General Info

File name

CuteWriter.exe

Full analysis
https://app.any.run/tasks/12816c1f-7f40-4a1a-9fe6-dd2def593078
Verdict
Malicious activity
Analysis date
11/8/2019, 17:39:23
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:

installer

Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

33fd7b23182dd55f1c8c8d4c4f6959cf

SHA1

d1290c304bf3e06f1dee9ab4e5b8b9588c263299

SHA256

de1ab47d7e5d6533c75c7f09205e465f99b534ed5024aa84f5ff91a9e4eea242

SSDEEP

98304:PXvFBSTEPOrAuzpejDkCToF9FDqVTwrvIt9z8o2gL:vvPjGLIjoCTkDOOvI78E

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (75.0.3770.100)
  • Google Update Helper (1.3.34.7)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.7.2 (4.7.03062)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Groove MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office IME (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office IME (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Language Pack 2010 - French/Français (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - German/Deutsch (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Italian/Italiano (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Japanese/日本語 (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Korean/한국어 (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Portuguese/Português (Brasil) (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Russian/русский (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Spanish/Español (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Turkish/Türkçe (14.0.4763.1013)
  • Microsoft Office O MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Arabic) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Basque) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Catalan) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Dutch) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Galician) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (German) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Proof (Ukrainian) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (French) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (German) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office SharePoint Designer MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office X MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (14.21.27702.2)
  • Microsoft Visual C++ 2019 X86 Additional Runtime - 14.21.27702 (14.21.27702)
  • Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.21.27702 (14.21.27702)
  • Mozilla Firefox 68.0.1 (x86 en-US) (68.0.1)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • Update for Microsoft .NET Framework 4.7.2 (KB4087364) (1)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB4019990
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads dropped or rewritten executable
  • spoolsv.exe (PID: 1204)
Creates files in the Windows directory
  • spoolsv.exe (PID: 1204)
  • Setup.exe (PID: 1932)
Removes files from Windows directory
  • spoolsv.exe (PID: 1204)
Executable content was dropped or overwritten
  • CuteWriter.exe (PID: 2412)
  • spoolsv.exe (PID: 1204)
  • CuteWriter.exe (PID: 3860)
  • CuteWriter.tmp (PID: 2880)
  • Setup.exe (PID: 1932)
Starts Internet Explorer
  • CuteWriter.tmp (PID: 2880)
Application was dropped or rewritten from another process
  • CuteWriter.tmp (PID: 3376)
  • CuteWriter.tmp (PID: 2880)
  • Setup.exe (PID: 1932)
Loads dropped or rewritten executable
  • CuteWriter.tmp (PID: 2880)
  • Setup.exe (PID: 1932)
Creates files in the program directory
  • Setup.exe (PID: 1932)
Application launched itself
  • iexplore.exe (PID: 2768)
Reads Internet Cache Settings
  • iexplore.exe (PID: 3840)
Reads internet explorer settings
  • iexplore.exe (PID: 3840)
Creates a software uninstall entry
  • Setup.exe (PID: 1932)
Adds / modifies Windows certificates
  • iexplore.exe (PID: 3840)
Creates files in the user directory
  • iexplore.exe (PID: 3840)
Changes internet zones settings
  • iexplore.exe (PID: 2768)
Changes settings of System certificates
  • iexplore.exe (PID: 3840)
Reads settings of System Certificates
  • iexplore.exe (PID: 3840)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Inno Setup installer (77.7%)
.exe
|   Win32 Executable Delphi generic (10%)
.dll
|   Win32 Dynamic Link Library (generic) (4.6%)
.exe
|   Win32 Executable (generic) (3.1%)
.exe
|   Win16/32 Executable Delphi generic (1.4%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
1992:06:20 00:22:17+02:00
PEType:
PE32
LinkerVersion:
2.25
CodeSize:
40448
InitializedDataSize:
17920
UninitializedDataSize:
null
EntryPoint:
0xa5f8
OSVersion:
1
ImageVersion:
6
SubsystemVersion:
4
Subsystem:
Windows GUI
FileVersionNumber:
4.0.0.1
ProductVersionNumber:
4.0.0.1
FileFlagsMask:
0x003f
FileFlags:
(none)
FileOS:
Win32
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
Neutral
CharacterSet:
Unicode
Comments:
CutePDF Setup
CompanyName:
Acro Software Inc.
FileDescription:
CutePDF Writer Setup
FileVersion:
4.0.0.1
LegalCopyright:
Copyright © 2003-2019 Acro Software Inc.
ProductName:
CutePDF Writer
ProductVersion:
4.0.0.1
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
19-Jun-1992 22:22:17
Detected languages
Dutch - Netherlands
English - United States
Comments:
CutePDF Setup
CompanyName:
Acro Software Inc.
FileDescription:
CutePDF Writer Setup
FileVersion:
4.0.0.1
LegalCopyright:
Copyright © 2003-2019 Acro Software Inc.
ProductName:
CutePDF Writer
ProductVersion:
4.0.0.1
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0050
Pages in file:
0x0002
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x000F
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x001A
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x00000100
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
8
Time date stamp:
19-Jun-1992 22:22:17
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_BYTES_REVERSED_HI
IMAGE_FILE_BYTES_REVERSED_LO
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
CODE 0x00001000 0x00009D30 0x00009E00 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ 6.63175
DATA 0x0000B000 0x00000250 0x00000400 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 2.75472
BSS 0x0000C000 0x00000E90 0x00000000 IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.idata 0x0000D000 0x00000950 0x00000A00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 4.43073
.tls 0x0000E000 0x00000008 0x00000000 IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0
.rdata 0x0000F000 0x00000018 0x00000200 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_SHARED 0.204488
.reloc 0x00010000 0x000008C4 0x00000000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_SHARED 0
.rsrc 0x00011000 0x00002C00 0x00002C00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_SHARED 4.59222
Resources
1

2

3

4

4089

4090

4091

4093

4094

4095

11111

MAINICON

Imports
    kernel32.dll

    user32.dll

    oleaut32.dll

    advapi32.dll

    comctl32.dll

Exports

    No exports.

Screenshots

Processes

Total processes
43
Monitored processes
8
Malicious processes
2
Suspicious processes
1

Behavior graph

+
drop and start start drop and start drop and start cutewriter.exe cutewriter.tmp no specs cutewriter.exe cutewriter.tmp setup.exe spoolsv.exe iexplore.exe iexplore.exe
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
1204
CMD
C:\Windows\System32\spoolsv.exe
Path
C:\Windows\System32\spoolsv.exe
Indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Spooler SubSystem App
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\spoolsv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\slc.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\credssp.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\winsta.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\umb.dll
c:\windows\system32\atl.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\localspl.dll
c:\windows\system32\spoolss.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\winspool.drv
c:\windows\system32\printisolationproxy.dll
c:\windows\system32\fxsmon.dll
c:\windows\system32\tcpmon.dll
c:\windows\system32\snmpapi.dll
c:\windows\system32\wsnmp32.dll
c:\windows\system32\msxml6.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\usbmon.dll
c:\windows\system32\wls0wndh.dll
c:\windows\system32\wsdmon.dll
c:\windows\system32\wsdapi.dll
c:\windows\system32\webservices.dll
c:\windows\system32\firewallapi.dll
c:\windows\system32\version.dll
c:\windows\system32\fundisc.dll
c:\windows\system32\fdpnp.dll
c:\windows\system32\spool\prtprocs\w32x86\winprint.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\win32spl.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\spinf.dll
c:\windows\system32\inetpp.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\netutils.dll
c:\windows\system32\spool\drivers\w32x86\pscript5.dll
c:\windows\system32\spool\drivers\w32x86\ps5ui.dll
c:\windows\system32\ntprint.dll
c:\windows\system32\mscms.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\spool\drivers\w32x86\3\pscript5.dll
c:\windows\system32\spool\drivers\w32x86\3\ps5ui.dll
c:\windows\system32\cpwmon32_v40.dll
c:\windows\system32\fxsresm.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll

PID
2412
CMD
"C:\Users\admin\AppData\Local\Temp\CuteWriter.exe"
Path
C:\Users\admin\AppData\Local\Temp\CuteWriter.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Acro Software Inc.
Description
CutePDF Writer Setup
Version
4.0.0.1
Modules
Image
c:\users\admin\appdata\local\temp\cutewriter.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\shell32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\is-qp7r3.tmp\cutewriter.tmp

PID
3376
CMD
"C:\Users\admin\AppData\Local\Temp\is-QP7R3.tmp\CuteWriter.tmp" /SL5="$4012C,3016218,56832,C:\Users\admin\AppData\Local\Temp\CuteWriter.exe"
Path
C:\Users\admin\AppData\Local\Temp\is-QP7R3.tmp\CuteWriter.tmp
Indicators
No indicators
Parent process
CuteWriter.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Setup/Uninstall
Version
51.52.0.0
Modules
Image
c:\users\admin\appdata\local\temp\is-qp7r3.tmp\cutewriter.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\mpr.dll
c:\windows\system32\version.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\imm32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll

PID
3860
CMD
"C:\Users\admin\AppData\Local\Temp\CuteWriter.exe" /SPAWNWND=$D011E /NOTIFYWND=$4012C
Path
C:\Users\admin\AppData\Local\Temp\CuteWriter.exe
Indicators
Parent process
CuteWriter.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Acro Software Inc.
Description
CutePDF Writer Setup
Version
4.0.0.1
Modules
Image
c:\users\admin\appdata\local\temp\cutewriter.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\shell32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\is-1dnl4.tmp\cutewriter.tmp

PID
2880
CMD
"C:\Users\admin\AppData\Local\Temp\is-1DNL4.tmp\CuteWriter.tmp" /SL5="$50126,3016218,56832,C:\Users\admin\AppData\Local\Temp\CuteWriter.exe" /SPAWNWND=$D011E /NOTIFYWND=$4012C
Path
C:\Users\admin\AppData\Local\Temp\is-1DNL4.tmp\CuteWriter.tmp
Indicators
Parent process
CuteWriter.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Setup/Uninstall
Version
51.52.0.0
Modules
Image
c:\users\admin\appdata\local\temp\is-1dnl4.tmp\cutewriter.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\mpr.dll
c:\windows\system32\version.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\profapi.dll
c:\users\admin\appdata\local\temp\is-ccrvt.tmp\_isetup\_shfoldr.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\imageres.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\riched20.dll
c:\windows\system32\msls31.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\is-ccrvt.tmp\setup.exe
c:\windows\system32\propsys.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\program files\internet explorer\iexplore.exe

PID
1932
CMD
"C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\Setup.exe" /inscpw4 -d"C:\Program Files\CutePDF Writer"
Path
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\Setup.exe
Indicators
Parent process
CuteWriter.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Acro Software Inc.
Description
CutePDF Writer Setup
Version
4, 0, 0, 1
Modules
Image
c:\users\admin\appdata\local\temp\is-ccrvt.tmp\setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\mfc42.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\odbc32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\winspool.drv
c:\windows\system32\shell32.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\odbcint.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cpwmon32_v40.dll

PID
2768
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" -nohome
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
CuteWriter.tmp
User
admin
Integrity Level
HIGH
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\cryptbase.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\ieui.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\clbcatq.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\url.dll
c:\windows\system32\version.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\propsys.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\msfeeds.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\mlang.dll
c:\windows\system32\mssprxy.dll

PID
3840
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2768 CREDAT:79873
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
iexplore.exe
User
admin
Integrity Level
HIGH
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\psapi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\comdlg32.dll
c:\program files\internet explorer\ieshims.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\sspicli.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mlang.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\apphelp.dll
c:\program files\java\jre1.8.0_92\bin\ssv.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\version.dll
c:\progra~1\micros~1\office14\urlredir.dll
c:\windows\system32\secur32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\progra~1\micros~1\office14\msohev.dll
c:\program files\java\jre1.8.0_92\bin\jp2ssv.dll
c:\program files\java\jre1.8.0_92\bin\msvcr100.dll
c:\program files\java\jre1.8.0_92\bin\deploy.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\sxs.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\credssp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\p2pcollab.dll
c:\windows\system32\qagentrt.dll
c:\windows\system32\fveui.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\jscript.dll
c:\windows\system32\iepeers.dll
c:\windows\system32\winspool.drv
c:\windows\system32\xmllite.dll
c:\windows\system32\macromed\flash\flash32_26_0_0_131.ocx
c:\windows\system32\winmm.dll
c:\windows\system32\dsound.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\mscms.dll
c:\windows\system32\dinput8.dll
c:\windows\system32\imgutil.dll
c:\windows\system32\pngfilt.dll

Registry activity

Total events
1481
Read events
708
Write events
769
Delete events
4

Modification events

PID
Process
Operation
Key
Name
Value
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\CutePDF Writer v4.0
Dependent Files
PSCRIPT.NTF
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\CutePDF Writer v4.0
Configuration File
PS5UI.DLL
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\CutePDF Writer v4.0
Data File
CUTEPDFW.PPD
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\CutePDF Writer v4.0
Driver
PSCRIPT5.DLL
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\CutePDF Writer v4.0
Help File
PSCRIPT.HLP
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\CutePDF Writer v4.0
Monitor
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\CutePDF Writer v4.0
Datatype
RAW
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\CutePDF Writer v4.0
Previous Names
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\CutePDF Writer v4.0
Version
3
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\CutePDF Writer v4.0
TempDir
0
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\CutePDF Writer v4.0
Attributes
2
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\CutePDF Writer v4.0
Manufacturer
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\CutePDF Writer v4.0
OEM URL
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\CutePDF Writer v4.0
HardwareID
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\CutePDF Writer v4.0
Provider
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\CutePDF Writer v4.0
Print Processor
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\CutePDF Writer v4.0
VendorSetup
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\CutePDF Writer v4.0
ColorProfiles
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\CutePDF Writer v4.0
InfPath
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\CutePDF Writer v4.0
PrinterDriverAttributes
0
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\CutePDF Writer v4.0
CoreDependencies
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\CutePDF Writer v4.0
DriverDate
01/01/1601
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\CutePDF Writer v4.0
DriverVersion
0.0.0.0
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\CutePDF Writer v4.0
MinInboxDriverVerDate
01/01/1601
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows NT x86\Drivers\Version-3\CutePDF Writer v4.0
MinInboxDriverVerVersion
0.0.0.0
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3804750
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3804750
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3804750
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Monitors\CutePDF Writer Monitor v4.0
Driver
cpwmon32_v40.dll
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Monitors\CutePDF Writer Monitor v4.0\CPW4:
CutePDF Writer
1204
spoolsv.exe
write
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\Devices
CutePDF Writer
winspool,CPW4:
1204
spoolsv.exe
write
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows NT\CurrentVersion\PrinterPorts
CutePDF Writer
winspool,CPW4:,15,45
1204
spoolsv.exe
write
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\Devices
CutePDF Writer
winspool,CPW4:
1204
spoolsv.exe
write
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows NT\CurrentVersion\PrinterPorts
CutePDF Writer
winspool,CPW4:,15,45
1204
spoolsv.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Windows NT\CurrentVersion\Devices
CutePDF Writer
winspool,CPW4:
1204
spoolsv.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Windows NT\CurrentVersion\PrinterPorts
CutePDF Writer
winspool,CPW4:,15,45
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3804796
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
StatusExt
0
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
Status
64
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
Name
CutePDF Writer
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
Share Name
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
Print Processor
winprint
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
Datatype
RAW
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
Parameters
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
Action
0
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ObjectGUID
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
DsKeyUpdate
0
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
DsKeyUpdateForeground
0
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
Description
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
Printer Driver
CutePDF Writer v4.0
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
Default DevMode
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
Priority
1
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
Default Priority
0
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
StartTime
0
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
UntilTime
0
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
Separator File
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
Location
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
Attributes
64
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
txTimeout
45000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
dnsTimeout
15000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
Security
01000C80D0000000DC00000000000000140000000200BC0007000000000024000C000F000105000000000005150000007C3E9B4DF44C73593E88FD13E80300000009240030000F000105000000000005150000007C3E9B4DF44C73593E88FD13E803000000091400000000100101000000000003000000000000140008000200010100000000000100000000000A140000000020010100000000000100000000000018000C000F0001020000000000052000000020020000000B18000000001001020000000000052000000020020000010100000000000512000000010100000000000512000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
CreatorSid
0105000000000005150000007C3E9B4DF44C73593E88FD13E8030000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
SpoolDirectory
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
Port
CPW4:
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
Status
0
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\PrinterDriverData
InitDriverVersion
1536
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3804828
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\PrinterDriverData
FreeMem
4096
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3804843
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\PrinterDriverData
JobTimeOut
0
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3804844
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\PrinterDriverData
Protocol
0
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3804859
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\PrinterDriverData
PrinterDataSize
560
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3804860
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\PrinterDriverData
PrinterData
00063002800C000000004000000000002C010000640058020000000000000000000000000000000075AC5E6D010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3804875
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\PrinterDriverData
FeatureKeywordSize
24
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3804890
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\PrinterDriverData
FeatureKeyword
496E7374616C6C65644D656D6F7279004E6F6E65000A0000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3804891
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
11 x 17
68430400B8960600000000000000000068430400B89606000100000002000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\11 x 17
FormKeyword
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3804906
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3804906
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3804906
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3804906
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
Screen
EC840200020202000000000000000000EC840200020202000200000002000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\Screen
FormKeyword
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3804921
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3804921
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3804921
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3804937
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
ISO A0
3ED50C00FD23120000000000000000003ED50C00FD2312000300000002000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\ISO A0
FormKeyword
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3804937
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3804937
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3804953
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3804953
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
ISO A1
9E1009003ED50C0000000000000000009E1009003ED50C000400000002000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\ISO A1
FormKeyword
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3804953
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3804953
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3804954
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3804968
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
ISO A2
3E6906009E10090000000000000000003E6906009E1009000500000002000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\ISO A2
FormKeyword
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3804968
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3804968
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3804968
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3804969
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
B1 (JIS)
451C0B00DFB70F000000000000000000451C0B00DFB70F000600000002000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\B1 (JIS)
FormKeyword
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3804984
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3804984
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3804984
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3804984
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
B2 (JIS)
F0DB0700451C0B000000000000000000F0DB0700451C0B000700000002000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\B2 (JIS)
FormKeyword
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3805000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3805000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3805000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
B3 (JIS)
238E0500F0DB07000000000000000000238E0500F0DB07000800000002000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\B3 (JIS)
FormKeyword
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805015
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3805015
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3805015
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3805031
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
B4 (JIS)[257 x 364 mm]
97EC0300238E0500000000000000000097EC0300238E05000900000002000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\B4 (JIS)[257 x 364 mm]
FormKeyword
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805031
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3805031
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3805031
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3805032
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
B5 (JIS)[182 x 257 mm]
11C7020097EC0300000000000000000011C7020097EC03000A00000002000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\B5 (JIS)[182 x 257 mm]
FormKeyword
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805046
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3805046
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3805046
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3805046
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
No. 10 Envelope[4.125 x 9.5 in]
4799010094AE030000000000000000004799010094AE03000B00000002000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\No. 10 Envelope[4.125 x 9.5 in]
FormKeyword
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805062
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3805062
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3805062
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3805062
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
C5 Envelope[162 x 229 mm]
85780200597E0300000000000000000085780200597E03000C00000002000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\C5 Envelope[162 x 229 mm]
FormKeyword
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805078
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3805078
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3805078
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3805078
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
DL Envelope[110 x 220 mm]
F3AD0100E55B03000000000000000000F3AD0100E55B03000D00000002000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\DL Envelope[110 x 220 mm]
FormKeyword
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805079
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3805093
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3805093
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3805093
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
Monarch Envelope[3.87 x 7.5 in]
7980010024E8020000000000000000007980010024E802000E00000002000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\Monarch Envelope[3.87 x 7.5 in]
FormKeyword
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805093
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3805109
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3805109
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3805109
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
ARCH A
F87C0300A0A604000000000000000000F87C0300A0A604000F00000002000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\ARCH A
FormKeyword
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805109
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3805125
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3805125
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3805125
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
ARCH B
A0A60400F0F906000000000000000000A0A60400F0F906001000000002000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\ARCH B
FormKeyword
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805125
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3805140
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3805140
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3805140
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
ARCH C
F0F90600404D09000000000000000000F0F90600404D09001100000002000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\ARCH C
FormKeyword
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805140
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3805141
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3805156
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3805156
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
ARCH D
404D0900E0F30D000000000000000000404D0900E0F30D001200000002000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\ARCH D
FormKeyword
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805156
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3805156
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3805171
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3805171
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
ARCH E
E0F30D00809A12000000000000000000E0F30D00809A12001300000002000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\ARCH E
FormKeyword
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805171
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3805171
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3805187
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3805187
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
ARCH E1
90A00B0030471000000000000000000090A00B00304710001400000002000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\ARCH E1
FormKeyword
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805187
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3805187
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3805188
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3805188
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
Folio[8.5 x 13 in]
5C4B0300D809050000000000000000005C4B0300D80905001500000002000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\Folio[8.5 x 13 in]
FormKeyword
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805203
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3805203
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3805203
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3805203
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
Statement[5.5 x 8.5 in]
B42102005C4B03000000000000000000B42102005C4B03001600000002000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\Statement[5.5 x 8.5 in]
FormKeyword
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805204
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3805204
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3805204
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3805204
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
Note[7.5 x 10 in]
24E8020030E00300000000000000000024E8020030E003001700000002000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\Note[7.5 x 10 in]
FormKeyword
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805218
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3805218
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3805218
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3805218
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
ISO-B1
97C90A001E440F00000000000000000097C90A001E440F001800000002000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\ISO-B1
FormKeyword
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805219
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3805234
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3805234
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3805234
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
8.5 x 10 in
5C4B030030E0030000000000000000005C4B030030E003001900000002000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\8.5 x 10 in
FormKeyword
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805234
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3805235
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3805235
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3805235
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
22 x 36 in
D0860800E0F30D000000000000000000D0860800E0F30D001A00000002000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\22 x 36 in
FormKeyword
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805250
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3805250
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3805250
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3805250
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
24 x 48 in
404D0900809A12000000000000000000404D0900809A12001B00000002000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\24 x 48 in
FormKeyword
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805251
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3805251
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3805265
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3805265
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
24 x 60 in
404D0900204117000000000000000000404D0900204117001C00000002000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\24 x 60 in
FormKeyword
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805265
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3805265
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3805266
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3805266
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
24 x 72 in
404D0900C0E71B000000000000000000404D0900C0E71B001D00000002000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\24 x 72 in
FormKeyword
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805281
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3805281
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3805281
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3805281
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
24 x 84 in
404D0900608E20000000000000000000404D0900608E20001E00000002000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\24 x 84 in
FormKeyword
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805296
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3805296
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3805296
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3805296
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
24 x 96 in
404D0900003525000000000000000000404D0900003525001F00000002000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\24 x 96 in
FormKeyword
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805297
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3805297
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3805297
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3805312
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
24 x 108 in
404D0900A0DB29000000000000000000404D0900A0DB29002000000002000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\24 x 108 in
FormKeyword
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805312
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3805312
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3805312
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3805328
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
36 x 42 in
E0F30D00304710000000000000000000E0F30D00304710002100000002000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\36 x 42 in
FormKeyword
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805328
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3805328
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3805328
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3805329
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
36 x 60 in
E0F30D00204117000000000000000000E0F30D00204117002200000002000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\36 x 60 in
FormKeyword
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805343
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3805343
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3805343
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3805343
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
36 x 72 in
E0F30D00C0E71B000000000000000000E0F30D00C0E71B002300000002000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\36 x 72 in
FormKeyword
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805359
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3805359
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3805359
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3805359
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
36 x 84 in
E0F30D00608E20000000000000000000E0F30D00608E20002400000002000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\36 x 84 in
FormKeyword
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805375
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3805375
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3805375
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3805375
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
36 x 96 in
E0F30D00003525000000000000000000E0F30D00003525002500000002000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\36 x 96 in
FormKeyword
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805390
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3805390
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3805390
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3805390
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms
36 x 108 in
E0F30D00A0DB29000000000000000000E0F30D00A0DB29002600000002000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Forms\36 x 108 in
FormKeyword
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805406
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Send To OneNote 2010
ChangeID
3805406
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Microsoft XPS Document Writer
ChangeID
3805406
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\Fax
ChangeID
3805406
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\PrinterDriverData
Forms?
1834921077
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805421
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\PrinterDriverData
DependentFiles
PSCRIPT.NTF
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805422
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805437
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
Status
128
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
DsKeyUpdateForeground
1
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\DsSpooler
driverName
CutePDF Writer v4.0
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\DsSpooler
portName
CPW4:
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\DsSpooler
printStartTime
0
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\DsSpooler
printEndTime
0
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\DsSpooler
printerName
CutePDF Writer
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\DsSpooler
printKeepPrintedJobs
00
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\DsSpooler
printSpooling
PrintWhileSpooling
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\DsSpooler
priority
1
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\DsSpooler
uNCName
\\User-PC\CutePDF Writer
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\DsSpooler
serverName
User-PC
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\DsSpooler
shortServerName
USER-PC
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\DsSpooler
versionNumber
4
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\DsSpooler
flags
0
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\DsDriver
printBinNames
Automatically Select
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
DsKeyUpdateForeground
3
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\DsDriver
printCollate
01
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\DsDriver
printColor
01
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\DsDriver
printDuplexSupported
00
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\DsDriver
printStaplingSupported
00
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\DsDriver
printMaxXExtent
32767
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\DsDriver
printMaxYExtent
32767
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\DsDriver
printMinXExtent
254
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\DsDriver
printMinYExtent
254
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\DsDriver
printMediaSupported
Letter
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\DsDriver
printMediaReady
Letter
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\DsDriver
printNumberUp
6
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\DsDriver
printMemory
4096
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\DsDriver
printOrientationsSupported
PORTRAIT
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\DsDriver
printMaxResolutionSupported
4000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\DsDriver
printLanguage
PostScript
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\DsDriver
printRate
400
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\DsDriver
printRateUnit
PagesPerMinute
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\DsDriver
printPagesPerMinute
400
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\DsDriver
driverVersion
1025
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805671
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
Default DevMode
4300750074006500500044004600200057007200690074006500720000004400460020005700720069007400650072002C004C006F00630061006C004F00000001040006DC008C0353EF810101000100EA0A6F08640001000F005802020001005802030001004C00650074007400650072000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000100000000000000010000000200000001000000000000000000000000000000000000000000000050524956E23000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000180000000000102710271027000010270000000000000000B8008C030000000000000000000000000000000000000000000000000300000000000000000010005C4B0300684304000000000000000000000000000000000000000000000000000000000075AC5E6D0500000003000000FF00FF0001000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001000000000000000000000000000000B8000000534D544A000000001000A800430075007400650050004400460020005700720069007400650072002000760034002E00300000005265736F6C7574696F6E00363030647069005061676553697A65004C65747465720050616765526567696F6E00004C656164696E67456467650000496E707574536C6F74004F6E6C794F6E6500000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
1204
spoolsv.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\DsDriver
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805687
1204
spoolsv.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\DsSpooler
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805812
1204
spoolsv.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Printers\DevModePerUser
CutePDF Writer
4300750074006500500044004600200057007200690074006500720000000000000000000000000000000000000000000000000000000000000000000000000001040006DC008C0353EF810101000100EA0A6F08640001000F005802020001005802030001004C00650074007400650072000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000100000000000000010000000200000001000000000000000000000000000000000000000000000050524956E23000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000180000000000102710271027000010270000000000000000B8008C030000000000000000000000000000000000000000000000000300000000000000000010005C4B0300684304000000000000000000000000000000000000000000000000000000000075AC5E6D0500000003000000FF00FF0001000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001000000000000000000000000000000B8000000534D544A000000001000A800430075007400650050004400460020005700720069007400650072002000760034002E00300000005265736F6C7574696F6E00363030647069005061676553697A65004C65747465720050616765526567696F6E00004C656164696E67456467650000496E707574536C6F74004F6E6C794F6E6500000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
ChangeID
3805906
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer
Attributes
576
1204
spoolsv.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\CutePDF Writer\DsSpooler
printSpooling
PrintAfterSpooled
2880
CuteWriter.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Owner
400B0000F0E718215396D501
2880
CuteWriter.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
SessionHash
9FD4B6B875FEFCC6707D6AF85E53B1FF4FD85BCDAA967DD88D516D06AD957D6A
2880
CuteWriter.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Sequence
1
2880
CuteWriter.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
RegFiles0000
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\cpwmon32_v40.dll
2880
CuteWriter.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
RegFilesHash
E974DF4AAB390B09E63C5ED8F8340CBEC5460BE85522B26F570E46C9A07020DD
2880
CuteWriter.tmp
delete key
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
1932
Setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Acro Software Inc\CutePDF Writer
Port Name
CPW4:
1932
Setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Acro Software Inc\CutePDF Writer
Printer Name
CutePDF Writer
1932
Setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Acro Software Inc\CutePDF Writer
Destination Folder
C:\Program Files\CutePDF Writer
1932
Setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Acro Software Inc\CutePDF Writer
Programmatic Access
0
1932
Setup.exe
write
HKEY_CURRENT_USER\Printers\DevModes2
CutePDF Writer
4300750074006500500044004600200057007200690074006500720000000000000000000000000000000000000000000000000000000000000000000000000001040006DC008C0353EF810101000100EA0A6F08640001000F005802020001005802030001004C00650074007400650072000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000100000000000000010000000200000001000000000000000000000000000000000000000000000050524956E23000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000180000000000102710271027000010270000000000000000B8008C030000000000000000000000000000000000000000000000000300000000000000000010005C4B0300684304000000000000000000000000000000000000000000000000000000000075AC5E6D0500000003000000FF00FF0001000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001000000000000000000000000000000B8000000534D544A000000001000A800430075007400650050004400460020005700720069007400650072002000760034002E00300000005265736F6C7574696F6E00363030647069005061676553697A65004C65747465720050616765526567696F6E00004C656164696E67456467650000496E707574536C6F74004F6E6C794F6E6500000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
1932
Setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CutePDF Writer Installation
DisplayName
CutePDF Writer
1932
Setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CutePDF Writer Installation
UninstallString
C:\Program Files\CutePDF Writer\uninstcpw.exe C:\Program Files\CutePDF Writer
1932
Setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CutePDF Writer Installation
DisplayVersion
4.0
1932
Setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CutePDF Writer Installation
Publisher
Acro Software Inc.
1932
Setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CutePDF Writer Installation
DisplayIcon
C:\Program Files\CutePDF Writer\CuteEdit.ico
1932
Setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CutePDF Writer Installation
InstallLocation
C:\Program Files\CutePDF Writer
1932
Setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CutePDF Writer Installation
HelpLink
http://www.CutePDF.com
1932
Setup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Acro Software Inc\CutePDF Writer\CPW4:
Destination Folder
C:\Program Files\CutePDF Writer
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
CompatibilityFlags
0
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
SecuritySafe
1
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000092000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\AdminActive
{6E5C9451-0246-11EA-AB41-5254004A04AF}
0
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Type
4
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Count
2
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Time
E3070B0005000800100028000C009301
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Type
4
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Count
2
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Time
E3070B0005000800100028000C009301
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
FullScreen
no
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Window_Placement
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF20000000200000004003000078020000
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\Links
Order
08000000020000000C01000001000000020000007E0000000000000070003200EC000000464B245120005355474745537E312E55524C0000540008000400EFBE454B974D464B24512A000000F94300000000020000000000000000000000000000005300750067006700650073007400650064002000530069007400650073002E00750072006C0000001C00000000000000820000000100000074003200E2000000464B24512000574542534C497E312E55524C0000580008000400EFBE454B864A464B24512A000000743E0000000003000000000000000000000000000000570065006200200053006C006900630065002000470061006C006C006500720079002E00750072006C0000001C00000000000000
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\WindowsSearch
UpgradeTime
0CD908335396D501
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
Path
C:\Users\admin\Favorites\Links\Suggested Sites.url
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
Handler
{B0FA7D7C-7195-4F03-B03E-9DC1C9EBC394}
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
FeedUrl
https://ieonline.microsoft.com/#ieslice
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
DisplayName
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
ErrorState
0
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
DisplayMask
0
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
Path
C:\Users\admin\Favorites\Links\Web Slice Gallery.url
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
Handler
{B0FA7D7C-7195-4F03-B03E-9DC1C9EBC394}
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
FeedUrl
http://go.microsoft.com/fwlink/?LinkId=121315
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
DisplayName
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
ErrorState
0
2768
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
DisplayMask
0
3840
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Type
3
3840
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Count
2
3840
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Time
E3070B0005000800100028000C004E02
3840
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
LoadTime
8
3840
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Type
3
3840
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Count
2
3840
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Time
E3070B0005000800100028000C007D02
3840
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
LoadTime
57
3840
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Type
3
3840
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Count
2
3840
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Time
E3070B0005000800100028000C00FA02
3840
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
LoadTime
32
3840
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3840
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3840
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3840
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000093000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3840
iexplore.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12C\52C64B7E
LanguageList
en-US
3840
iexplore.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12C\52C64B7E
@%SystemRoot%\system32\p2pcollab.dll,-8042
Peer to Peer Trust
3840
iexplore.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12C\52C64B7E
@%SystemRoot%\system32\qagentrt.dll,-10
System Health Authentication
3840
iexplore.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12C\52C64B7E
@%SystemRoot%\system32\dnsapi.dll,-103
Domain Name System (DNS) Server Trust
3840
iexplore.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12C\52C64B7E
@%SystemRoot%\System32\fveui.dll,-843
BitLocker Drive Encryption
3840
iexplore.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12C\52C64B7E
@%SystemRoot%\System32\fveui.dll,-844
BitLocker Data Recovery Agent
3840
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\47BEABC922EAE80E78783462A79F45C254FDE68B
Blob
0F00000001000000200000003560E45B41E46B8F36537025D1D5BC02D9652A10645B0EFF69E8B6A52191F335090000000100000054000000305206082B0601050507030106082B0601050507030206082B0601050507030306082B0601050507030406082B06010505070308060A2B0601040182370A030406082B0601050507030606082B060105050703070B000000010000005200000047006F00200044006100640064007900200052006F006F007400200043006500720074006900660069006300610074006500200041007500740068006F00720069007400790020001320200047003200000053000000010000002500000030233021060B6086480186FD6D0107170330123010060A2B0601040182373C0101030200C062000000010000002000000045140B3247EB9CC8C5B4F0D7B53091F73292089E6E5A63E2749DD3ACA9198EDA1400000001000000140000003A9A8507106728B6EFF6BD05416E20C194DA0FDE1D000000010000001000000070253FBCBDE32A014D38C1993098AD9903000000010000001400000047BEABC922EAE80E78783462A79F45C254FDE68B2000000001000000C9030000308203C5308202ADA003020102020100300D06092A864886F70D01010B0500308183310B30090603550406130255533110300E060355040813074172697A6F6E61311330110603550407130A53636F74747364616C65311A3018060355040A1311476F44616464792E636F6D2C20496E632E3131302F06035504031328476F20446164647920526F6F7420436572746966696361746520417574686F72697479202D204732301E170D3039303930313030303030305A170D3337313233313233353935395A308183310B30090603550406130255533110300E060355040813074172697A6F6E61311330110603550407130A53636F74747364616C65311A3018060355040A1311476F44616464792E636F6D2C20496E632E3131302F06035504031328476F20446164647920526F6F7420436572746966696361746520417574686F72697479202D20473230820122300D06092A864886F70D01010105000382010F003082010A0282010100BF716208F1FA5934F71BC918A3F7804958E9228313A6C52043013B84F1E685499F27EAF6841B4EA0B4DB7098C73201B1053E074EEEF4FA4F2F593022E7AB19566BE28007FCF316758039517BE5F935B6744EA98D8213E4B63FA90383FAA2BE8A156A7FDE0BC3B6191405CAEAC3A804943B467C320DF3006622C88D696D368C1118B7D3B21C60B438FA028CCED3DD4607DE0A3EEB5D7CC87CFBB02B53A4926269512505611A44818C2CA9439623DFAC3A819A0E29C51CA9E95D1EB69E9E300A39CEF18880FB4B5DCC32EC85624325340256270191B43B702A3F6EB1E89C88017D9FD4F9DB536D609DBF2CE758ABB85F46FCCEC41B033C09EB49315C6946B3E0470203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E041604143A9A8507106728B6EFF6BD05416E20C194DA0FDE300D06092A864886F70D01010B0500038201010099DB5D79D5F99759670361F17E3B0631752DA1208E4F6587B4F7A69CBCD8E92FD0DB5AEECF748C73B43842DA057BF80275B8FDA5B1D7AEF6D7DE13CB53107E8A46D197FAB72E2B11AB90B02780F9E89F5AE9379FABE4DF6CB385179D3DD9244F799135D65F04EB8083AB9A022DB510F4D890C7047340ED7225A0A99FEC9EAB68129957C68F123A09A4BD44FD061537C19BE432A3ED38E8D864F32C7E14FC02EA9FCDFF076817DB2290382D7A8DD154F169E35F33CA7A3D7B0AE3CA7F5F39E5E275BAC5761833CE2CF02F4CADF7B1E7CE4FA8C49B4A5406C57F7DD5080FE21CFE7E17B8AC5EF6D416B243090C4DF6A76BB4998465CA7A88E2E244BE5CF7EA1CF5
3840
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\47BEABC922EAE80E78783462A79F45C254FDE68B
Blob
19000000010000001000000021D008B47B7A2A81C8435903DED424C903000000010000001400000047BEABC922EAE80E78783462A79F45C254FDE68B1D000000010000001000000070253FBCBDE32A014D38C1993098AD991400000001000000140000003A9A8507106728B6EFF6BD05416E20C194DA0FDE62000000010000002000000045140B3247EB9CC8C5B4F0D7B53091F73292089E6E5A63E2749DD3ACA9198EDA53000000010000002500000030233021060B6086480186FD6D0107170330123010060A2B0601040182373C0101030200C00B000000010000005200000047006F00200044006100640064007900200052006F006F007400200043006500720074006900660069006300610074006500200041007500740068006F007200690074007900200013202000470032000000090000000100000054000000305206082B0601050507030106082B0601050507030206082B0601050507030306082B0601050507030406082B06010505070308060A2B0601040182370A030406082B0601050507030606082B060105050703070F00000001000000200000003560E45B41E46B8F36537025D1D5BC02D9652A10645B0EFF69E8B6A52191F3352000000001000000C9030000308203C5308202ADA003020102020100300D06092A864886F70D01010B0500308183310B30090603550406130255533110300E060355040813074172697A6F6E61311330110603550407130A53636F74747364616C65311A3018060355040A1311476F44616464792E636F6D2C20496E632E3131302F06035504031328476F20446164647920526F6F7420436572746966696361746520417574686F72697479202D204732301E170D3039303930313030303030305A170D3337313233313233353935395A308183310B30090603550406130255533110300E060355040813074172697A6F6E61311330110603550407130A53636F74747364616C65311A3018060355040A1311476F44616464792E636F6D2C20496E632E3131302F06035504031328476F20446164647920526F6F7420436572746966696361746520417574686F72697479202D20473230820122300D06092A864886F70D01010105000382010F003082010A0282010100BF716208F1FA5934F71BC918A3F7804958E9228313A6C52043013B84F1E685499F27EAF6841B4EA0B4DB7098C73201B1053E074EEEF4FA4F2F593022E7AB19566BE28007FCF316758039517BE5F935B6744EA98D8213E4B63FA90383FAA2BE8A156A7FDE0BC3B6191405CAEAC3A804943B467C320DF3006622C88D696D368C1118B7D3B21C60B438FA028CCED3DD4607DE0A3EEB5D7CC87CFBB02B53A4926269512505611A44818C2CA9439623DFAC3A819A0E29C51CA9E95D1EB69E9E300A39CEF18880FB4B5DCC32EC85624325340256270191B43B702A3F6EB1E89C88017D9FD4F9DB536D609DBF2CE758ABB85F46FCCEC41B033C09EB49315C6946B3E0470203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E041604143A9A8507106728B6EFF6BD05416E20C194DA0FDE300D06092A864886F70D01010B0500038201010099DB5D79D5F99759670361F17E3B0631752DA1208E4F6587B4F7A69CBCD8E92FD0DB5AEECF748C73B43842DA057BF80275B8FDA5B1D7AEF6D7DE13CB53107E8A46D197FAB72E2B11AB90B02780F9E89F5AE9379FABE4DF6CB385179D3DD9244F799135D65F04EB8083AB9A022DB510F4D890C7047340ED7225A0A99FEC9EAB68129957C68F123A09A4BD44FD061537C19BE432A3ED38E8D864F32C7E14FC02EA9FCDFF076817DB2290382D7A8DD154F169E35F33CA7A3D7B0AE3CA7F5F39E5E275BAC5761833CE2CF02F4CADF7B1E7CE4FA8C49B4A5406C57F7DD5080FE21CFE7E17B8AC5EF6D416B243090C4DF6A76BB4998465CA7A88E2E244BE5CF7EA1CF5
3840
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore
CachePath
%USERPROFILE%\AppData\Local\Microsoft\Internet Explorer\DOMStore
3840
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore
CachePrefix
DOMStore
3840
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore
CacheLimit
1000
3840
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore
CacheOptions
8
3840
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore
CacheRepair
0
3840
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\Total
17
3840
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\DOMStorage\cutepdf-editor.com
17
3840
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D27CDB6E-AE6D-11CF-96B8-444553540000}\iexplore
Type
1
3840
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D27CDB6E-AE6D-11CF-96B8-444553540000}\iexplore
Count
1
3840
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D27CDB6E-AE6D-11CF-96B8-444553540000}\iexplore
Time
E3070B0005000800100028000E002903
3840
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\47BEABC922EAE80E78783462A79F45C254FDE68B
Blob
040000000100000010000000803ABC22C1E6FB8D9B3B274A321B9A010F00000001000000200000003560E45B41E46B8F36537025D1D5BC02D9652A10645B0EFF69E8B6A52191F335090000000100000054000000305206082B0601050507030106082B0601050507030206082B0601050507030306082B0601050507030406082B06010505070308060A2B0601040182370A030406082B0601050507030606082B060105050703070B000000010000005200000047006F00200044006100640064007900200052006F006F007400200043006500720074006900660069006300610074006500200041007500740068006F00720069007400790020001320200047003200000053000000010000002500000030233021060B6086480186FD6D0107170330123010060A2B0601040182373C0101030200C062000000010000002000000045140B3247EB9CC8C5B4F0D7B53091F73292089E6E5A63E2749DD3ACA9198EDA1400000001000000140000003A9A8507106728B6EFF6BD05416E20C194DA0FDE1D000000010000001000000070253FBCBDE32A014D38C1993098AD9903000000010000001400000047BEABC922EAE80E78783462A79F45C254FDE68B19000000010000001000000021D008B47B7A2A81C8435903DED424C92000000001000000C9030000308203C5308202ADA003020102020100300D06092A864886F70D01010B0500308183310B30090603550406130255533110300E060355040813074172697A6F6E61311330110603550407130A53636F74747364616C65311A3018060355040A1311476F44616464792E636F6D2C20496E632E3131302F06035504031328476F20446164647920526F6F7420436572746966696361746520417574686F72697479202D204732301E170D3039303930313030303030305A170D3337313233313233353935395A308183310B30090603550406130255533110300E060355040813074172697A6F6E61311330110603550407130A53636F74747364616C65311A3018060355040A1311476F44616464792E636F6D2C20496E632E3131302F06035504031328476F20446164647920526F6F7420436572746966696361746520417574686F72697479202D20473230820122300D06092A864886F70D01010105000382010F003082010A0282010100BF716208F1FA5934F71BC918A3F7804958E9228313A6C52043013B84F1E685499F27EAF6841B4EA0B4DB7098C73201B1053E074EEEF4FA4F2F593022E7AB19566BE28007FCF316758039517BE5F935B6744EA98D8213E4B63FA90383FAA2BE8A156A7FDE0BC3B6191405CAEAC3A804943B467C320DF3006622C88D696D368C1118B7D3B21C60B438FA028CCED3DD4607DE0A3EEB5D7CC87CFBB02B53A4926269512505611A44818C2CA9439623DFAC3A819A0E29C51CA9E95D1EB69E9E300A39CEF18880FB4B5DCC32EC85624325340256270191B43B702A3F6EB1E89C88017D9FD4F9DB536D609DBF2CE758ABB85F46FCCEC41B033C09EB49315C6946B3E0470203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E041604143A9A8507106728B6EFF6BD05416E20C194DA0FDE300D06092A864886F70D01010B0500038201010099DB5D79D5F99759670361F17E3B0631752DA1208E4F6587B4F7A69CBCD8E92FD0DB5AEECF748C73B43842DA057BF80275B8FDA5B1D7AEF6D7DE13CB53107E8A46D197FAB72E2B11AB90B02780F9E89F5AE9379FABE4DF6CB385179D3DD9244F799135D65F04EB8083AB9A022DB510F4D890C7047340ED7225A0A99FEC9EAB68129957C68F123A09A4BD44FD061537C19BE432A3ED38E8D864F32C7E14FC02EA9FCDFF076817DB2290382D7A8DD154F169E35F33CA7A3D7B0AE3CA7F5F39E5E275BAC5761833CE2CF02F4CADF7B1E7CE4FA8C49B4A5406C57F7DD5080FE21CFE7E17B8AC5EF6D416B243090C4DF6A76BB4998465CA7A88E2E244BE5CF7EA1CF5
3840
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019110820191109
CachePath
%USERPROFILE%\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019110820191109
3840
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019110820191109
CachePrefix
:2019110820191109:
3840
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019110820191109
CacheLimit
8192
3840
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019110820191109
CacheOptions
11
3840
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019110820191109
CacheRepair
0
3840
iexplore.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019092020190921

Files activity

Executable files
28
Suspicious files
9
Text files
41
Unknown types
11

Dropped files

PID
Process
Filename
Type
2412
CuteWriter.exe
C:\Users\admin\AppData\Local\Temp\is-QP7R3.tmp\CuteWriter.tmp
executable
MD5: ffcf263a020aa7794015af0edee5df0b
SHA256: 1d07cfb7104b85fc0dffd761f6848ad176117e146bbb4079fe993efa06b94c64
1932
Setup.exe
C:\Program Files\CutePDF Writer\CPWriter2.exe
executable
MD5: 065af54ac2b735d81cdd61f43b1ae459
SHA256: be4efc18e54b0da1df2d7dcb5d115222131063a91714355f1f097c36a0946358
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\pdfwriter64.exe
executable
MD5: 5d98b3bd72d5fb31dddb0d46d20e0125
SHA256: 3b493d06decbb0a5b2f9e45d8803678bb5b41db1d816fb185d0da06fdeebd85d
1932
Setup.exe
C:\Program Files\CutePDF Writer\uninstcpw.exe
executable
MD5: 4933213459affc3a3648d5e0df42d039
SHA256: 959f6535b60721a621154e6d6d15e67029158839c55475cb8967d7f5f200ff31
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\pdfwriter32.exe
executable
MD5: 8ec1e96e785295b1afc899321e4ba0d9
SHA256: c6387faa456ff9607764e67bb5b912aca0147ecd9cf357459bb5be40d21504a2
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\Setup.exe
executable
MD5: 039fd2c70917f26783841217fd7e2e8b
SHA256: f6a6032925ac809f883b28f3a3a3619a85027903167b28d161946ed232779f6d
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\CutePDFWriter.exe
executable
MD5: c53d95b4df4cea2a34724dee08599557
SHA256: 3fadf11079547c0b9f86fb35850289fec22af2c9625ebc153384a9776c90dd05
1932
Setup.exe
C:\Windows\system32\spool\DRIVERS\W32X86\PSCRIPT5.DLL
executable
MD5: 28e60cef92843c1ea5c221ddc308b766
SHA256: dc0956aab89babbcc6f335192f7fbf1dc5349e13b1746c429feff75427a47030
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\CPWriter2.exe
executable
MD5: 065af54ac2b735d81cdd61f43b1ae459
SHA256: be4efc18e54b0da1df2d7dcb5d115222131063a91714355f1f097c36a0946358
1932
Setup.exe
C:\Windows\system32\spool\DRIVERS\W32X86\PS5UI.DLL
executable
MD5: a8c4d265f14c4f977c399d51971041b6
SHA256: 8b105e50eb3289b7a52e70cfe4644800eff98d8a50288b55f5eb0c3e8b2f16e1
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\cpwmon64_v40.dll
executable
MD5: de5b72ea70f252420237ea411b5c9a28
SHA256: a2e9fe45f3d0c350b65bd142332eed01cfc7242ffd69ab3e3b631703654dd61c
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\unInstcpw.exe
executable
MD5: 4933213459affc3a3648d5e0df42d039
SHA256: 959f6535b60721a621154e6d6d15e67029158839c55475cb8967d7f5f200ff31
1204
spoolsv.exe
C:\Windows\system32\spool\DRIVERS\W32X86\3\PS5UI.DLL
executable
MD5: a8c4d265f14c4f977c399d51971041b6
SHA256: 8b105e50eb3289b7a52e70cfe4644800eff98d8a50288b55f5eb0c3e8b2f16e1
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\unInstcpw64.exe
executable
MD5: c183a7a175d4f205495db21d4aa4c14a
SHA256: 38b5a4afe0bb8ada237b0ef1327783f332fd5be37d7750f6a4847dd116780da8
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\cpwmon32_v40.dll
executable
MD5: 9c2e3849e5e57f3ce8bf864739336bd9
SHA256: 4928417b10ebcc16985c5f7f4b27d206c6159d2cb4d45b452d657442ea852f0b
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\Driver\ICONLIB.DLL
executable
MD5: 9de3278966747fd3d36c6a6e8469eeca
SHA256: d50e32dfac6c05e20572c0a6279c37f622da290d5a7bca4d84a28039f32cc16a
1204
spoolsv.exe
C:\Windows\system32\spool\DRIVERS\W32X86\3\PSCRIPT5.DLL
executable
MD5: 28e60cef92843c1ea5c221ddc308b766
SHA256: dc0956aab89babbcc6f335192f7fbf1dc5349e13b1746c429feff75427a47030
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\Driver\PS5UI.DLL
executable
MD5: a8c4d265f14c4f977c399d51971041b6
SHA256: 8b105e50eb3289b7a52e70cfe4644800eff98d8a50288b55f5eb0c3e8b2f16e1
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\_isetup\_shfoldr.dll
executable
MD5: 92dc6ef532fbb4a5c3201469a5b5eb63
SHA256: 9884e9d1b4f8a873ccbd81f8ad0ae257776d2348d027d811a56475e028360d87
1932
Setup.exe
C:\Program Files\CutePDF Writer\CPWSave.exe
executable
MD5: 8ec1e96e785295b1afc899321e4ba0d9
SHA256: c6387faa456ff9607764e67bb5b912aca0147ecd9cf357459bb5be40d21504a2
1932
Setup.exe
C:\Windows\system32\cpwmon32_v40.dll
executable
MD5: 9c2e3849e5e57f3ce8bf864739336bd9
SHA256: 4928417b10ebcc16985c5f7f4b27d206c6159d2cb4d45b452d657442ea852f0b
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\Driver\PSCRIPT5.DLL
executable
MD5: 28e60cef92843c1ea5c221ddc308b766
SHA256: dc0956aab89babbcc6f335192f7fbf1dc5349e13b1746c429feff75427a47030
3860
CuteWriter.exe
C:\Users\admin\AppData\Local\Temp\is-1DNL4.tmp\CuteWriter.tmp
executable
MD5: ffcf263a020aa7794015af0edee5df0b
SHA256: 1d07cfb7104b85fc0dffd761f6848ad176117e146bbb4079fe993efa06b94c64
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\Driver\PSMON.DLL
executable
MD5: 28e9ec320646cc0779422f5f9dc9129a
SHA256: 6f9aaecb57de35d7abd922e6514d62ea3f66ff114b4ace6011085d17c603f566
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\Driver\PSCRIPT.DRV
executable
MD5: 7196a6992c91776b9e6ec50357c412b2
SHA256: 9b7ef4226b9450fa16b30c6830370777134ce45f41c245863cc031dcce2caa73
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\Driver\x64\PS5UI.DLL
executable
MD5: 1ede62e047f4bb3d0398eba367c16484
SHA256: 277d1da8c6fd51c3cc958a459ecc18ba5551adbc1c1d8588082c9583324c8953
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\Driver\x64\PSCRIPT5.DLL
executable
MD5: fb270d281f4929b9e0894afc816c9dbe
SHA256: 9f0dc9c094ae73aa052817e0233f5deb5c18c7c8ef63733e95d4cde65e0386f0
1932
Setup.exe
C:\Program Files\CutePDF Writer\CutePDFWriter.exe
executable
MD5: c53d95b4df4cea2a34724dee08599557
SHA256: 3fadf11079547c0b9f86fb35850289fec22af2c9625ebc153384a9776c90dd05
3840
iexplore.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
binary
MD5: f5501a69c73c7846e65d2f405b2a23e7
SHA256: ea8634013ec3d010673dcb1d72fd49f961adf269b2d3f3eca55bd78f69280091
3840
iexplore.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
compressed
MD5: 5ad071a3917588e8cd883b123b395b21
SHA256: de62965c15528da598b0079d2d20d953dd6f71b13a23807bff0666d03f69c0fa
3840
iexplore.exe
C:\Users\admin\AppData\Local\Temp\Tar1C1E.tmp
––
MD5:  ––
SHA256:  ––
3840
iexplore.exe
C:\Users\admin\AppData\Local\Temp\Cab1C1D.tmp
––
MD5:  ––
SHA256:  ––
3840
iexplore.exe
C:\Users\admin\AppData\Local\Temp\Tar1B9F.tmp
––
MD5:  ––
SHA256:  ––
3840
iexplore.exe
C:\Users\admin\AppData\Local\Temp\Cab1B9E.tmp
––
MD5:  ––
SHA256:  ––
3840
iexplore.exe
C:\Users\admin\AppData\Local\Temp\Cab1B8C.tmp
––
MD5:  ––
SHA256:  ––
3840
iexplore.exe
C:\Users\admin\AppData\Local\Temp\Tar1B8D.tmp
––
MD5:  ––
SHA256:  ––
2768
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\favicon[1].png
image
MD5: 9fb559a691078558e77d6848202f6541
SHA256: 6d8a01dc7647bc218d003b58fe04049e24a9359900b7e0cebae76edf85b8b914
2768
iexplore.exe
C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
––
MD5:  ––
SHA256:  ––
2768
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\favicon[1].ico
––
MD5:  ––
SHA256:  ––
1204
spoolsv.exe
C:\Windows\system32\spool\DRIVERS\W32X86\3\CUTEPDFW.BPD
binary
MD5: df331c25eaf9ba82bea7246547f7a4a5
SHA256: 0ef816ca889f3c8ccde11b4986085cfeb88f0a800702cf92cf65c2ec922e3d30
3840
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\favicon[1].ico
image
MD5: a68ef3a5fc089796c7275b46a3d5aa68
SHA256: b24e29cdc992531db2213e85f200e2e659eb78b0c91bff9c657269df7992b907
1204
spoolsv.exe
C:\Windows\system32\spool\DRIVERS\W32X86\3\PSCRIPT.HLP
hlp
MD5: 02c3f8c32018f3aaf66e7421400f1781
SHA256: 6faef4c998e810fff139958f28722c79879ec2fd66c97c7e3e2c5040fd5550d9
1204
spoolsv.exe
C:\Windows\system32\spool\DRIVERS\W32X86\3\PSCRIPT.NTF
ntf
MD5: acd06ccd864e483846b624642a0114b3
SHA256: c19d4922df0298d693f08d67557d48c1de14ebfaba6bad2cd69b1b4ddd5f0b82
1204
spoolsv.exe
C:\Windows\system32\spool\DRIVERS\W32X86\3\CUTEPDFW.PPD
text
MD5: 4c4c993507312e1d744eaf74c878ba1d
SHA256: 454216087aca9c7a3326bb247b84c782281c5e71ae43ee8a977a480b0fa4ed25
1204
spoolsv.exe
C:\Windows\system32\spool\DRIVERS\W32X86\3\New\PSCRIPT.NTF
––
MD5:  ––
SHA256:  ––
1204
spoolsv.exe
C:\Windows\system32\spool\DRIVERS\W32X86\3\New\CUTEPDFW.PPD
––
MD5:  ––
SHA256:  ––
1204
spoolsv.exe
C:\Windows\system32\spool\DRIVERS\W32X86\3\New\PSCRIPT.HLP
––
MD5:  ––
SHA256:  ––
3840
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\footbg[1].gif
image
MD5: 2dbf707eae24c8bfc799a6c59b1af0a7
SHA256: 2486d3ec361bda5b6565c6860784c66e5dc6ca09c7f9c7c48b3af970f489efc1
3840
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\Security[1].png
image
MD5: f00fb8d963212bea8d5fcaa9b618c690
SHA256: 52ea398a3d12cd4be21f7499093eb973b316b8b9d109abb9470e5ac665759b71
1204
spoolsv.exe
C:\Windows\system32\spool\DRIVERS\W32X86\3\New\PS5UI.DLL
––
MD5:  ––
SHA256:  ––
1204
spoolsv.exe
C:\Windows\system32\spool\DRIVERS\W32X86\3\New\PSCRIPT5.DLL
––
MD5:  ––
SHA256:  ––
1932
Setup.exe
C:\Windows\system32\spool\DRIVERS\W32X86\PSCRIPT.NTF
ntf
MD5: acd06ccd864e483846b624642a0114b3
SHA256: c19d4922df0298d693f08d67557d48c1de14ebfaba6bad2cd69b1b4ddd5f0b82
3840
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\DocProp[1].png
image
MD5: b1cf0a0668c0d09c3ec78b161e964464
SHA256: e5d09079353bdb2f3d4b06cd6f8b0c8b9e14db7190e897ea83502ecc1f78d727
3840
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\background[1].jpg
image
MD5: c39a0df9b68e1f723b3927bf8dc25939
SHA256: 7832b2b1b0be70d22a1de6b8613bddb9ab78c05fc00ec48ee56f824cc53b9157
1932
Setup.exe
C:\Windows\system32\spool\DRIVERS\W32X86\PSCRIPT.HLP
hlp
MD5: 02c3f8c32018f3aaf66e7421400f1781
SHA256: 6faef4c998e810fff139958f28722c79879ec2fd66c97c7e3e2c5040fd5550d9
1932
Setup.exe
C:\Windows\system32\spool\DRIVERS\W32X86\CUTEPDFW.PPD
text
MD5: 4c4c993507312e1d744eaf74c878ba1d
SHA256: 454216087aca9c7a3326bb247b84c782281c5e71ae43ee8a977a480b0fa4ed25
3840
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\companybm[1].gif
image
MD5: d86b0e72ef2a847dd9ca8d8e9bde9077
SHA256: c2d2d895c8246de24cce3bd6c4d029237a8756461a4d0895126ded1e27252887
3840
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\Print[1].gif
image
MD5: 626fed0626c307193691208b3ac7287c
SHA256: f25b8fe2669b4f5f388609d13e26852c2d99cec66d57b786da8c3900c6c2c8c2
1932
Setup.exe
C:\Program Files\CutePDF Writer\PDFWrite.rsp
text
MD5: fef862eb25dfdc61a328b941960629ee
SHA256: c21b6fc73a4d92ee282c927699b892a8d7207ac1c78475a530c1d1e4264940d6
1932
Setup.exe
C:\Program Files\CutePDF Writer\CPWSave.exe.manifest
xml
MD5: d8385d9758b759942365b1acc0e414fe
SHA256: 278bcf994bfbd8c625e1fcc67610280200908ba984dc6c99df5ebaf379754491
1932
Setup.exe
C:\Program Files\CutePDF Writer\CuteEdit.ico
image
MD5: a68ef3a5fc089796c7275b46a3d5aa68
SHA256: b24e29cdc992531db2213e85f200e2e659eb78b0c91bff9c657269df7992b907
3840
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\Save[1].png
image
MD5: dd48b22ebfc9bb6fe9ae16008afbe90c
SHA256: 61bd73fe74b8a136aecf3a52942342fe894afc93535774966fbd83c80159f3fa
1932
Setup.exe
C:\Program Files\CutePDF Writer\setup.ini
text
MD5: 98d4f595778e7fd9c0d0fd54e4be16a1
SHA256: cc7146a7dde8bdaf039607dd230627d3b95dcae75fe8222315b7da02f1e1c11e
3840
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\NEW[1].gif
image
MD5: c123a1142cd0e858531455f7119ac623
SHA256: 3f7923e3b28cd8f2507d56c7688e47219c82971e985fd5c340ba7bae372902bd
1932
Setup.exe
C:\Program Files\CutePDF Writer\setup.inf
binary
MD5: 67035d9c58c47711636b51dd93446fdb
SHA256: 1e34d78c2bf339a20867107244bdc5ebc36dff14a36bb4abac133f89a41ac602
3840
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\htabs1[1].gif
image
MD5: ad8d58521af2afd68d9060e1a368cc69
SHA256: 8667633125d3b6dbabbf9543340a292f0553a9862617dee161c130e86a8cbf26
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\WizModernSmallImage-IS.bmp
image
MD5: b747dc945b4672f955db5f55ca163765
SHA256: f6731fda2d388389d74de9a5961b6175edc091f9dfd755d6d6c402621c5e1279
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\is-I3NKD.tmp
––
MD5:  ––
SHA256:  ––
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\Driver\x64\is-UIHDU.tmp
––
MD5:  ––
SHA256:  ––
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\Driver\x64\PSCRIPT.NTF
ntf
MD5: c18e8da3f5c91760e00dfae8b6364bed
SHA256: f49c950531e485bbc4b35161cf049adf8363d0bd222cfed2eede2a13fe418187
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\Driver\x64\is-AVOOA.tmp
––
MD5:  ––
SHA256:  ––
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\Driver\x64\PSCRIPT.HLP
hlp
MD5: 02c3f8c32018f3aaf66e7421400f1781
SHA256: 6faef4c998e810fff139958f28722c79879ec2fd66c97c7e3e2c5040fd5550d9
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\Driver\x64\is-NKIL1.tmp
––
MD5:  ––
SHA256:  ––
3840
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\htabs3[1].gif
image
MD5: eab4b7c1964754bfa854d2f251e6b239
SHA256: 3ba1f37896e4b76f1f65d6d0de9f0875a9a13e87dc9e78d086afdacf608bd91e
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\Driver\x64\is-D0BOD.tmp
––
MD5:  ––
SHA256:  ––
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\Driver\TESTPS.TXT
binary
MD5: 667bdcf7167048569d0fe44060de3574
SHA256: ebcea08c1ef7e6146ad74fec109e682e5c12a99e45c9d6e5f9b43a2309f7a0b2
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\Driver\is-V48TO.tmp
––
MD5:  ––
SHA256:  ––
3840
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\companybg[1].jpg
image
MD5: 5691522deb7e6a2895188461693923f4
SHA256: a64b147c4ecf574a27dda4aac8141d28be50801668f32bf933a5170774560878
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\Driver\is-EGKHL.tmp
––
MD5:  ––
SHA256:  ––
3840
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\PDF_Editor[1].gif
image
MD5: 67fbc3737fca56e812f1b0578fbf89af
SHA256: 51b3f4baaa34b9d033743b4a09a626af56ab475782a45c66f29c8190f7bde8c7
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\Driver\is-5DMDT.tmp
––
MD5:  ––
SHA256:  ––
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\Driver\PSCRIPT.NTF
ntf
MD5: acd06ccd864e483846b624642a0114b3
SHA256: c19d4922df0298d693f08d67557d48c1de14ebfaba6bad2cd69b1b4ddd5f0b82
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\Driver\is-9RC56.tmp
––
MD5:  ––
SHA256:  ––
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\Driver\PSCRIPT.INI
text
MD5: 7e7ff4e86258ed8360218db6445f5b74
SHA256: 24504b2ad45c5e7f845cba1d90d6331311e51862c2b515a61f1301de0c467805
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\Driver\is-3PPIG.tmp
––
MD5:  ––
SHA256:  ––
3840
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\PrintDialogBox[1].gif
image
MD5: 4a9ee6787cba9fc64927ef4a75c172ec
SHA256: ee172f27571e2e184509331861c167a80016b95e7e9229d3606a8d7e999d870f
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\Driver\PSCRIPT.HLP
hlp
MD5: 02c3f8c32018f3aaf66e7421400f1781
SHA256: 6faef4c998e810fff139958f28722c79879ec2fd66c97c7e3e2c5040fd5550d9
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\Driver\is-LCM2D.tmp
––
MD5:  ––
SHA256:  ––
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\Driver\is-A7U1R.tmp
––
MD5:  ––
SHA256:  ––
3840
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\headerbg[1].gif
image
MD5: 44861eedc752a076f749f95dc8502a85
SHA256: f5eee58dc54d8fe9db5b64589df985d74981233fa0282e0d9a93d8c7e4bb2a6a
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\Driver\is-OOA0V.tmp
––
MD5:  ––
SHA256:  ––
3840
iexplore.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][1].txt
text
MD5: edf288711ef1011af6b88ea2fa83c253
SHA256: caca0c07c48b654d8380dce3c0f0948fb06aa2299adb5e383863384e1f1b65f4
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\Driver\CUTEPDFW.PPD
text
MD5: 4c4c993507312e1d744eaf74c878ba1d
SHA256: 454216087aca9c7a3326bb247b84c782281c5e71ae43ee8a977a480b0fa4ed25
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\Driver\Cutepdfw.spd
text
MD5: 97be5b2a50b2089bdea807a819367160
SHA256: 40fca15e1c3556cdbea32079dd67a26da4c9e0ab0d824de6b50c719cd3bd101e
3840
iexplore.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\[email protected][2].txt
––
MD5:  ––
SHA256:  ––
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\Driver\FONTS.MFM
binary
MD5: 0429bc080c0571eb67c958df9b46932d
SHA256: 4e8fa2d66eca983f0e14c9338e6f81a06998a490c865d96abe6616f12fe68296
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\Driver\is-0UODF.tmp
––
MD5:  ––
SHA256:  ––
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\Driver\is-7E6AQ.tmp
––
MD5:  ––
SHA256:  ––
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\Driver\is-B9G44.tmp
––
MD5:  ––
SHA256:  ––
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\Driver\is-P7UM1.tmp
––
MD5:  ––
SHA256:  ––
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\setup_svr.ini
text
MD5: c442f0dc65635ad58f399894ef9d92ca
SHA256: 78254629fe90c549b6e7b8901eb67d7a738ca6b57ba84656a3c00f0c088ce3be
3840
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\space[1].gif
image
MD5: fc94fb0c3ed8a8f909dbc7630a0987ff
SHA256: 2dfe28cbdb83f01c940de6a88ab86200154fd772d568035ac568664e52068363
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\setup.ini
text
MD5: 98d4f595778e7fd9c0d0fd54e4be16a1
SHA256: cc7146a7dde8bdaf039607dd230627d3b95dcae75fe8222315b7da02f1e1c11e
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\is-G3S3S.tmp
––
MD5:  ––
SHA256:  ––
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\is-A2RF3.tmp
––
MD5:  ––
SHA256:  ––
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\is-2BLRV.tmp
––
MD5:  ––
SHA256:  ––
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\is-FATIJ.tmp
––
MD5:  ––
SHA256:  ––
3840
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\analytics[1].js
text
MD5: b66b3b5d54e154c81a50880cdcd7e5f8
SHA256: dbb67c620eaabf6679a314db18d3ae43037aef71ab27422e6feec08ee987cc0a
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\Setup.inf
binary
MD5: 67035d9c58c47711636b51dd93446fdb
SHA256: 1e34d78c2bf339a20867107244bdc5ebc36dff14a36bb4abac133f89a41ac602
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\is-5C6UV.tmp
––
MD5:  ––
SHA256:  ––
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\is-AKQNG.tmp
––
MD5:  ––
SHA256:  ––
3840
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\DOMStore\JMJ84TMO\www.cutepdf-editor[1].xml
text
MD5: a544637391c324b369fda020b6ddc539
SHA256: 9a134f0d8c3726ee89ecd9c13d50b11ab8f81ef60ad9e2de2c84fe1048867b46
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\PDFWrite.rsp
text
MD5: fef862eb25dfdc61a328b941960629ee
SHA256: c21b6fc73a4d92ee282c927699b892a8d7207ac1c78475a530c1d1e4264940d6
3840
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\DOMStore\index.dat
dat
MD5: 3cb290e1a71fcf3b963a5f4959af290c
SHA256: a0dc273867b3f16fbf796bf70cb03190c7ced481bbdc61345b0846145564324b
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\is-DSL4L.tmp
––
MD5:  ––
SHA256:  ––
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\is-3568U.tmp
––
MD5:  ––
SHA256:  ––
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\is-JNGS2.tmp
––
MD5:  ––
SHA256:  ––
3840
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\f[1].txt
text
MD5: 677f95c2ae6d629979a89cfd5ea76aad
SHA256: afbfcaff971a7d778697daebe38e51adc752c0f1705473bff4fa342ff1fec1ba
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\is-OCQGA.tmp
––
MD5:  ––
SHA256:  ––
3840
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\js[1]
text
MD5: bda054f637d431196852e83ecd179905
SHA256: 7f1346bcbc6adba45f80aeb0d241f375d09d9c30586931eee40024290a5a9c04
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\CPWSave.exe.manifest
xml
MD5: d8385d9758b759942365b1acc0e414fe
SHA256: 278bcf994bfbd8c625e1fcc67610280200908ba984dc6c99df5ebaf379754491
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\CuteEdit.ico
image
MD5: a68ef3a5fc089796c7275b46a3d5aa68
SHA256: b24e29cdc992531db2213e85f200e2e659eb78b0c91bff9c657269df7992b907
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\is-46ADE.tmp
––
MD5:  ––
SHA256:  ––
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\is-7IMFA.tmp
––
MD5:  ––
SHA256:  ––
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\is-IPHCA.tmp
––
MD5:  ––
SHA256:  ––
3840
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\main[1].css
text
MD5: 4be817709f6825ffec9d19b85a6ada52
SHA256: 635a2c8b892f5737ccc623a21a00d67510caf46dfcf160c3d7fb6069937e37ce
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\is-UT49P.tmp
––
MD5:  ––
SHA256:  ––
3840
iexplore.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\PrivacIE\index.dat
dat
MD5: f59e8d5b0ca3050ad3b3222b196ef131
SHA256: f5b9615d8054ba020fa7d2d85c1954c3d966760cfb79af9b7621e11a825c6635
2880
CuteWriter.tmp
C:\Users\admin\AppData\Local\Temp\is-CCRVT.tmp\is-0A2PH.tmp
––
MD5:  ––
SHA256:  ––
3840
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\writer[1].htm
html
MD5: 89cc96e5edd3e02c0c9cfff0ee215aff
SHA256: 7859ff2739965cb442f1c8ae7e93d3e429c1a18aacb801c4eb2b1205c1789e8b
3840
iexplore.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
binary
MD5: dc2b075bca9725fe41518ebee2d88234
SHA256: 53ce2bfe422c4013b74deb27a4402143d1b349645d7bf769a6ed12e127fce3ce
3840
iexplore.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019110820191109\index.dat
dat
MD5: 7c063e8054a32b05fae4b8ab0d2d8e87
SHA256: db9a1b3884d37cc968bf97fa23875a91c57dff9fc7670511dc02c61d51270e69

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
3
TCP/UDP connections
11
DNS requests
6
Threats
0

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
2768 iexplore.exe GET 200 13.107.21.200:80 http://www.bing.com/favicon.ico US
image
whitelisted
3840 iexplore.exe GET 200 8.253.204.249:80 http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab US
compressed
whitelisted
3840 iexplore.exe GET 200 8.253.204.249:80 http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/47BEABC922EAE80E78783462A79F45C254FDE68B.crt US
der
whitelisted

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
3840 iexplore.exe 166.62.55.163:443 GoDaddy.com, LLC US unknown
2768 iexplore.exe 13.107.21.200:80 Microsoft Corporation US whitelisted
3840 iexplore.exe 8.253.204.249:80 Global Crossing US unknown
3840 iexplore.exe 216.58.207.40:443 Google Inc. US whitelisted
3840 iexplore.exe 216.58.210.2:443 Google Inc. US whitelisted
3840 iexplore.exe 172.217.18.110:443 Google Inc. US whitelisted

DNS requests

Domain IP Reputation
www.cutepdf-editor.com 166.62.55.163
suspicious
www.bing.com 13.107.21.200
204.79.197.200
whitelisted
www.download.windowsupdate.com 8.253.204.249
67.26.73.254
67.26.139.254
8.253.95.120
8.253.95.121
whitelisted
www.googletagmanager.com 216.58.207.40
whitelisted
pagead2.googlesyndication.com 216.58.210.2
whitelisted
www.google-analytics.com 172.217.18.110
whitelisted

Threats

No threats detected.

Debug output strings

No debug info.