C\WordMUI.msi
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0047
RegFilesHash
F3085CCC1283971534315C7D0621DDC5D75040EEE407757447EF6E7792E42C42
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Owner
FC00000010547D832238D501
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
SessionHash
7EC1107C30AA61EB7E13B5438B37C7A80E60F078C1C68EDBE4DF0F1FB2C07D1E
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Sequence
1
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
RegFiles0000
C:\MSOCache\All Users\{90140000-0016-0409-0000-0000000FF1CE}-C\ExcelMUI.msi
252
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
RegFilesHash
3623E6A443CC3155F82DEA7ECC3553D2D2CCF4A66EBD5C906507E964D88A78C0
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
Owner
A4090000D23F89832238D501
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
SessionHash
72092E44677C89DC6F577EAC10B475E8C4D16C522F0E8F458726F4395C9F9F14
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
Sequence
1
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
RegFiles0000
C:\MSOCache\All Users\{90140000-001A-0409-0000-0000000FF1CE}-C\OutlookMUI.xml
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
RegFilesHash
9816C685CB4767E3306512D834925110E5D22A839E36C8ACE108E5AABB568B50
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0006
Owner
A4090000D23F89832238D501
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0006
SessionHash
6869F2AFF3DB8D2CE5CCEE11C770C1D03666C1B0088A3A10CF3742E23951E9FD
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0006
Sequence
1
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0006
RegFiles0000
C:\MSOCache\All Users\{90140000-0115-0409-0000-0000000FF1CE}-C\OfficeMUI.xml
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0006
RegFilesHash
678BEA0835191D82DB614EE9B7473C9E06E9228E0847A50150379B5496DCAB5A
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0010
Owner
A4090000D23F89832238D501
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0010
SessionHash
9264815892068393B079850E8320B3AD84D9CD28A5F787AED801B423EECB3959
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0010
Sequence
1
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0010
RegFiles0000
C:\MSOCache\All Users\{90140000-0115-0409-0000-0000000FF1CE}-C\branding.xml
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0010
RegFilesHash
DAEE39FB9DB442F657549BA504D6049C298284F429214A91EB3D8FC182A40B6A
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0017
Owner
A4090000D23F89832238D501
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0017
SessionHash
F473AB59F334EA56A61B554547BB84A82B1AB4C94B7E18EA6F9B475F362E22DD
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0017
Sequence
1
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0017
RegFiles0000
C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\Setup.xml
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0017
RegFilesHash
C7EDBFF30D22B38E03C7745B9A695DD61DACE31DFC0D2336671BF910A85EC2F8
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0022
Owner
A4090000D23F89832238D501
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0022
SessionHash
E076746ACBEDE045EF61C5DE107F27BB93087F12E80E1FDD98CE2706A120D666
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0022
Sequence
1
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0022
RegFiles0000
C:\MSOCache\All Users\{90140000-001B-0409-0000-0000000FF1CE}-C\Setup.xml
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0022
RegFilesHash
AFCC775181D0CB9CB33AF827E6AEC6393E4C6CDB09ACFBA350288F9EF0D48C5D
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0026
Owner
A4090000D23F89832238D501
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0026
SessionHash
D940190401B0DC54BC26CB4DE8DFC7866911C3E78CDD4F6DA21D2267F857A9F1
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0026
Sequence
1
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0026
RegFiles0000
C:\MSOCache\All Users\{90140000-002C-0409-0000-0000000FF1CE}-C\Setup.xml
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0026
RegFilesHash
56941B24DE2C21152969D6052E49541864C21AB74C99BF6A5C2FF30C6E90B588
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0031
Owner
A4090000D23F89832238D501
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0031
SessionHash
A9D7611A02153C9F4076BE099B1B02494EB1B1098AD77F426F048E80B27DB620
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0031
Sequence
1
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0031
RegFiles0000
C:\MSOCache\All Users\{90140000-001B-0409-0000-0000000FF1CE}-C\WordLR.cab
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0031
RegFilesHash
C9F6C928E01CC087499992E65C79BFED1D352EFFCBFC7BDA578C082657C797EE
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0034
Owner
A4090000D23F89832238D501
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0034
SessionHash
84C60A2B2540BC570B4670B96CB427FC11EDA39E981C4C2ADEF1C8B189E9447A
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0034
Sequence
1
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0034
RegFiles0000
C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\OWOW64WW.cab
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0034
RegFilesHash
A555E97B9F62F5A84FCD44B22EF1E2D64AD2333C8E89E48ABB6AAB729FDF6718
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0037
Owner
A4090000D23F89832238D501
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0037
SessionHash
20B1A75F4485FC19BFD4EE57CCB9BCCBF6E20D4D65B64BC54AC7A01979EC3366
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0037
Sequence
1
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0037
RegFiles0000
C:\MSOCache\All Users\{90140000-0016-0409-0000-0000000FF1CE}-C\ExcelLR.cab
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0037
RegFilesHash
D6CC77B0BC6676DA7405850333087F748362F65CF58C0D3FE8930EA9C54E6E4C
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0041
Owner
A4090000D23F89832238D501
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0041
SessionHash
A5457B4CD46A743E2EFA4BEA19FCCE92FA495A4861E08EB87991FED9CC73B543
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0041
Sequence
1
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0041
RegFiles0000
C:\MSOCache\All Users\{90140000-002C-0409-0000-0000000FF1CE}-C\Proof.en\Proof.cab
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0041
RegFilesHash
19396DED696C2EBD1748CD68631AF6BFB6AB92203BB5C9EDEB0658E8B16F0B60
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0046
Owner
A4090000D23F89832238D501
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0046
SessionHash
7EF9DAF1E1D3E7022B51D017708322AFA012CDD7B60E0CDC3B834466B762F6D7
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0046
Sequence
1
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0046
RegFiles0000
C:\MSOCache\All Users\{90140000-001A-0409-0000-0000000FF1CE}-C\OutlookMUI.msi
2468
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0046
RegFilesHash
6B131682D0E76BF74788FC63AD45CA1414BC155902E728FA2B2612DE49F3774F
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0006
Owner
840E0000B6D270892238D501
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0006
SessionHash
5211D7BE12C20A489F6CF5751085B4C71A1885863E1831FB1956B27FF7B74836
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0006
Sequence
1
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0006
RegFiles0000
C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\PidGenX.dll
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0006
RegFilesHash
81ED4A8CCD4CECD11830885AA24263F2FA6276193DED3766896E0C676A3208A3
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0005
Owner
840E0000B6D270892238D501
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0005
SessionHash
7A9486B48B4F54D26C1F7BAB07D0BEA2E188F1482E04CC26A71B522120D7F033
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0005
Sequence
1
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0005
RegFiles0000
C:\MSOCache\All Users\{90140000-002C-0409-0000-0000000FF1CE}-C\Proof.es\Proof.msi
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0005
RegFilesHash
8A56C5A0995BA3FEDD434E6E25D7442C0CAD7EE3796836D13CA0363E25BB0548
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0002
Owner
840E0000B6D270892238D501
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0002
SessionHash
1FE5EE466F5DDEC22E90B767D00820C2B1D315EEBE7EF7F04EAC54A35D25AE7E
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0002
Sequence
1
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0002
RegFiles0000
C:\MSOCache\All Users\{90140000-0115-0409-0000-0000000FF1CE}-C\DW20.EXE
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0002
RegFilesHash
112774AF08A292CC3832A429468327BCE65D678970D60825933CFCCDAEEAD737
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Owner
840E0000B6D270892238D501
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
SessionHash
22702529D781B709B73A5AE4EE9F8D403A4A179CDDABA83B69474635854E4456
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Sequence
1
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
RegFiles0000
C:\MSOCache\All Users\{90140000-002C-0409-0000-0000000FF1CE}-C\Proof.en\Proof.msi
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
RegFilesHash
DF1DEAE260D5C4C2290ED5C3EE558C9881E79573E22C3BB9BEC6FB6B04506FD3
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0003
Owner
840E0000B6D270892238D501
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0003
SessionHash
A3E203F55BA29AB6267579F8A58E0AC055DB693E33DA3C8A8DA33C4CCB8B44A9
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0003
Sequence
1
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0003
RegFiles0000
C:\MSOCache\All Users\{90140000-002C-0409-0000-0000000FF1CE}-C\Proofing.msi
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0003
RegFilesHash
CF4743AAA7090040FA25D591C594214F73C3C4EB5C92720975E7AFF1644F2E5D
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0009
Owner
840E0000B6D270892238D501
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0009
SessionHash
0F398C9A275339210A22E62D42DE08BF4B143272BAFFC6F5C2858EBD146C7F7A
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0009
Sequence
1
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0009
RegFiles0000
C:\MSOCache\All Users\{90140000-0115-0409-0000-0000000FF1CE}-C\dwdcw20.dll
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0009
RegFilesHash
FCF6089DCB6AC18ECA47DF69FE14214425FC1A97C51708D93BF8DDC6F20DBF4C
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0012
Owner
840E0000B6D270892238D501
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0012
SessionHash
F045DF817D2DF21D4473065CE31214E0330DC0C4B19C014CFB21FF950C2DB3A2
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0012
Sequence
1
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0012
RegFiles0000
C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\ose.exe
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0012
RegFilesHash
D0B3A11251CE248F9D9CFAE52B478397313691FD6926851DEB41E56938D22ECE
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0017
Owner
840E0000B6D270892238D501
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0017
SessionHash
78F40DA445F540E35E9B7E25902EEFFC3B3190AB8502962B63D817A7B3DB76D8
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0017
Sequence
1
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0017
RegFiles0000
C:\MSOCache\All Users\{90140000-0115-0409-0000-0000000FF1CE}-C\Microsoft.VC90.CRT.manifest
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0017
RegFilesHash
818ABF077615E391230837E42320DFB86C286FE0C51B1EA3E44FD99E0B1152D2
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0022
Owner
840E0000B6D270892238D501
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0022
SessionHash
6DDDB14F9A7BA602CA646F1A025008DAFC74DF1CC4AEDF630D16C6605A495FED
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0022
Sequence
1
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0022
RegFiles0000
C:\Program Files\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\add-account\js\nls\pl-pl\ui-strings.js
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0022
RegFilesHash
71C62200BD1016F22BE2589E0D7A11D0B793785DF384B5AB94A9D20C446C2891
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0027
Owner
840E0000B6D270892238D501
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0027
SessionHash
9ABC36B98C606D75F12C7B95C3B62A15489DB9DC969D2DC1C5CC48B3A4A1A45C
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0027
Sequence
1
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0027
RegFiles0000
C:\Program Files\FileZilla FTP Client\resources\lone\48x48\uploadadd.png
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0027
RegFilesHash
2B169A67E764A876FFF5CD10EF4CC78D47922023E18D9FDB3434E92FFE183E28
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0032
Owner
840E0000B6D270892238D501
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0032
SessionHash
17149CD9AE9BF135689A0717E2DCD91A1E517F03A8299A70E64CE93BEC9DC4BE
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0032
Sequence
1
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0032
RegFiles0000
C:\Program Files\FileZilla FTP Client\resources\opencrystal\16x16\downloadadd.png
3716
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0032
RegFilesHash
7D6E1A673FB744C3A41FB7082C801DA8DDC77E277D49F0687B7A293C9C1D0EE2
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0004
Owner
B00B0000DACFAE892238D501
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0004
SessionHash
2327891274777E96EFA217E8BCF2F264983C6223714CF204F485D274E37A8C64
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0004
Sequence
1
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0004
RegFiles0000
C:\MSOCache\All Users\{90140000-002C-0409-0000-0000000FF1CE}-C\Proof.fr\Proof.msi
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0004
RegFilesHash
8BD12B63E6203777DF5D7314CE1C974BB8EBF2D625FCB8F87A9D0AAD0FEA4A2C
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
Owner
B00B0000DACFAE892238D501
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
SessionHash
8B4B2001F3B22DDD79DC7D7BC977AC0A6DE394AE769F83F1A4C119B6B904B8E9
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
Sequence
1
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
RegFiles0000
C:\MSOCache\All Users\{90140000-0115-0409-0000-0000000FF1CE}-C\msvcr90.dll
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
RegFilesHash
7F0F722B45BC80DF300439959C72E79B9D4B28D3406B7C4198184EAA5FA09297
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0007
Owner
B00B0000DACFAE892238D501
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0007
SessionHash
2238CCD57F0F4D1545029B8F35D78B775040C4EED73A70E81D4B26C72E2D0EFB
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0007
Sequence
1
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0007
RegFiles0000
C:\MSOCache\All Users\{90140000-0117-0409-0000-0000000FF1CE}-C\AccessMUISet.msi
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0007
RegFilesHash
6A644634B1E36FE9E3540588105E767B82CA23F762FF074F66CF9665879C5018
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0011
Owner
B00B0000DACFAE892238D501
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0011
SessionHash
864D032538E7CB3F17AA510ABDCF98788CAEC8D599FE3B2D8FBE0106C342D286
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0011
Sequence
1
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0011
RegFiles0000
C:\MSOCache\All Users\{90140000-0115-0409-0000-0000000FF1CE}-C\osetupui.dll
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0011
RegFilesHash
C8416C9AE7950E3E556CA449C592D80570955748EAC05ADC78BBB27B9766B396
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0015
Owner
B00B0000DACFAE892238D501
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0015
SessionHash
6F73C992216F32F52DE6F51AC9ED33BBDBF0820DBB210FC2D6FCCD7A6D8F247A
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0015
Sequence
1
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0015
RegFiles0000
C:\MSOCache\All Users\{90140000-0115-0409-0000-0000000FF1CE}-C\ShellUI.MST
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0015
RegFilesHash
DE2296FFCCA922C8A848370B22D206E7DACD95CBDAB8B1D415305490AEA0DBF6
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0020
Owner
B00B0000DACFAE892238D501
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0020
SessionHash
5BDEEF20552EC3C9FB22B76F7E0E72153BF42258EA5E5769923CAC820556881E
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0020
Sequence
1
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0020
RegFiles0000
C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroApp\SVE\CPDF_Full.aapp
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0020
RegFilesHash
1061EBFA7FB839FB7CF8EF179E82558C5D66D53F228939655831975FF8A0C869
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0025
Owner
B00B0000DACFAE892238D501
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0025
SessionHash
65EB2F59F2CBF288AB7138D14AD98AB645CA698DF700279C8F158EC3F9BBD281
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0025
Sequence
1
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0025
RegFiles0000
C:\Program Files\FileZilla FTP Client\resources\lone\16x16\uploadadd.png
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0025
RegFilesHash
5D1C2AA295239F1443E6398B33AB7C501342ED1D65C76819BB581A7892BE63B5
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0030
Owner
B00B0000DACFAE892238D501
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0030
SessionHash
85056F750CADC9353E5407FDBF2933C893C82FDAE2A17F4C8568AFF9A039BC99
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0030
Sequence
1
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0030
RegFiles0000
C:\Program Files\FileZilla FTP Client\resources\minimal\32x32\file.png
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0030
RegFilesHash
EFCD62B74BF71F46F5391DC0C00D0E3B26F1C37228C8CE93CB38438601D74C7E
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0035
Owner
B00B0000DACFAE892238D501
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0035
SessionHash
83529518A69E0C82AF46F5F1BD3D822B23FEB12631E16A3C35FD74A1364EC067
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0035
Sequence
1
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0035
RegFiles0000
C:\Program Files\FileZilla FTP Client\resources\opencrystal\16x16\sitemanager.png
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0035
RegFilesHash
23050CC0BF903AC49337522E8692FBB65A266BB96FA716C8548A3C02B61D6214
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0005
Owner
B00B0000DACFAE892238D501
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0005
SessionHash
B6C31028F6A806D864DE2B1824C77EF74ACF0BA3E0B761ED2385E9CA5EE637BB
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0005
Sequence
1
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0005
RegFiles0000
C:\Program Files\FileZilla FTP Client\resources\opencrystal\32x32\localtreeview.png
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0005
RegFilesHash
DDDDBFF8D14B966F667C7CB7EF7EF6D0F097129D6D1164D975108E855489D0F1
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0017
Owner
B00B0000DACFAE892238D501
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0017
SessionHash
B85047A5F1D2A0755A0AF6384696C02179C21402E86A7EA3BAD94D5EA0680047
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0017
Sequence
1
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0017
RegFiles0000
C:\Program Files\FileZilla FTP Client\resources\tango\16x16\server.png
2992
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0017
RegFilesHash
B997C13D34021C913EAA4C5DAFE99D59838122589CB6F9DCFF0860E660287A84
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0008
Owner
7C0A00004A08E8892238D501
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0008
SessionHash
10BE851BD75D3803156CAEDAB70680CC41609E484CCA89E64319D68C691F34FB
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0008
Sequence
1
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0008
RegFiles0000
C:\MSOCache\All Users\{90140000-0115-0409-0000-0000000FF1CE}-C\OfficeMUISet.msi
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0008
RegFilesHash
9ABAAFB3F7BA820A06D25F13EE0BC1D8F111D73678DF93F8FA506F11D1C7C22C
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0013
Owner
7C0A00004A08E8892238D501
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0013
SessionHash
945CABC0F1FEA0CB8062648A1966D628DE9852E3746BF818B95570CB77B1966A
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0013
Sequence
1
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0013
RegFiles0000
C:\MSOCache\All Users\{90140000-0115-0409-0000-0000000FF1CE}-C\1033\dwintl20.dll
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0013
RegFilesHash
0170B6C2BEBC0312DB79C8982670D22BC3D1C96613DEE6112E9D7DB2E506424D
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0018
Owner
7C0A00004A08E8892238D501
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0018
SessionHash
8C0067D47B2705FBDA1004FCD79D67C26987C756FA8D50F679625567919A1D8D
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0018
Sequence
1
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0018
RegFiles0000
C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroApp\CHT\Edit_R_Full.aapp
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0018
RegFilesHash
B815EB3A149FB48824D908A38E0535DA387A69E66C36A58A41810E70287280A9
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0023
Owner
7C0A00004A08E8892238D501
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0023
SessionHash
99FF7038F4E9846F1E415E336FB603F3934A7E09E3D6AAE75F9FDE78DC90AF04
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0023
Sequence
1
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0023
RegFiles0000
C:\Program Files\Common Files\microsoft shared\OFFICE14\Office Setup Controller\Excel.en-us\SETUP.XML
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0023
RegFilesHash
2BE8A06E231094C49B1B206C2E01BED91001788B6F648AC7826E0304EE63E93A
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0028
Owner
7C0A00004A08E8892238D501
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0028
SessionHash
AE32C7D9E25F2FD41B3C23E5F02472D0741229A4E412B2D505666E043AAD3F5B
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0028
Sequence
1
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0028
RegFiles0000
C:\Program Files\FileZilla FTP Client\resources\minimal\16x16\processqueue.png
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0028
RegFilesHash
A1E105E90C65FEED9E022BAD215447F4FADB7CD994A3701A2CD42E198DAE5288
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0033
Owner
7C0A00004A08E8892238D501
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0033
SessionHash
EFD92FE13436161650323956AEB7847F72A48FFACB2859D0EDFAB6989D32A481
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0033
Sequence
1
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0033
RegFiles0000
C:\Program Files\FileZilla FTP Client\resources\opencrystal\16x16\remotetreeview.png
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0033
RegFilesHash
7BD9F436C94DAF9F99055F7E62158B3E0A2AD1D26F60FDCF3FBA2E18F6D506F3
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0002
Owner
7C0A00004A08E8892238D501
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0002
SessionHash
8C615C8A3FF3297B2820796922CB580D5A0609DA5365C0B1775CAFD82434001C
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0002
Sequence
1
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0002
RegFiles0000
C:\Program Files\FileZilla FTP Client\resources\opencrystal\16x16\upload.png
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0002
RegFilesHash
ACD229F73531C88C50A0A2032B8BABE7F3FB7D9F7E1F69F3AD42806BA2B5390D
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0009
Owner
7C0A00004A08E8892238D501
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0009
SessionHash
9D81DFD3359E93B378E5153B69D5CD2A8B5C122F11CDDA967D3C584EA6829B9A
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0009
Sequence
1
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0009
RegFiles0000
C:\Program Files\FileZilla FTP Client\resources\opencrystal\48x48\sitemanager.png
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0009
RegFilesHash
F1C411C7086283D1AC6CBE3C13961C9112AE133C7A6F7C772AC8A1D2DBDC1291
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0027
Owner
7C0A00004A08E8892238D501
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0027
SessionHash
3D49AB6FD1AA690BC4F660B06E7DB0F498E5E94CFE9060571B75650CC77526C8
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0027
Sequence
1
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0027
RegFiles0000
C:\Program Files\FileZilla FTP Client\resources\tango\48x48\lock.png
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0027
RegFilesHash
B9462CDAF8021BC3E30A6B270701EE287D669E8E6328887A678C95E8E73F96A3
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
Owner
7C0A00004A08E8892238D501
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
SessionHash
094895BA80576EE8054AFFF415DD143E01C925C3DC2180C8AF7C8941C18F75D1
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
Sequence
1
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
RegFiles0000
C:\Program Files\Google\Chrome\Application\75.0.3770.100\Locales\ar.pak
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
RegFilesHash
CC7F1FBC75A202EA453AB42B612E80777CA186C086711B136D825F108223494E
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0007
Owner
7C0A00004A08E8892238D501
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0007
SessionHash
AD04492F0D477CCB405F6ACA02AB1EC665D3DD5F84FC7CB6578A6FEE2E314E27
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0007
Sequence
1
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0007
RegFiles0000
C:\Program Files\Google\Chrome\Application\75.0.3770.100\VisualElements\logocanary.png
2684
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0007
RegFilesHash
F0C6D8E875687D74245A0D38E13AA21BE2643C099315D4F326C9883AA5A8E633
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0010
Owner
700D0000DC06078A2238D501
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0010
SessionHash
6BF4D7AA76140A3E8035FC13A34D59AB1527FA0363F4FF2AA95150AB762143E5
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0010
Sequence
1
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0010
RegFiles0000
C:\MSOCache\All Users\{90140000-0115-0409-0000-0000000FF1CE}-C\dwtrig20.exe
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0010
RegFilesHash
725E4B7D36D81DF25A6E9B06EC2C391A6727A425894D20A954E8C7D384D57932
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0014
Owner
700D0000DC06078A2238D501
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0014
SessionHash
E5E1BEA9ED015BB4A03E845A393C5F20CDFBEBAD5DF1C65BEB2797063C0074D5
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0014
Sequence
1
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0014
RegFiles0000
C:\MSOCache\All Users\{90140000-0115-0409-0000-0000000FF1CE}-C\setup.chm
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0014
RegFilesHash
10EA633F2B6DE75BDD090971B42C28BB3F9E9B41461C681316C3E39EA2FE7A74
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0019
Owner
700D0000DC06078A2238D501
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0019
SessionHash
D4ADB87C52DEF7837113DA288F95F6B95E51627348C055B468103CD8463A2E9F
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0019
Sequence
1
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0019
RegFiles0000
C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroApp\FRA\EPDF_RHP.aapp
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0019
RegFilesHash
9DA037BA66E667A28F1EF71A2F2CAE064ECADB9D587AD6B8B4556F935543E34C
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0024
Owner
700D0000DC06078A2238D501
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0024
SessionHash
A416925C52C608227F2A806F341CBD84EB6A7E124DB88848C39D2C972C56BE90
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0024
Sequence
1
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0024
RegFiles0000
C:\Program Files\FileZilla FTP Client\resources\lone\16x16\filter.png
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0024
RegFilesHash
814E44B013E0B38CF62A7B52C0AD7FD58EE11833CAF87FEA10505B16990836A7
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0029
Owner
700D0000DC06078A2238D501
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0029
SessionHash
5C2B8C5A8F888286A72723D6D36A6FDE14611092754CFE5D6474EB92EA827BA7
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0029
Sequence
1
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0029
RegFiles0000
C:\Program Files\FileZilla FTP Client\resources\minimal\theme.xml
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0029
RegFilesHash
00788B2A0CD91D246325C48878C7E133C785749719113065791BBA623823EC2A
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0034
Owner
700D0000DC06078A2238D501
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0034
SessionHash
DFAD966DBDD8A5BF666C804C8D3A53B0CC73F7D43BD719F750CFBC8737B20B37
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0034
Sequence
1
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0034
RegFiles0000
C:\Program Files\FileZilla FTP Client\resources\opencrystal\16x16\speedlimits.png
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0034
RegFilesHash
A21B8ABA473E9822506D43B282595B2E2BAE623D102DB41E7FA7482F3C10252B
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0003
Owner
700D0000DC06078A2238D501
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0003
SessionHash
9DD9AD6523385E1CE748C9581116BD80CC0359E021EA381394658A6261C1A6ED
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0003
Sequence
1
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0003
RegFiles0000
C:\Program Files\FileZilla FTP Client\resources\opencrystal\24x24\server.png
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0003
RegFilesHash
53C06F07D837F51872B5EE39CFE68DAE0D9597D21D3BB6DC9A87BD6085AA75B4
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0012
Owner
700D0000DC06078A2238D501
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0012
SessionHash
9F6A47DF28CAEC9424DF3BD91A44B62CF972D1BC1AB026E42A07C892BDB4F86C
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0012
Sequence
1
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0012
RegFiles0000
C:\Program Files\FileZilla FTP Client\resources\sun\48x48\reconnect.png
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0012
RegFilesHash
E4B810D74D27D1812DDE48F9372407A4C4817898686E4ABCA2CC5F34F885CB8B
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0032
Owner
700D0000DC06078A2238D501
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0032
SessionHash
F3B9B9AF2521F926071F4CD6BCD8BE85A2E0068DBAC950A2E84833C83FBFA9F5
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0032
Sequence
1
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0032
RegFiles0000
C:\Program Files\FileZilla FTP Client\resources\xrc\sitemanager.xrc
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0032
RegFilesHash
B4F3225DA28835B16208F09485107DBFB15E787A5ABD7248DCE8F5AC4F1036BE
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0005
Owner
700D0000DC06078A2238D501
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0005
SessionHash
D948D718C68B0D4B3E109F2AF5C4625191E8955CEC8CB886F5FB936DC1287B84
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0005
Sequence
1
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0005
RegFiles0000
C:\Program Files\Google\Chrome\Application\75.0.3770.100\nacl_irt_x86_32.nexe
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0005
RegFilesHash
7BC2EE825C47B6C9800FD080607C066D233E6912AEA1F1BF8ED62B5EC7755714
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0002
Owner
700D0000DC06078A2238D501
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0002
SessionHash
C06BA2A58DAE946761EB5836A6757AA1AB8E7F3AE2384EFCA6D2387EC2050525
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0002
Sequence
1
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0002
RegFiles0000
C:\Program Files\Google\Update\1.3.34.11\goopdateres_cs.dll
3440
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0002
RegFilesHash
7833A5A3973312C5B32B5F446F90B3A8AA277B5D99E7C7B15A755EC371BD4FD1
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0016
Owner
340F0000B6FFA18A2238D501
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0016
SessionHash
78632D374F316373716A5AED92B1353D0107C6C618784C2EE88563D5841D26FB
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0016
Sequence
1
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0016
RegFiles0000
C:\MSOCache\All Users\{90140000-0115-0409-0000-0000000FF1CE}-C\pss10r.chm
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0016
RegFilesHash
A37CCAA3298EA56E4531A4FDA34111B07F901EBEEBBF54B087A1A02DBFD6C6A0
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0021
Owner
340F0000B6FFA18A2238D501
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0021
SessionHash
DBF85F0666C248B131C06749AE089CE01C99592C650CE62BF1C72F949B4B9050
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0021
Sequence
1
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0021
RegFiles0000
C:\Program Files\Adobe\Acrobat Reader DC\Reader\Locale\hu_HU\makeaccessible.HUN
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0021
RegFilesHash
9122B036C22699BE5B9CE851B8F3435A157B9AAC2015E4C679F41D4ECA3568DB
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0026
Owner
340F0000B6FFA18A2238D501
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0026
SessionHash
5B7C675E447C4480F8B9708E57F14466EC9B8A6B9B857C99406D8F7D0926185C
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0026
Sequence
1
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0026
RegFiles0000
C:\Program Files\FileZilla FTP Client\resources\lone\48x48\bookmark.png
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0026
RegFilesHash
7176C179890241E5C873D272C7CE2700B1ECB1658BA42AB22B74FB086D545452
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0031
Owner
340F0000B6FFA18A2238D501
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0031
SessionHash
78D859982B2D4C8EA58BFB5A02891BBD5E8B5C576A908796E476BB31610DAA4E
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0031
Sequence
1
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0031
RegFiles0000
C:\Program Files\FileZilla FTP Client\resources\opencrystal\16x16\ascii.png
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0031
RegFilesHash
1E19D844ADF53D853A914DA32BB71EFA4D274889576A993882719281CB8D9CFD
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Owner
340F0000B6FFA18A2238D501
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
SessionHash
4CB168FD6B81CC8C1C3381C7912F5F652577D59C095B1B148FCC26B788C78D3C
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Sequence
1
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
RegFiles0000
C:\Program Files\FileZilla FTP Client\resources\opencrystal\16x16\synchronize.png
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
RegFilesHash
90416A8D462FEC611704D99915943636042C408B66C7C670B9AAFF390A512C33
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0006
Owner
340F0000B6FFA18A2238D501
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0006
SessionHash
43BAE36483EA055520ADDD0A41171C5BB1BE183CC2BE31410403D15E55D6538B
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0006
Sequence
1
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0006
RegFiles0000
C:\Program Files\FileZilla FTP Client\resources\opencrystal\48x48\bookmark.png
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0006
RegFilesHash
E5F7DE55717B4EE63FC9D0394B5DF37F8D721A2558A229511335F6011AF69ABE
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0022
Owner
340F0000B6FFA18A2238D501
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0022
SessionHash
65DC7E3F74E37B870182C47C18BA3EB53EC3120E72F6589794F3B490FB91BC77
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0022
Sequence
1
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0022
RegFiles0000
C:\Program Files\FileZilla FTP Client\resources\tango\32x32\lock.png
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0022
RegFilesHash
F95F7A05609BB454228565421BDB186EF3F4CE759C6996735605DBA511964818
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0036
Owner
340F0000B6FFA18A2238D501
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0036
SessionHash
2CBF1CCA4AAF9DCBBF014DC45B24C27D235380BCDF0A09F7049A23C9B3973A5E
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0036
Sequence
1
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0036
RegFiles0000
C:\Program Files\Google\Chrome\Application\75.0.3770.100\default_apps\drive.crx
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0036
RegFilesHash
23CAEB3836C4329F94B69E331B85A21F9ECC645776AC2BE6BDA6EE5E4E4D0763
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0004
Owner
340F0000B6FFA18A2238D501
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0004
SessionHash
1A335286A9289A778D6C295DBBF438B740CD64D3845FC5670A817089247E27EC
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0004
Sequence
1
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0004
RegFiles0000
C:\Program Files\Google\Chrome\Application\75.0.3770.100\Locales\pl.pak
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0004
RegFilesHash
5112B27C6BCD3510DAFD9DEA7C04B8F0B3514E7BC04FD084CF195B644CB4D27C
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0015
Owner
340F0000B6FFA18A2238D501
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0015
SessionHash
B97ECE2CA5F2AC8A3B42374B8A44FF8DBC050EB2CF127C02E0816D570B1AE99A
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0015
Sequence
1
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0015
RegFiles0000
C:\Program Files\Google\Update\1.3.34.11\goopdateres_ar.dll
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0015
RegFilesHash
5831039243D4406DD3A592FBA4B7BA10BE414EE366C6074D99155A5313D6109E
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
Owner
340F0000B6FFA18A2238D501
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
SessionHash
DF949896BA1C7F46B13471D5146A67E646ECAB669FD869B7A33E357C9F6758D5
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
Sequence
1
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
RegFiles0000
C:\Program Files\Google\Update\1.3.34.11\goopdateres_bg.dll
3892
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0001
RegFilesHash
FCBE161B743C21DC5DBD742C4BF5365C4852346299DFEA44DA1C93D6BBFF42A0
4008
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0011
Owner
A80F0000AA3C248C2238D501
4008
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0011
SessionHash
AE6BD4904DE9AF3EFDA793D7319C4B4AAD648AA5FAC0FD41D5331CB38C78276D
4008
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0011
Sequence
1
4008
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0011
RegFiles0000
C:\Program Files\Google\Update\1.3.34.11\GoogleUpdateBroker.exe
4008
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0011
RegFilesHash
861CA8BC9E1B8E777771155F42396BAACC7E4D2911B84AC4DC4255B309758883
4008
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0007
Owner
A80F0000AA3C248C2238D501
4008
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0007
SessionHash
365D0870C10CAE1F12BEE4E0B9A020496E6967E36BF9DBA820BA71CC75CC9591
4008
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0007
Sequence
1
4008
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0007
RegFiles0000
C:\Program Files\Google\Update\1.3.34.11\goopdateres_de.dll
4008
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0007
RegFilesHash
F72E195CA76498E45D8007D6EFD1F08C9A234A4DFAFA1C0FB2B0D9C2281BE6E5
4008
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Owner
A80F0000AA3C248C2238D501
4008
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
SessionHash
BFFF5E5C5A71B5108F27C8906DA5F3D2B869DCCCB51CE817EF132B49350A17FF
4008
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Sequence
1
4008
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
RegFiles0000
C:\Program Files\Google\Update\1.3.34.11\goopdateres_hu.dll
4008
tgytutrc2548.exe
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
RegFilesHash
60C40CD82B21E9793DA4644754595B382045F4A45BCCC250E728F54D0D43D57E

Files activity

Executable files
1
Suspicious files
88
Text files
5
Unknown types
3

Dropped files

PID
Process
Filename
Type
2820
cmd.exe
C:\Users\admin\AppData\Local\Temp\tgytutrc2548.exe
executable
MD5: e11502659f6b5c5bd9f78f534bc38fea
SHA256: c97d9bbc80b573bdeeda3812f4d00e5183493dd0d5805e2508728f65977dda15
2468
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-0016-0409-0000-0000000FF1CE}-C\ExcelLR.cab.locked
––
MD5:  ––
SHA256:  ––
3892
tgytutrc2548.exe
C:\Program Files\Google\Chrome\Application\75.0.3770.100\default_apps\drive.crx.locked
bs
MD5: 1acd8f77acf7e2f5a84503c31a6b82b9
SHA256: 8ea4a8b74f14ac497eff543f76d3cff890930b730c33d668d651fc31a3a8a6ff
3440
tgytutrc2548.exe
C:\Program Files\FileZilla FTP Client\resources\xrc\sitemanager.xrc.locked
binary
MD5: a017dce06e2b3a80a1694b306abbdf4f
SHA256: 120b8212b7de0210dfa90d65a5cce8ea79cea4549558f2535db28688a008eeb3
2684
tgytutrc2548.exe
C:\Program Files\FileZilla FTP Client\resources\tango\48x48\lock.png.locked
binary
MD5: b80d3c2ee545fa41a32c0e148625e353
SHA256: 70445b245ad33e3ac3fa576f2923f53b983b1c6cfd4e8b7fab4b88dd2b2720ba
3892
tgytutrc2548.exe
C:\Program Files\FileZilla FTP Client\resources\tango\32x32\lock.png.locked
binary
MD5: 73c1c99e68ca9acd21c8f8659be2310b
SHA256: d712bc4c18b7f868dbe6d4bec8656f96999a46e67bec696a14be7cf57ccb9821
2992
tgytutrc2548.exe
C:\Users\Public\Desktop\README_LOCKED.txt
text
MD5: b0c3680511bb097c2b306a275ed5740e
SHA256: 7fa663bf6aa840278f94e46ae7572bb41474adf1d80e8ab4ec5e4550fcf30314
2992
tgytutrc2548.exe
C:\Program Files\FileZilla FTP Client\resources\tango\16x16\server.png.locked
binary
MD5: 8898b9b51148c44417e90f8085ee7636
SHA256: ea26f157213595abc39b06f85f15d66ac1c0a916c1af35b80f656e3600cdda6e
3440
tgytutrc2548.exe
C:\Program Files\FileZilla FTP Client\resources\sun\48x48\reconnect.png.locked
binary
MD5: 2b989c9d950876a94b8e3031890015fd
SHA256: 060c0b024f70800dbd504fd95817006838cfe18663f575c58f46e4a353180432
2684
tgytutrc2548.exe
C:\Program Files\FileZilla FTP Client\resources\opencrystal\48x48\sitemanager.png.locked
binary
MD5: fe7441809ecf1c94f96673b64e4c6bff
SHA256: 2ae201b0b5da074fa1dee71db54a573fc38640db580c1b7842c59d3efcf1d217
3892
tgytutrc2548.exe
C:\Program Files\FileZilla FTP Client\resources\opencrystal\48x48\bookmark.png.locked
binary
MD5: 8884ba479c4addd90b249aa796f6f8bf
SHA256: ed7b9736aef9a3363ac0f3260ca09e0b8d9672559a49ef9adc0739786f312232
2992
tgytutrc2548.exe
C:\Program Files\FileZilla FTP Client\resources\opencrystal\32x32\localtreeview.png.locked
binary
MD5: f1f9788a5f5cf7e8bd5e409d70856905
SHA256: f8243f62236a5c5d4b14e64f35bda2eff5052d960f4cbd4c914d603f91d1b62e
3440
tgytutrc2548.exe
C:\Program Files\FileZilla FTP Client\resources\opencrystal\24x24\server.png.locked
binary
MD5: 8ae95217b5bb8ebe3a26f24ce04f4461
SHA256: 458f7ba5db79f96bc44deb0c6aa02211af7837ecad7cef4111b6141a782258af
2684
tgytutrc2548.exe
C:\Program Files\FileZilla FTP Client\resources\opencrystal\16x16\upload.png.locked
binary
MD5: 5c6f11b853a7f29f63c72a8989dbbf59
SHA256: e1c61804e3c8a2f5bcfc00c0cb1421a67584600990abab92598b20cba451bae2
3892
tgytutrc2548.exe
C:\Program Files\FileZilla FTP Client\resources\opencrystal\16x16\synchronize.png.locked
binary
MD5: 96db31c741afa544be0ea7601629da00
SHA256: dc461d8c4db7bec5f9577b96a7dc9ae09d6ac7df3391439feacc602921f72259
2992
tgytutrc2548.exe
C:\Program Files\FileZilla FTP Client\resources\opencrystal\16x16\sitemanager.png.locked
binary
MD5: fd4b214c43462ad4fbf8aa4dd10dfdfe
SHA256: c3ac83c053ad0143d68539c98989e74f608fe3a7c689f567f223b49c38bff61d
3440
tgytutrc2548.exe
C:\Program Files\FileZilla FTP Client\resources\opencrystal\16x16\speedlimits.png.locked
binary
MD5: 3f58fd3f881981b75f6d61568cd529e6
SHA256: 6d45aba05441204a5fbd62770a4174deadcf45a5eb80c4e54966eb8966ec5661
2684
tgytutrc2548.exe
C:\Program Files\FileZilla FTP Client\resources\opencrystal\16x16\remotetreeview.png.locked
binary
MD5: 0777e35d0e0204cdf38349f3eecc2af1
SHA256: 15adc487fa239aa9a5bb3ff94d41f5104073243ad1bfca85e51c7240389c7901
3716
tgytutrc2548.exe
C:\Users\Public\Desktop\README_LOCKED.txt
text
MD5: b0c3680511bb097c2b306a275ed5740e
SHA256: 7fa663bf6aa840278f94e46ae7572bb41474adf1d80e8ab4ec5e4550fcf30314
3716
tgytutrc2548.exe
C:\Program Files\FileZilla FTP Client\resources\opencrystal\16x16\downloadadd.png.locked
binary
MD5: 387f64b98b848d806b182a6a86d7b517
SHA256: fc16ec2b13286559577609d828f652524197d23c3714fa7d660aae238c3dd63f
3892
tgytutrc2548.exe
C:\Program Files\FileZilla FTP Client\resources\opencrystal\16x16\ascii.png.locked
binary
MD5: 77a0235db1bc57c43c4f242d941c7ea2
SHA256: 276d8bf17b14d177a17fdd142bb0d3e6a5360f3ff473f40b102732084561313d
3892
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-0115-0409-0000-0000000FF1CE}-C\pss10r.chm.locked
binary
MD5: 0787f9f41a9f3dc6bad87d7e3d0625f6
SHA256: f920328b54121728167f11f38edf07e839ea1087ba591f506118d697e9c1832b
2992
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-0115-0409-0000-0000000FF1CE}-C\ShellUI.MST.locked
binary
MD5: 9f97fc1ab0161498ecc1ac34a0931b59
SHA256: 0a9e5a907a37e4ce7830f9109362f47c5bfcebcb2ab8f8916dc5a8470468365d
3440
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-0115-0409-0000-0000000FF1CE}-C\setup.chm.locked
binary
MD5: 20eea4d98966f9f9a5b3dd930c74de84
SHA256: 6ce1aa3de62e8a867975f16e8f0607ccfef9996ec67b7645b428a6bdbdec221b
2992
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-0117-0409-0000-0000000FF1CE}-C\AccessMUISet.msi.locked
binary
MD5: 97c69675335847378ff5aba2ecf1abcf
SHA256: d5cd05da20243029e8156334ef9742031e20e9dff9bb816b639c3ee51107a4e7
3716
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-0115-0409-0000-0000000FF1CE}-C\dwdcw20.dll.locked
binary
MD5: 74e3b3771b36aeb8424ec5cf9229e4c1
SHA256: 040cbb41d4a6f7ea0989921061a3a6e6f41c51c976a01b3a66ef894d705a53f9
2684
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-0115-0409-0000-0000000FF1CE}-C\OfficeMUISet.msi.locked
binary
MD5: 1a1802ef349ae49c71a1be2aa2723559
SHA256: 6b0194b34b24fa0cab37453650505137dff6ba642568a5a8773b85d2e21fa4f3
3716
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-002C-0409-0000-0000000FF1CE}-C\Proof.es\Proof.msi.locked
binary
MD5: 9b8596797df22b4b3f78a34d493192a3
SHA256: e11daf9f3595abc0e2c581d31392f383517068519ba825a9668d1ffc988fbf60
3932
tgytutrc2548.exe
C:\Users\Public\Desktop\README_LOCKED.txt
text
MD5: b0c3680511bb097c2b306a275ed5740e
SHA256: 7fa663bf6aa840278f94e46ae7572bb41474adf1d80e8ab4ec5e4550fcf30314
3932
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\setup.exe.locked
binary
MD5: 7accfda05779e56b36c66d62e91786d1
SHA256: 51a77d79cc10a8ca78b833867bbbcaefcb7dad9d41e1c517d93d73d35448c119
3932
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-0018-0409-0000-0000000FF1CE}-C\PowerPointMUI.msi.locked
binary
MD5: bedcd33553b814837b468d46ec3c89ac
SHA256: 71dda817c04ed59abb0ea63d9636c1b3f84c7ea105ee3725d34c9999cb8198a0
3716
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\PidGenX.dll.locked
binary
MD5: 3a96352504b1f89b9fcb13fc119c829d
SHA256: 186846573cd9b1da181ed4a4494ee46902906493e0a7a2d6cfb5326918cd741c
3860
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-0115-0409-0000-0000000FF1CE}-C\OfficeMUI.msi.locked
binary
MD5: d51550fc9edb6086678001fa305b7514
SHA256: af29f98a96b35f46aaa8e2b999f09cf2281fe979f43692bd12bba80348ca7a21
2468
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-001A-0409-0000-0000000FF1CE}-C\OutlookMUI.msi.locked
binary
MD5: 557ec0d9a58eb65350055c84ffbb02d3
SHA256: e90f1445357f8ee515ac75c9c972ee45d6fcc81ce0f04d1b200e53ef1f859a5f
3932
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-0019-0409-0000-0000000FF1CE}-C\PubLR.cab.locked
––
MD5:  ––
SHA256:  ––
252
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\osetup.dll.locked
––
MD5:  ––
SHA256:  ––
2468
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-002C-0409-0000-0000000FF1CE}-C\Proof.en\Proof.cab.locked
––
MD5:  ––
SHA256:  ––
3860
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-0115-0409-0000-0000000FF1CE}-C\OfficeMUI.msi.locked
binary
MD5: 5203af9c2cda25c7c2f84bea1abb3f12
SHA256: 9625b4a6e1a01418aa4a1212c832fcd61436b555ac319565c445d9ad4e159292
4016
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\Office64WW.msi.locked
binary
MD5: 74a01502b0504a13b1e98587203c4e24
SHA256: cd3a3c59489c7d2c8eeb43ca08314dc6bbc32fd79399248da12935454c27bfa5
3860
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-0115-0409-0000-0000000FF1CE}-C\OfficeLR.cab.locked
––
MD5:  ––
SHA256:  ––
4016
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-002C-0409-0000-0000000FF1CE}-C\Proof.es\Proof.cab.locked
––
MD5:  ––
SHA256:  ––
252
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-001A-0409-0000-0000000FF1CE}-C\OutlkLR.cab.locked
––
MD5:  ––
SHA256:  ––
3892
tgytutrc2548.exe
C:\Program Files\Google\Chrome\Application\75.0.3770.100\Locales\pl.pak.locked
binary
MD5: fca6ca6e09a9e97421996b71d49cc77c
SHA256: ef937b5393b21554faedb475b29fd53bf03dcc8b8eecdcbbed1a2f6d3bc3ebda
3932
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\SIWW2.cab.locked
––
MD5:  ––
SHA256:  ––
4016
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-00A1-0409-0000-0000000FF1CE}-C\OnoteLR.cab.locked
––
MD5:  ––
SHA256:  ––
252
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-002C-0409-0000-0000000FF1CE}-C\Proof.fr\Proof.cab.locked
––
MD5:  ––
SHA256:  ––
3860
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\SIWW.cab.locked
––
MD5:  ––
SHA256:  ––
2468
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\OWOW64WW.cab.locked
––
MD5:  ––
SHA256:  ––
4016
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\SingleImageWW.msi.locked
––
MD5:  ––
SHA256:  ––
252
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-0018-0409-0000-0000000FF1CE}-C\PptLR.cab.locked
––
MD5:  ––
SHA256:  ––
2468
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-001B-0409-0000-0000000FF1CE}-C\WordLR.cab.locked
––
MD5:  ––
SHA256:  ––
4016
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-0117-0409-0000-0000000FF1CE}-C\Access.en-us\AccLR.cab.locked
––
MD5:  ––
SHA256:  ––
2468
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-002C-0409-0000-0000000FF1CE}-C\Setup.xml.locked
binary
MD5: f53bce26284c1703b691f2f95ad30ccd
SHA256: 50a2ece3cf16fa70377151c216c69e27a7c2dc2fd61c4317e0fdad2f19cc57a5
4016
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-0117-0409-0000-0000000FF1CE}-C\Access.en-us\AccessMUI.xml.locked
binary
MD5: b05a25ff87d37c05f808e7aab9c3ec46
SHA256: 0c0c917a799c67b188f34d01af7124f0933220bc8c192d6624d9fa055a8593d2
252
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-0115-0409-0000-0000000FF1CE}-C\Setup.xml.locked
binary
MD5: 952e4507e4ca1a9b104fa8c8591c314d
SHA256: 32cead44f6cb64e65a51d143cc7565f97358406a80258478881bff05831c8623
3860
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\Office64WW.xml.locked
binary
MD5: 883288622912d37dd721422ce42c609c
SHA256: 7a9efb376bdc9e0162504d9ffb7c5e27f386eaef0ff297064a5c69651ad6863a
252
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-0115-0409-0000-0000000FF1CE}-C\Setup.xml.locked
binary
MD5: bc34bcb0dce41c5309934cb96bdabbf1
SHA256: 0273d1af56c76fd05c528ae59065f437ca60ee5151f18507c18c89afdcebfcca
3932
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-0117-0409-0000-0000000FF1CE}-C\Access.en-us\branding.xml.locked
binary
MD5: 35fb127fc23a307d6fefdf9303777708
SHA256: f1b623c2c691e82aaf58789de70d14a8463b6bae82ca7dbdda06e37dea93321f
2468
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-002C-0409-0000-0000000FF1CE}-C\Setup.xml.locked
binary
MD5: c53741a2d2de676c03b509e6fc3ff0e8
SHA256: 038d7e4e6199be0f2a5460017f01df5ee7c0f61d9c856bef1dabc02872ed6ff2
4016
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-0117-0409-0000-0000000FF1CE}-C\Access.en-us\AccessMUI.xml.locked
xml
MD5: f191beec568f2fc8d58f27121411a664
SHA256: bfa9cbe55fd4e2cb3c77358976873ab864dad7376756c21d0d6b39de7958aada
4016
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-0117-0409-0000-0000000FF1CE}-C\AccessMUISet.xml.locked
binary
MD5: 24b1f9a993d0d345fecbf0d99b6ee5d4
SHA256: e39a35ea716043b8e625a0fa009beaed1238a52acfddc4ac4bea4b3564d8b788
3860
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-0117-0409-0000-0000000FF1CE}-C\Setup.xml.locked
binary
MD5: 1f47531a0751083d75795cc47bc690ab
SHA256: 9537452f92a8c23abc31ed75e2930e02fb0b1031c5cbf161b5be3c5b0ecf1083
3932
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-0018-0409-0000-0000000FF1CE}-C\Setup.xml.locked
binary
MD5: c9529af52281cfdc017dc08f712da374
SHA256: 13d34351ca9de0245f023e9dc51c1b2285a62ddba8e79de1311c9977bf0150ec
252
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-001A-0409-0000-0000000FF1CE}-C\Setup.xml.locked
bs
MD5: aaf18b070ec60a29fd5b536c8ac8d5b8
SHA256: 3d5b06a0b7dc4002e91a6c90bf90d47a8c7fd011066242c46937efdb0f81ccf2
2468
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-001B-0409-0000-0000000FF1CE}-C\Setup.xml.locked
binary
MD5: 45abacffcbc8ac8485591461a1f88bd8
SHA256: a260684e25d39fdb9b5becd1a5e0aa45aefaa61ab062bfc590a1831a60b645bf
2468
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\Setup.xml.locked
binary
MD5: c8d16377b7771272f0c819b833e05491
SHA256: 78f2f6f0c193b2a902d8690d17e83e3686e26dda72b69fd1e766d08466ac0bda
252
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\SingleImageWW.xml.locked
binary
MD5: c781336cb39b9c931e29d0b262222d45
SHA256: 32166867a8d276c9d8c07ad1ad4c4124470457b9599bbf188992b256f8d8422c
3860
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-001B-0409-0000-0000000FF1CE}-C\WordMUI.xml.locked
binary
MD5: 72de7aa8c893c0968068b41770182860
SHA256: 4d636dab390edd2e375effedeb647631a7d39aa418d7400bbc9f8f1cb04af61b
4016
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-00A1-0409-0000-0000000FF1CE}-C\OneNoteMUI.xml.locked
binary
MD5: a17162a426fe3eef46204b8c247ea74d
SHA256: 84ece080793c30c69565134a2a9209ff0db2aeb2486f8d241ab25d398442c6d0
3932
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-002C-0409-0000-0000000FF1CE}-C\Proof.en\Proof.xml.locked
binary
MD5: 60ae98b96d820ced3abc758131821e86
SHA256: 53e88e0e01c033b63a6e31ad9b60d4fe95603347f2df4b5559e91b413e77853d
2468
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-0115-0409-0000-0000000FF1CE}-C\branding.xml.locked
binary
MD5: b1c823eff59d85f54c20a8d8b2612c35
SHA256: 3335828ad0c8f3e94dd579f2c9c2c36ae8a927944e99abd394d664336660678a
252
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-0019-0409-0000-0000000FF1CE}-C\PublisherMUI.xml.locked
binary
MD5: 63bc26db5ce3c79f85a4e3c075db09ee
SHA256: a268b085a6dacdd66145acbd752343fb3296fc8ea8de5aafaea8faef5f667300
3860
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-0016-0409-0000-0000000FF1CE}-C\Setup.xml.locked
binary
MD5: 72100c434a9526ca06f22bcc87fb92ed
SHA256: 2834526d6e268e4b5f5d30d4fd7761ed823ee09840f9d0f7248fb3f245b1fa0b
4016
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-00A1-0409-0000-0000000FF1CE}-C\Setup.xml.locked
binary
MD5: d8dedc22b645b066779bfdc7022b242c
SHA256: 5622a07e29e0a21cdf3f6d2a5cc66a75468e8072f889f47dbacd033c1311d31c
3932
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-002C-0409-0000-0000000FF1CE}-C\Proof.es\Proof.xml.locked
binary
MD5: 5eca701bd3b5d664137002ec0bb60141
SHA256: 0da33476cd2107f7146bf6a70124ddbfb28a9f9a4fec22e6cba28ca5bc5ed7f7
3860
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-0019-0409-0000-0000000FF1CE}-C\Setup.xml.locked
binary
MD5: 93f0e15759fb44d31918d2b8242b2bc6
SHA256: 2154180a357224bb827e471064a3c5817cf0c437ae746eccf4e3e5a5df872f05
252
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-0115-0409-0000-0000000FF1CE}-C\OfficeMUISet.xml.locked
binary
MD5: 68f1db0c84ded75dffb4291be02ce0ce
SHA256: 780cb53f8284a8c45eb86bdbd7ebe6a85b540dc78b1efe7765d2b9284ff33298
2468
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-0115-0409-0000-0000000FF1CE}-C\OfficeMUI.xml.locked
binary
MD5: 3dbff6356e57c1502c68d7326de0f138
SHA256: fb0049b62fae9c777b1d8cb23ba100efeb08846d0014284a7f26811ae0945762
4016
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-002C-0409-0000-0000000FF1CE}-C\Proof.fr\Proof.xml.locked
binary
MD5: 94ee6fce772b34618aef0fca9e7ea89b
SHA256: e28e0d776d7b2124c9472c5732f1758dbf5bdfdf2531b8c9822a32e179280128
3932
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-0016-0409-0000-0000000FF1CE}-C\ExcelMUI.xml.locked
binary
MD5: b7f6c8d9c7ca67e6f38d83bbcfcbe4d4
SHA256: e4e8fdac535835762a1b7a11fb6219bf9299e3777b9221a85ce5e179240ad505
3860
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-002C-0409-0000-0000000FF1CE}-C\Proofing.xml.locked
binary
MD5: df29ca09be69d66ec195da304af61604
SHA256: 04e79a581ab7aedaafdc135475321f2f98638f5088d4f955d50c32d007233741
2468
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-001A-0409-0000-0000000FF1CE}-C\OutlookMUI.xml.locked
binary
MD5: 65095ce061db1065368a39b167b2044f
SHA256: 8eef0d5126507850c9529c7286178608b643ae5116261d5dfa3a642926318a09
4016
tgytutrc2548.exe
C:\MSOCache\All Users\{90140000-0018-0409-0000-0000000FF1CE}-C\PowerPointMUI.xml.locked
binary
MD5: a06dbaa53c018c6684d5ff8c612190f1
SHA256: 134313bc1a236af1400dbd608be05ee6d5abfde85e8fc65496fe71d2de23b5fc
3704
LockerGoga.exe
C:\Users\Public\Desktop\README_LOCKED.txt
text
MD5: b0c3680511bb097c2b306a275ed5740e
SHA256: 7fa663bf6aa840278f94e46ae7572bb41474adf1d80e8ab4ec5e4550fcf30314
2684
tgytutrc2548.exe
C:\Program Files\Google\Chrome\Application\75.0.3770.100\Locales\ar.pak.locked
binary
MD5: 67c798b79f87de53bb8a1db6768f6bac
SHA256: 6ddddd229841ec2b4b9ca9e1e31f46273417a93ed61d5c7a48ee434f0a528bf7

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

No network activity.

Debug output strings

Process Message
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui
tgytutrc2548.exe C:\Program Files\Internet Explorer\en-US\hmmapi.dll.mui