General Info

File name

http://wcdownloadercdn.lavasoft.com/4.5.1957.3838/WebCompanion-4.5.1957.3838-prod.zip

Full analysis
https://app.any.run/tasks/ea0f8ddc-949c-4610-bc86-4425337a3514
Verdict
Malicious activity
Analysis date
2/10/2019, 17:01:34
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/zip
File info:
Zip archive data, at least v2.0 to extract
MD5

878dd52b5fe88270689c327b67efe1fc

SHA1

0beb1b3fd892cc156ac51476607adea92db43864

SHA256

ecd3d5601df8d7e443f8169e076b6284fb261e30288246ecb2e3549f64929a89

SSDEEP

196608:cVTPgN79xT/cEYJy2R4AvpWPlFJAy5YyQPQhr5F5ZpudK:cdIN7Ti4A4ZAHQdJzf

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
120 seconds
Additional time used
60 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads dropped or rewritten executable
  • explorer.exe (PID: 116)
  • SearchProtocolHost.exe (PID: 1576)
  • WebCompanion.exe (PID: 3428)
Application was dropped or rewritten from another process
  • WebCompanion.exe (PID: 3428)
  • Ad-Aware Web Companion.exe (PID: 3140)
  • WebCompanionInstaller.exe (PID: 3796)
Creates files in the user directory
  • explorer.exe (PID: 116)
Reads Internet Cache Settings
  • explorer.exe (PID: 116)
Executable content was dropped or overwritten
  • WinRAR.exe (PID: 3736)
Creates files in the program directory
  • WebCompanion.exe (PID: 3428)
Dropped object may contain Bitcoin addresses
  • WinRAR.exe (PID: 3736)
Application was crashed
  • WebCompanionInstaller.exe (PID: 3796)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.zip
|   ZIP compressed archive (100%)
EXIF
ZIP
ZipRequiredVersion:
20
ZipBitFlag:
null
ZipCompression:
Deflated
ZipModifyDate:
2018:12:14 08:46:22
ZipCRC:
0x0a3bab5f
ZipCompressedSize:
64866
ZipUncompressedSize:
129312
ZipFileName:
Application/Ad-Aware Web Companion.exe

Screenshots

Processes

Total processes
40
Monitored processes
7
Malicious processes
5
Suspicious processes
0

Behavior graph

+
start winrar.exe searchprotocolhost.exe no specs ad-aware web companion.exe no specs webcompanion.exe webcompanioninstaller.exe dw20.exe no specs explorer.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
116
CMD
C:\Windows\Explorer.EXE
Path
C:\Windows\explorer.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Windows Explorer
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\slc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\profapi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\iconcodecservice.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sndvolsso.dll
c:\windows\system32\hid.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\timedate.cpl
c:\windows\system32\atl.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\actxprxy.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\userenv.dll
c:\windows\system32\shacct.dll
c:\windows\system32\samlib.dll
c:\windows\system32\samcli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\winanr.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\program files\winrar\winrar.exe
c:\windows\system32\msftedit.dll
c:\windows\system32\msls31.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\authui.dll
c:\windows\system32\cryptui.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\gameux.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\wer.dll
c:\windows\system32\msiltcfg.dll
c:\windows\system32\version.dll
c:\windows\system32\msi.dll
c:\windows\system32\winsta.dll
c:\windows\system32\psapi.dll
c:\windows\system32\networkexplorer.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wdmaud.drv
c:\windows\system32\ksuser.dll
c:\windows\system32\avrt.dll
c:\windows\system32\audioses.dll
c:\windows\system32\msacm32.drv
c:\windows\system32\msacm32.dll
c:\windows\system32\midimap.dll
c:\windows\system32\stobject.dll
c:\windows\system32\batmeter.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\es.dll
c:\windows\system32\prnfldr.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dxp.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\syncreg.dll
c:\windows\ehome\ehsso.dll
c:\windows\system32\netshell.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\alttab.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
c:\program files\filezilla ftp client\fzshellext.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\pnidui.dll
c:\windows\system32\qutil.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\npmproxy.dll
c:\windows\system32\wlanapi.dll
c:\windows\system32\wlanutil.dll
c:\windows\system32\wwanapi.dll
c:\windows\system32\wwapi.dll
c:\windows\system32\qagent.dll
c:\windows\system32\srchadmin.dll
c:\windows\system32\sxs.dll
c:\windows\system32\bthprops.cpl
c:\windows\system32\ieframe.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\synccenter.dll
c:\windows\system32\actioncenter.dll
c:\windows\system32\imapi2.dll
c:\windows\system32\hgcpl.dll
c:\windows\system32\provsvc.dll
c:\windows\system32\netprofm.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\fxsst.dll
c:\windows\system32\fxsapi.dll
c:\windows\system32\fxsresm.dll
c:\windows\system32\wscinterop.dll
c:\windows\system32\wscapi.dll
c:\windows\system32\wscui.cpl
c:\windows\system32\werconcpl.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\wercplsupport.dll
c:\windows\system32\msxml6.dll
c:\windows\system32\hcproviders.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\mpr.dll
c:\windows\system32\drprov.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\thumbcache.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\zipfldr.dll
c:\windows\system32\mlang.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\webcompanioninstaller.exe
c:\windows\system32\imageres.dll
c:\windows\system32\structuredquery.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\audiodev.dll
c:\windows\system32\wmvcore.dll
c:\windows\system32\wmasf.dll
c:\windows\system32\ehstorapi.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\ad-aware web companion.exe
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\lavasoft.wcassistant.winservice.exe
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\webcompanion.exe
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\webcompanion.loader.exe
c:\windows\system32\photometadatahandler.dll
c:\windows\microsoft.net\framework\v2.0.50727\dw20.exe
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\ucrtbased.dll

PID
1576
CMD
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe6_ Global\UsGthrCtrlFltPipeMssGthrPipe6 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
Path
C:\Windows\System32\SearchProtocolHost.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft Windows Search Protocol Host
Version
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\tquery.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msshooks.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\msidle.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\mssph.dll
c:\windows\system32\mapi32.dll
c:\windows\system32\authz.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shell32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\propsys.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\windows\system32\version.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\vcruntime140d.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\zh-hans\webcompanion.resources.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\zh-chs\webcompanioninstaller.resources.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\x86\sqlite.interop.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\tr-tr\webcompanioninstaller.resources.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\tr-tr\webcompanion.resources.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\ru-ru\webcompanioninstaller.resources.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\ru-ru\webcompanion.resources.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\pt-br\webcompanioninstaller.resources.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\pt-br\webcompanion.resources.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\ja-jp\webcompanioninstaller.resources.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\ja-jp\webcompanion.resources.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\it-it\webcompanioninstaller.resources.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\it-it\webcompanion.resources.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\fr-ca\webcompanioninstaller.resources.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\fr-ca\webcompanion.resources.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\es-es\webcompanioninstaller.resources.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\es-es\webcompanion.resources.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\en-us\webcompanioninstaller.resources.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\en-us\webcompanion.resources.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\de-de\webcompanioninstaller.resources.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\de-de\webcompanion.resources.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\webcompanioninstaller.exe
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\webcompanionextensionie.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\webcompanion.loader.exe
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\webcompanion.exe
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\ucrtbased.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\system.data.sqlite.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\newtonsoft.json.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\mozcompressor.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\microsoft.mshtml.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\lz4.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\log4net.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\liblz4.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\lavasoft.wcassistant.winservice.exe
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\lavasoft.wcassistant.wcfservice.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\lavasoft.wcassistant.service.logger.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\lavasoft.utils.sqllite.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\lavasoft.utils.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\lavasoft.sysinfo.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\lavasoft.settings.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\lavasoft.searchprotect.repositories.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\lavasoft.searchprotect.business.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\lavasoft.omni.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\lavasoft.iecontroller.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\lavasoft.events.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\lavasoft.csharp.utilities.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\lavasoft.compression.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\lavasoft.automation.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\lavasoft.appcore.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\lavasoft.adblocker.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\interop.shell32.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\interop.shdocvw.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\interop.lavasofttcpservicelib.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\interop.iwshruntimelibrary.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\icsharpcode.sharpziplib.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\esent.interop.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\dotnetzip.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\bcusdk.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\bcuengines.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\ad-aware web companion.exe
c:\windows\system32\netutils.dll

PID
3736
CMD
"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod.zip"
Path
C:\Program Files\WinRAR\WinRAR.exe
Indicators
Parent process
explorer.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Alexander Roshal
Description
WinRAR archiver
Version
5.60.0
Modules
Image
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\uxtheme.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\riched20.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\mpr.dll
c:\windows\system32\drprov.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\winmm.dll
c:\windows\system32\portabledeviceapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\audiodev.dll
c:\windows\system32\wmvcore.dll
c:\windows\system32\wmasf.dll
c:\windows\system32\ehstorapi.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll

PID
3140
CMD
"C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\Ad-Aware Web Companion.exe"
Path
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\Ad-Aware Web Companion.exe
Indicators
No indicators
Parent process
explorer.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Description
Ad-Aware Web Companion.exe
Version
4.5.1957.3838
Modules
Image
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\ad-aware web companion.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\shell32.dll
c:\windows\system32\iertutil.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\version.dll

PID
3428
CMD
"C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\WebCompanion.exe"
Path
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\WebCompanion.exe
Indicators
Parent process
explorer.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Lavasoft
Description
Web Companion
Version
4.5.1957.3838
Modules
Image
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\webcompanion.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\profapi.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorsec.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\riched20.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\userenv.dll
c:\windows\system32\gpapi.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system\9e0a3b9b9f457233a335d7fba8f95419\system.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\windowsbase\cf293040f3a93afa1ea782487acae816\windowsbase.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\presentationcore\2ad23de8284d4594aa658dfb5e667d97\presentationcore.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\presentationframewo#\bfaf8f86e69928fb2f67987c0203f603\presentationframework.ni.dll
c:\windows\assembly\gac_32\presentationcore\3.0.0.0__31bf3856ad364e35\presentationcore.dll
c:\windows\microsoft.net\framework\v3.0\wpf\wpfgfx_v0300.dll
c:\windows\system32\oleaut32.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\log4net.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.core\fbc05b5b05dc6366b02b8e2f77d080f1\system.core.ni.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorjit.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\lavasoft.appcore.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.configuration\bc09ad2d49d8535371845cd7532f9271\system.configuration.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.xml\461d3b6b3f43e6fbe6c897d5936e17e4\system.xml.ni.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\lavasoft.utils.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.drawing\dbfe8642a8ed7b2b103ad28e0c96418a\system.drawing.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.windows.forms\3afcd5168c7a6cb02eab99d7fd71e102\system.windows.forms.ni.dll
c:\windows\microsoft.net\framework\v2.0.50727\diasymreader.dll
c:\windows\system32\shfolder.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\lavasoft.searchprotect.business.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\newtonsoft.json.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.servicemodel\e2642bff810609f64343e53dddb6b59c\system.servicemodel.ni.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.componentmod#\221fa10bd3cb407e43b7476af5039090\system.componentmodel.dataannotations.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.runtime.seri#\4a984a9ad59d14063bc6ae64a0c8f62a\system.runtime.serialization.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.xml.linq\70aac9dff3bdde548962557151c1ff49\system.xml.linq.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.data\1e85062785e286cd9eae9c26d2c61f73\system.data.ni.dll
c:\windows\assembly\gac_32\system.data\2.0.0.0__b77a5c561934e089\system.data.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\interop.lavasofttcpservicelib.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\icsharpcode.sharpziplib.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\lavasoft.events.dll

PID
3796
CMD
"C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\WebCompanionInstaller.exe"
Path
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\WebCompanionInstaller.exe
Indicators
Parent process
explorer.exe
User
admin
Integrity Level
MEDIUM
Exit code
3762507597
Version:
Company
Lavasoft
Description
Web Companion
Version
4.5.1957.3838
Modules
Image
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\webcompanioninstaller.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\profapi.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorsec.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\riched20.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\userenv.dll
c:\windows\system32\gpapi.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system\9e0a3b9b9f457233a335d7fba8f95419\system.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\windowsbase\cf293040f3a93afa1ea782487acae816\windowsbase.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\presentationcore\2ad23de8284d4594aa658dfb5e667d97\presentationcore.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\presentationframewo#\bfaf8f86e69928fb2f67987c0203f603\presentationframework.ni.dll
c:\windows\assembly\gac_32\presentationcore\3.0.0.0__31bf3856ad364e35\presentationcore.dll
c:\windows\microsoft.net\framework\v3.0\wpf\wpfgfx_v0300.dll
c:\windows\system32\oleaut32.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.core\fbc05b5b05dc6366b02b8e2f77d080f1\system.core.ni.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorjit.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.configuration\bc09ad2d49d8535371845cd7532f9271\system.configuration.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.xml\461d3b6b3f43e6fbe6c897d5936e17e4\system.xml.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.servicemodel\e2642bff810609f64343e53dddb6b59c\system.servicemodel.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.servicemodel#\4782a5d2bc7d86895faf404a3470aacb\system.servicemodel.web.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\smdiagnostics\8218dc4808b77f3585fb048c61597af1\smdiagnostics.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.web\da5da08245467818759aa44c4eb948e1\system.web.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.runtime.seri#\4a984a9ad59d14063bc6ae64a0c8f62a\system.runtime.serialization.ni.dll
c:\windows\system32\httpapi.dll
c:\windows\system32\pcwum.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\microsoft.net\framework\v2.0.50727\diasymreader.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.management\6f3b99ed0b791ff4d8aa52f2f0cd0bcf\system.management.ni.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wmiutils.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\microsoft.net\framework\v2.0.50727\wminet_utils.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\apphelp.dll
c:\windows\microsoft.net\framework\v2.0.50727\dw20.exe
c:\windows\microsoft.net\framework\v2.0.50727\culture.dll

PID
3360
CMD
dw20.exe -x -s 2004
Path
C:\Windows\Microsoft.NET\Framework\v2.0.50727\dw20.exe
Indicators
No indicators
Parent process
WebCompanionInstaller.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft .NET Error Reporting Shim
Version
2.0.50727.4927 (NetFXspW7.050727-4900)
Modules
Image
c:\windows\microsoft.net\framework\v2.0.50727\dw20.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\version.dll
c:\windows\system32\psapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\wer.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\werui.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dui70.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\duser.dll
c:\windows\system32\riched20.dll
c:\windows\system32\shell32.dll
c:\users\admin\desktop\webcompanion-4.5.1957.3838-prod\webcompanioninstaller.exe
c:\windows\system32\uxtheme.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll

Registry activity

Total events
3009
Read events
2826
Write events
181
Delete events
2

Modification events

PID
Process
Operation
Key
Name
Value
116
explorer.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018082720180903
116
explorer.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018090920180910
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.zip\OpenWithList
a
WinRAR.exe
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.zip\OpenWithList
MRUList
a
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.zip\OpenWithProgids
WinRAR.ZIP
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
3
57006500620043006F006D00700061006E0069006F006E002D0034002E0035002E0031003900350037002E0033003800330038002D00700072006F0064002E007A00690070000000B200320000000000000000000000576562436F6D70616E696F6E2D342E352E313935372E333833382D70726F642E7A69702E6C6E6B007C0008000400EFBE00000000000000002A0000000000000000000000000000000000000000000000000057006500620043006F006D00700061006E0069006F006E002D0034002E0035002E0031003900350037002E0033003800330038002D00700072006F0064002E007A00690070002E006C006E006B00000036000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.zip
0
57006500620043006F006D00700061006E0069006F006E002D0034002E0035002E0031003900350037002E0033003800330038002D00700072006F0064002E007A00690070000000B200320000000000000000000000576562436F6D70616E696F6E2D342E352E313935372E333833382D70726F642E7A69702E6C6E6B007C0008000400EFBE00000000000000002A0000000000000000000000000000000000000000000000000057006500620043006F006D00700061006E0069006F006E002D0034002E0035002E0031003900350037002E0033003800330038002D00700072006F0064002E007A00690070002E006C006E006B00000036000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.zip
MRUListEx
00000000FFFFFFFF
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019021020190211
CachePath
%USERPROFILE%\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019021020190211
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019021020190211
CachePrefix
:2019021020190211:
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019021020190211
CacheLimit
8192
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019021020190211
CacheOptions
11
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019021020190211
CacheRepair
0
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs
MRUListEx
03000000000000000200000001000000FFFFFFFF
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\JvaENE\JvaENE.rkr
00000000000000000000000000000000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002E0000003D000000FA3A1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
NodeSlots
02020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
MRUListEx
0000000001000000020000000700000006000000030000000500000004000000FFFFFFFF
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\JvaENE\JvaENE.rkr
00000000000000000000000007110000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002E0000003D000000014C1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
8
88003100000000004A4E4F801000574542434F4D7E312E33383300006C0008000400EFBE4A4E4E804A4E4F802A000000F5DD000000000500000000000000000000000000000057006500620043006F006D00700061006E0069006F006E002D0034002E0035002E0031003900350037002E0033003800330038002D00700072006F00640000001C000000
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
MRUListEx
080000000000000001000000020000000700000006000000030000000500000004000000FFFFFFFF
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
NodeSlots
0202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\8
NodeSlot
95
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\8
MRUListEx
FFFFFFFF
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell
KnownFolderDerivedFolderType
{57807898-8C4F-4462-BB63-71042380B109}
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar
Locked
1
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell
SniffedFolderType
Generic
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell
NavBar
000000000000000000000000000000008B000000870000003153505305D5CDD59C2E1B10939708002B2CF9AE6B0000005A000000007B00360044003800420042003300440033002D0039004400380037002D0034004100390031002D0041004200350036002D003400460033003000430046004600450046004500390046007D005F0057006900640074006800000013000000F00000000000000000000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.exe\OpenWithProgids
exefile
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\Qrfxgbc\JroPbzcnavba-4.5.1957.3838-cebq\Nq-Njner Jro Pbzcnavba.rkr
00000000010000000000000000000000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF503DAD0A5AC1D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000003D000000014C1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\Qrfxgbc\JroPbzcnavba-4.5.1957.3838-cebq\JroPbzcnavba.rkr
00000000010000000000000000000000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFFF09FEF155AC1D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
00000000300000003D000000014C1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\rkcybere.rkr
0000000006000000090000000F3E0400000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF6012F7D45C48D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
00000000300000003D00000068B01500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\Qrfxgbc\JroPbzcnavba-4.5.1957.3838-cebq\JroPbzcnavba.rkr
000000000100000000000000BC1A0000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFFF09FEF155AC1D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
00000000300000003D00000024CB1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\rkcybere.rkr
00000000060000000A0000000F3E0400000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF6012F7D45C48D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
00000000300000003E00000024CB1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\Qrfxgbc\JroPbzcnavba-4.5.1957.3838-cebq\JroPbzcnavbaVafgnyyre.rkr
00000000010000000000000000000000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFFF0B979215AC1D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
00000000310000003E00000024CB1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
{A38B883C-1682-497E-97B0-0A3A9E801682} {886D8EEB-8CF2-4446-8D02-CDBA1DBDCF99} 0xFFFF
0100000000000000C23016235AC1D401
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\rkcybere.rkr
00000000060000000A000000DC770400000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF6012F7D45C48D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
00000000310000003E000000F1041600090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\rkcybere.rkr
00000000060000000B000000DC770400000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF6012F7D45C48D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
00000000310000003F000000F1041600090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702060000000B000000DC7704007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000005C004400650073006B0074006F0070005C0057006500620043006F006D00700061006E0069006F006E002D0034002E0035002E0031003900350037002E0033003800330038002D00700072006F0064005C0057006500620043006F006D00700061006E0069006F006E002E006500780065000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000036F60A770FB925750200C40AD8EA3702000000000000000000000000800000008000C40A00000000FCE837020000000088E93702EDE00677174C1800FEFFFFFF36F60A7744FA0A77010000008000C40A8000C40A207312770000000098E937025A140B77207312774A140B7736F60A7793B92575FCE93702D8EA37020000C40A1E00000011000000B8457800B045780000000000FCE900002251A06B00EA00002A51A06BB4E937028291F07500EA3702B8E937022795F075000000005459EE02E0E93702CD94F0755459EE02C854EE0284EA3702E194F07500000000C854EE0284EA3702E8E93702
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\Zvpebfbsg.ARG\Senzrjbex\i2.0.50727\qj20.rkr
000000000000000000000000C6130000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
00000000310000003F000000B7181600090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702060000000B000000DC7704007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000005C004400650073006B0074006F0070005C0057006500620043006F006D00700061006E0069006F006E002D0034002E0035002E0031003900350037002E0033003800330038002D00700072006F0064005C0057006500620043006F006D00700061006E0069006F006E002E006500780065000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000036F60A770FB925750200C40AD8EA3702000000000000000000000000800000008000C40A00000000FCE837020000000088E93702EDE00677174C1800FEFFFFFF36F60A7744FA0A77010000008000C40A8000C40A207312770000000098E937025A140B77207312774A140B7736F60A7793B92575FCE93702D8EA37020000C40A1E00000011000000B8457800B045780000000000FCE900002251A06B00EA00002A51A06BB4E937028291F07500EA3702B8E937022795F075000000005459EE02E0E93702CD94F0755459EE02C854EE0284EA3702E194F07500000000C854EE0284EA3702E8E93702
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\Zvpebfbsg.ARG\Senzrjbex\i2.0.50727\qj20.rkr
000000000000000001000000C6130000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000003100000040000000B7181600090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702060000000B000000DC7704007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000005C004400650073006B0074006F0070005C0057006500620043006F006D00700061006E0069006F006E002D0034002E0035002E0031003900350037002E0033003800330038002D00700072006F0064005C0057006500620043006F006D00700061006E0069006F006E002E006500780065000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000036F60A770FB925750200C40AD8EA3702000000000000000000000000800000008000C40A00000000FCE837020000000088E93702EDE00677174C1800FEFFFFFF36F60A7744FA0A77010000008000C40A8000C40A207312770000000098E937025A140B77207312774A140B7736F60A7793B92575FCE93702D8EA37020000C40A1E00000011000000B8457800B045780000000000FCE900002251A06B00EA00002A51A06BB4E937028291F07500EA3702B8E937022795F075000000005459EE02E0E93702CD94F0755459EE02C854EE0284EA3702E194F07500000000C854EE0284EA3702E8E93702
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\rkcybere.rkr
00000000060000000B00000098780400000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF6012F7D45C48D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
00000000310000004000000073191600090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702060000000B000000987804007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000002E004E00450054005C004600720061006D00650077006F0072006B005C00760032002E0030002E00350030003700320037005C0064007700320030002E00650078006500000033003800330038002D00700072006F0064005C0057006500620043006F006D00700061006E0069006F006E002E006500780065000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000036F60A770FB925750200C40AD8EA3702000000000000000000000000800000008000C40A00000000FCE837020000000088E93702EDE00677174C1800FEFFFFFF36F60A7744FA0A77010000008000C40A8000C40A207312770000000098E937025A140B77207312774A140B7736F60A7793B92575FCE93702D8EA37020000C40A1E00000011000000B8457800B045780000000000FCE900002251A06BACE937028291F075FCE93702B0E937022795F075000000005459EE02D8E93702CD94F0755459EE0284EA3702C854EE02E194F07500000000C854EE0284EA3702E0E93702
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dll\OpenWithProgids
dllfile
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\Zvpebfbsg.ARG\Senzrjbex\i2.0.50727\qj20.rkr
000000000000000001000000C6200000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
00000000310000004000000073261600090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702060000000B000000987804007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000002E004E00450054005C004600720061006D00650077006F0072006B005C00760032002E0030002E00350030003700320037005C0064007700320030002E00650078006500000033003800330038002D00700072006F0064005C0057006500620043006F006D00700061006E0069006F006E002E006500780065000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000036F60A770FB925750200C40AD8EA3702000000000000000000000000800000008000C40A00000000FCE837020000000088E93702EDE00677174C1800FEFFFFFF36F60A7744FA0A77010000008000C40A8000C40A207312770000000098E937025A140B77207312774A140B7736F60A7793B92575FCE93702D8EA37020000C40A1E00000011000000B8457800B045780000000000FCE900002251A06BACE937028291F075FCE93702B0E937022795F075000000005459EE02D8E93702CD94F0755459EE0284EA3702C854EE02E194F07500000000C854EE0284EA3702E0E93702
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\rkcybere.rkr
00000000060000000C00000098780400000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF6012F7D45C48D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
00000000310000004100000073261600090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702060000000C000000987804007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C004D006900630072006F0073006F00660074002E004E00450054005C004600720061006D00650077006F0072006B005C00760032002E0030002E00350030003700320037005C0064007700320030002E0065007800650000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000036F60A770FB925750200C40AD8EA3702000000000000000000000000800000008000C40A00000000FCE837020000000088E93702EDE00677174C1800FEFFFFFF36F60A7744FA0A77010000008000C40A8000C40A207312770000000098E937025A140B77207312774A140B7736F60A7793B92575FCE93702D8EA37020000C40A1E00000011000000B8457800B045780000000000FCE900002251A06B00EA00002A51A06BB4E937028291F07500EA3702B8E937022795F075000000005459EE02E0E93702CD94F0755459EE02C854EE0284EA3702E194F07500000000C854EE0284EA3702E8E93702
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell
MinPos1280x720x96(1).x
4294967295
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell
MinPos1280x720x96(1).y
4294967295
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell
MaxPos1280x720x96(1).x
4294967295
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell
MaxPos1280x720x96(1).y
4294967295
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell
WinPos1280x720x96(1).left
22
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell
WinPos1280x720x96(1).top
22
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell
WinPos1280x720x96(1).right
822
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell
WinPos1280x720x96(1).bottom
582
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell
WFlags
2
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell
ShowCmd
3
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell
HotKey
0
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Rev
0
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
1092616193
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Vid
{137E7700-3573-11CF-AE69-08002B2E1262}
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\rkcybere.rkr
00000000060000000C000000CFD70400000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF6012F7D45C48D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000003100000041000000AA851600090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702060000000C000000CFD704007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000005C004600720061006D00650077006F0072006B005C00760032002E0030002E00350030003700320037005C0064007700320030002E0065007800650000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000036F60A770FB925750200C40AD8EA3702000000000000000000000000800000008000C40A00000000FCE837020000000088E93702EDE00677174C1800FEFFFFFF36F60A7744FA0A77010000008000C40A8000C40A207312770000000098E937025A140B77207312774A140B7736F60A7793B92575FCE93702D8EA37020000C40A1E00000011000000B8457800B045780000000000FCE900002251A06B00EA00002A51A06BB4E937028291F07500EA3702545900000651A06BC8E93702B69CF0755859EE024C060000E0E93702C854EE02ECE9370211000000B8457800B0457800E0E93702E854EE0250EA00005E51A06B00EA37028291F07550EA370204EA37022795F075000000005459EE022CEA3702CD94F0755459EE02D8EA3702C854EE02E194F07500000000C854EE02D8EA370234EA3702
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\JvaENE\JvaENE.rkr
00000000000000000100000007110000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000003100000042000000AA851600090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702060000000C000000CFD704007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000005C004600720061006D00650077006F0072006B005C00760032002E0030002E00350030003700320037005C0064007700320030002E0065007800650000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000036F60A770FB925750200C40AD8EA3702000000000000000000000000800000008000C40A00000000FCE837020000000088E93702EDE00677174C1800FEFFFFFF36F60A7744FA0A77010000008000C40A8000C40A207312770000000098E937025A140B77207312774A140B7736F60A7793B92575FCE93702D8EA37020000C40A1E00000011000000B8457800B045780000000000FCE900002251A06B00EA00002A51A06BB4E937028291F07500EA3702545900000651A06BC8E93702B69CF0755859EE024C060000E0E93702C854EE02ECE9370211000000B8457800B0457800E0E93702E854EE0250EA00005E51A06B00EA37028291F07550EA370204EA37022795F075000000005459EE022CEA3702CD94F0755459EE02D8EA3702C854EE02E194F07500000000C854EE02D8EA370234EA3702
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Mode
4
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
LogicalViewMode
1
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
1092616209
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
IconSize
16
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
ColInfo
00000000000000000000000000000000FDDFDFFD100000000000000000000000040000001800000030F125B7EF471A10A5F102608C9EEBAC0A0000001001000030F125B7EF471A10A5F102608C9EEBAC0E0000007800000030F125B7EF471A10A5F102608C9EEBAC040000007800000030F125B7EF471A10A5F102608C9EEBAC0C00000050000000
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Sort
000000000000000000000000000000000100000030F125B7EF471A10A5F102608C9EEBAC0A00000001000000
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupView
0
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:FMTID
{00000000-0000-0000-0000-000000000000}
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:PID
0
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByDirection
1
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Modules\GlobalSettings\ProperTreeModuleInner
ProperTreeModuleInner
94000000900000003153505305D5CDD59C2E1B10939708002B2CF9AE4100000030000000004E0061007600500061006E0065005F00530068006F0077004C00690062007200610072007900500061006E00650000000B000000FFFF00003300000022000000004E0061007600500061006E0065005F0046006900720073007400520075006E0000000B000000000000000000000000000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Modules\NavPane
ExpandedState
06000000160014001F8080A63C324DC29940B94D446DD2D7249E0000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000160014001F4225481E03947BC34DB131E946B44C8DD50000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000160014001F43983FFBB4EAC18D42A78AD1F5659CBA930000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D0000000000000000002000000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000160014001F580D1A2CF021BE504388B07367FC96EF3C0000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B00000000000000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000160014001F50E04FD020EA3A6910A2D808002B30309D0000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\JvaENE\JvaENE.rkr
0000000000000000010000005F2C0000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
00000000310000004200000002A11600090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702060000000C000000CFD704007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E0065007800650000005C004600720061006D00650077006F0072006B005C00760032002E0030002E00350030003700320037005C0064007700320030002E0065007800650000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000036F60A770FB925750200C40AD8EA3702000000000000000000000000800000008000C40A00000000FCE837020000000088E93702EDE00677174C1800FEFFFFFF36F60A7744FA0A77010000008000C40A8000C40A207312770000000098E937025A140B77207312774A140B7736F60A7793B92575FCE93702D8EA37020000C40A1E00000011000000B8457800B045780000000000FCE900002251A06B00EA00002A51A06BB4E937028291F07500EA3702545900000651A06BC8E93702B69CF0755859EE024C060000E0E93702C854EE02ECE9370211000000B8457800B0457800E0E93702E854EE0250EA00005E51A06B00EA37028291F07550EA370204EA37022795F075000000005459EE022CEA3702CD94F0755459EE02D8EA3702C854EE02E194F07500000000C854EE02D8EA370234EA3702
3736
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
ShellExtBMP
3736
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
ShellExtIcon
3736
WinRAR.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
3736
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
0
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod.zip
3736
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
name
120
3736
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
size
80
3736
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
type
120
3736
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
mtime
100
3736
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\DialogEditHistory\ExtrPath
0
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod
3736
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\MainWin
Placement
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF1900000088000000D90300007D020000
3736
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\General
LastFolder
C:\Users\admin\Desktop
3736
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
name
120
3736
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
size
80
3736
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
psize
80
3736
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
type
120
3736
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
mtime
100
3736
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\ArcColumnWidths
crc
70
3736
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\General\Toolbar\Layout
Band56_0
38000000730100000402000000000000D4D0C8000000000000000000000000001C0103000000000039000000B40200000000000001000000
3736
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\General\Toolbar\Layout
Band56_1
38000000730100000500000000000000D4D0C8000000000000000000000000003601010000000000160000002A0000000000000002000000
3736
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\General\Toolbar\Layout
Band56_2
38000000730100000400000000000000D4D0C800000000000000000000000000200101000000000016000000640000000000000003000000
3428
WebCompanion.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
3428
WebCompanion.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanion_RASAPI32
EnableFileTracing
0
3428
WebCompanion.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanion_RASAPI32
EnableConsoleTracing
0
3428
WebCompanion.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanion_RASAPI32
FileTracingMask
4294901760
3428
WebCompanion.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanion_RASAPI32
ConsoleTracingMask
4294901760
3428
WebCompanion.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanion_RASAPI32
MaxFileSize
1048576
3428
WebCompanion.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanion_RASAPI32
FileDirectory
%windir%\tracing
3428
WebCompanion.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanion_RASMANCS
EnableFileTracing
0
3428
WebCompanion.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanion_RASMANCS
EnableConsoleTracing
0
3428
WebCompanion.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanion_RASMANCS
FileTracingMask
4294901760
3428
WebCompanion.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanion_RASMANCS
ConsoleTracingMask
4294901760
3428
WebCompanion.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanion_RASMANCS
MaxFileSize
1048576
3428
WebCompanion.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\WebCompanion_RASMANCS
FileDirectory
%windir%\tracing
3796
WebCompanionInstaller.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US

Files activity

Executable files
62
Suspicious files
3
Text files
21
Unknown types
5

Dropped files

PID
Process
Filename
Type
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\vcruntime140d.dll
executable
MD5: 51ddcfce2543560785eaac03cc7204fc
SHA256: 971011d311d2778c1c46c0c091ccce068235197bb24ca3becd3e7ad00af9ec3d
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\Lavasoft.SearchProtect.Repositories.dll
executable
MD5: ea5df96cfe8ac13914a76abc89a1f7fb
SHA256: 06c3fb4d31cd08f22b3aff87f542a1d124f68d0c004d93d3f95f8893716735fe
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\fr-CA\WebCompanion.resources.dll
executable
MD5: 8aee156182f31631ca9d865dfcd76c5f
SHA256: ae1cc6f868f969c114bee156a9204057f496fc55d1d794c8f9098d4fcf1097ce
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\Lavasoft.IEController.dll
executable
MD5: 6169b7730d8ab21f17b9e555759a134f
SHA256: f60f4c7078f90c2bbff959f4081a6d4d5f0394023bdf1fff0ab9f0d082b55610
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\it-IT\WebCompanionInstaller.resources.dll
executable
MD5: 6744ea0600ee54552b510269436db359
SHA256: 3bb123bcb813542fef5278ac7bc156e71b6784b53912abb94d50ffccc599b6c3
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\Lavasoft.CSharp.Utilities.dll
executable
MD5: a4f1bd8c28676040198b9e7a479e4ea8
SHA256: 3673820228173c6104565eebb8f737baa965fd9ca47234b75f727b17ac39c425
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\it-IT\WebCompanion.resources.dll
executable
MD5: d0c9e6bd1271fee2105ba81527fa0bb8
SHA256: 97b6e4d190d842943e4ce5e7a355417130056f1731a5488ad6ffca398a0ce268
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\Lavasoft.Compression.dll
executable
MD5: 8d82375d08171ddc8adb89d02dceeaf0
SHA256: 647eb7bdaba5df5bfae08cc2f2440f5088a547bfae23cf25d4117bc6d7f2d2d6
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\es-ES\WebCompanionInstaller.resources.dll
executable
MD5: 489a92a44efeb8039340220242890e64
SHA256: f1623e31bd1479837e770c9048facf7771d7e5d25409de0e758c700f0194d4c6
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\Lavasoft.Automation.dll
executable
MD5: 0bb90cfa68900451292a12fb126314d8
SHA256: ae39b4543e6628acae520114cfd61cb46fff73cab78a5a348548d6eb0f4a0724
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\Lavasoft.Events.dll
executable
MD5: 0beff872855ba1bc7d18f3476e5c7666
SHA256: f705cb2f2ac5c8cfdb354bd660713c433865b26f06d5984bc197faee12cd5096
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\pt-BR\WebCompanion.resources.dll
executable
MD5: f49ceeb0796453b9d19039c667ca4014
SHA256: 9b0010f0a0f6602929c904a513feffe13cdc3d243897833317877a7074c22268
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\es-ES\WebCompanion.resources.dll
executable
MD5: 2d9d870df9aa03fe298fa2112b025b82
SHA256: bcfb514754f716c36a8d02b10f6c790195a8515a851497b640a3871d6f9dc85a
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\Lavasoft.AppCore.dll
executable
MD5: 1aa8da2640e7f6ea8f7c0cdfc5f4024e
SHA256: e08701f4919bfe54925ad7e4159a99eba8567b9ce548bdc65c2f0f8a86cd7685
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\Lavasoft.SearchProtect.Business.dll
executable
MD5: 7e11c637878d9409e007187b2d5668dd
SHA256: 114f4452a26357573e11a40416da743fdb1508e2be697cbf969c330b4c66b4f9
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\pt-BR\WebCompanionInstaller.resources.dll
executable
MD5: 3438f7a593923c56d6310c6dc4c34a2a
SHA256: 0e7c81313e227ba6c4900d09f63544e531ffd68a6e4648fca613af7aea830555
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\en-US\WebCompanionInstaller.resources.dll
executable
MD5: 22e96171bf73a677956b5dbcf83cedbd
SHA256: 04b456a18333bbee1ea097549f7b2a9cc9875344fef33fff3fcf6dc750b34985
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\Interop.Shell32.dll
executable
MD5: b1617b2566b5539f436c87d65881532f
SHA256: 6274c620af95b3c2362a20753063be3961268e1465b762c55da996fbbee5576b
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\Lavasoft.Omni.dll
executable
MD5: a09b1b4fe629a9b6d15760eb2e55e158
SHA256: 2cc9e89dcdd8be5b569f1b682a4aecf8c0bf90fb0dbcda38ccd21dd96dd884a0
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\ja-JP\WebCompanion.resources.dll
executable
MD5: b97ab52471f5976e7134887685f8e799
SHA256: ecba5e3a8b943524bcc988c933085036d9fbb8064a44ed6de3ffdc8ecff5483a
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\de-DE\WebCompanion.resources.dll
executable
MD5: 0c0690bbc7671c4592ed2e4dc0c06a53
SHA256: 1b22337094a8bdac40a02607040d19aa63855f687be25c8b2c897d66629f04ee
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\ucrtbased.dll
executable
MD5: f613b3e5cca1a96c330c24e0b36519c0
SHA256: 71d212ca650cbb35d2fd9b01fa7643cb90af9ce8957f4ece6de1ffd6fa5f5422
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\Lavasoft.Settings.dll
executable
MD5: f874ec972a6ada14bc84bea924d141a4
SHA256: 7e9050a6a989a87be3ecf55d54c7a66d9d03b87f4625009ca51a323a705221b9
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\ja-JP\WebCompanionInstaller.resources.dll
executable
MD5: 7ef9acd8e1885fb3d82ec46e8d20d6de
SHA256: 8e763ad7aef4285b18feda15fc2a7a7c4f26a7a0a153defa4db35af03aee8ed9
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\de-DE\WebCompanionInstaller.resources.dll
executable
MD5: 806f197797e112cc9f661d8d5058e62f
SHA256: 97865fdf4d2b3418839761882c1191ea4325ae025aecca86acca1f3fca53d0b5
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\Lavasoft.adblocker.dll
executable
MD5: c88591046c523d07996b10125363d5ca
SHA256: c11cb02ed0adfbb9e6c291c5e623af8e74f4dd77eabaf614e3e94f32a4c3f78f
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\Lavasoft.Utils.SqlLite.dll
executable
MD5: e2a10b48a1f60040d92f205e7ec99c1f
SHA256: abe63723826163050f8eff41f8f869e0b7da798a4545dcc7da9de0d28c98d368
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\ru-RU\WebCompanionInstaller.resources.dll
executable
MD5: 6049666b7a7e230c0435b243387c1000
SHA256: 95b627a94bffa0e536aad30c5168127b7d864e0776e50753ac36e0bc2d7bb211
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\en-US\WebCompanion.resources.dll
executable
MD5: fce6f16f838aff53344494112adfa5f5
SHA256: 05de6e9450b37e1893f7e8a63225933558bc84e7aef2416ff6748cc61886acef
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\Interop.LavasoftTcpServiceLib.dll
executable
MD5: 138f15a09476a2b209531315e8228b90
SHA256: 3989bef039965cded5e491894d3c8eb567108e043675b0d94496a4fbcef3ca67
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\Lavasoft.SysInfo.dll
executable
MD5: b8660d3929eb12492d2c2938a80763d3
SHA256: fd8efdc823b7c773894a9fb5d43b6e8be4e880afa57b8ccc145953c2cd6f31cf
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\ru-RU\WebCompanion.resources.dll
executable
MD5: 85ed00d1108743ef6d89b2c09ebdf4de
SHA256: 38ecf991081eaa1307541b0148a33275f14205e2ec40d71df30b6d6d682820f5
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\WebCompanionInstaller.exe
executable
MD5: 5b602e029cdca41f0a164de35468db78
SHA256: d4945c914dafc42aafff882687b32a42b17f863a17282a47076ac99727ab4f2b
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\ICSharpCode.SharpZipLib.dll
executable
MD5: 5e39ffdd87208d903620630f9d509d30
SHA256: cbf19183840c197bf01fe1c9641df38b0977f36c3eb151e810936548b7dc9bf1
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\Lavasoft.Utils.dll
executable
MD5: c9a15b209a1bb60a0f33b2afe4ae58fa
SHA256: 667f0c643c5061ee928c7c26fc51e494da35b6f541012534efeb886fa3b7ea47
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\tr-TR\WebCompanionInstaller.resources.dll
executable
MD5: f06c3e42348989e6d1fc4b2e45f991f4
SHA256: 24b8873e7b90d543315382e7f1c6f68d0fdd18c79ffe5cfd641c280825d7a42b
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\WebCompanionExtensionIE.dll
executable
MD5: 11bc0b010fc5675739efb468d6905b7e
SHA256: 29802de54306db086b52729d7d481ce06d66c503a5492301436b9ef34b9078c6
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\Interop.IWshRuntimeLibrary.dll
executable
MD5: c659dffcf6a93c0affa18df9fe685988
SHA256: fd9115d84705c0741d555c256a797d9df2a289dfc84923839a3bfa7a41400b57
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\Lavasoft.WCAssistant.WinService.exe
executable
MD5: b73cf58927cdcf36af99d1eea1e2cc52
SHA256: 0c47914d67b95a66a7984d50c5261039fab00b9be2fd5242f9fff22f6d6556cb
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\tr-TR\WebCompanion.resources.dll
executable
MD5: f79fcfc64b3a7053e76cb260262dc5f6
SHA256: 82e29c53fa2da958d5734522f01c19ff9ab3e95d027e167863c6c7e8a3e8ed17
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\WebCompanion.exe
executable
MD5: 8d7a9f79725a1e0cf2a9a33d1135aa8b
SHA256: 433424c9dbc3aac52f0b5511f9e642116631e40d8704d847f0e9bc536360b160
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\Esent.Interop.dll
executable
MD5: d88c833b390e85fa4fec243ba8c10c67
SHA256: 914f735626912a1cfbb6ed11504d375cf4bd55e8a7814f6def3c1216ffc0686c
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\Lavasoft.WCAssistant.WcfService.dll
executable
MD5: 1f512a34a8f5ee955f747325849d2ec6
SHA256: 08ca6ddcc301b5a3b95c2c1377591da4076d4c1522a325bda57ae0a19eadd988
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\x64\SQLite.Interop.dll
executable
MD5: 80d988a4d41732717f9128af8c92a517
SHA256: fdb786dee6b26225ea5f7122e250cf108383d9149fe910f2f67a4c9bf11b7074
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\Lavasoft.WCAssistant.Service.Logger.dll
executable
MD5: f7a71aaad7920110d54ea777ed7af59b
SHA256: d0a526ffde2833760aa7065f2b2be2380d862e553cb8cc450522075477e754a6
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\DotNetZip.dll
executable
MD5: b4621f76b27389bcbc55d54ce65e7bb3
SHA256: 810803fd105f36e6cc2a036f70ae15ec07d08a12f40d398bc0636cfccf4b7afe
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\liblz4.dll
executable
MD5: dbbcf4ac93dd341d99085d4af697c793
SHA256: d4cd6f9ed87671a15f1487d2d949fa688f90804b38029ba3d95a424aaacf9791
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\x86\SQLite.Interop.dll
executable
MD5: fd1bda81106b82c8ff35a6557512c989
SHA256: de4ed266e7b283eabd8e86c8aab66bd037c55c06e1025be063904c3beca394e7
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\log4net.dll
executable
MD5: b75c70cd0892b256fa09b0750d530281
SHA256: e36547ca5107454ba86d4b9366fce8979caac91627564df97df1b44840d49f5d
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\BCUSDK.dll
executable
MD5: e657a22a327dfbb3d34909c8776b29a0
SHA256: 9e149208942325a423fa6015ad1fde7a5853e13aac7e3f67a0f5d99e870e58d8
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\LZ4.dll
executable
MD5: 77c89e969662f3b49a6bf9bb23f778d9
SHA256: 3e760703e2aea439735ae44e9e80e0602763ea93f1add0357e37a159a37421ea
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\zh-CHS\WebCompanionInstaller.resources.dll
executable
MD5: 844a70a984616940e891a987cdf0514f
SHA256: d38c2127f151da48bd09939a456811e35759f3d821c7efde3e41450b0293d0fa
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\WebCompanion.Loader.exe
executable
MD5: b4455bcde1e616c7cb352daac84aab5e
SHA256: e10609e99cdf71c1ff3db00aada129bbe60af60119ebde02ef9417880594e8c4
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\BCUEngineS.dll
executable
MD5: c87c375b917256aad2cbd45d975457f7
SHA256: 7e3d7d8c5375178414cc684aac6e96183a01c53bb9498a9f518820aa00d96867
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\Microsoft.mshtml.dll
executable
MD5: c9d6adf11c19728959cff10fa6bebfd6
SHA256: 3f61b33ea7e04460ac12dfbc015cf82c64dbaaa34dca523baff732eae553af99
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\zh-Hans\WebCompanion.resources.dll
executable
MD5: a1e94e7d8985f5837e58bdec6a416639
SHA256: 986b9ede9fd7d934c5bead47b41bbf933d3d540819a5cfbe353d185d5fdea1d8
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\Newtonsoft.Json.dll
executable
MD5: ef00c9baa6972b34fdda9b486247051b
SHA256: 7eb3030cef20a706b6c045b84fc946b30d35f70853baa066f16f04ec8e4cdd13
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\Ad-Aware Web Companion.exe
executable
MD5: 8ac52271e29328bd44e1ac8ec4a3224c
SHA256: 8e61b41490370bb2b73f65189b7e959d1f445eb6ca220d3902bbfdbf1121bd9e
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\System.Data.SQLite.dll
executable
MD5: 7e46f83453f85e30c3fc207e4000b300
SHA256: 661d75c0f684521384156af4e9ccbfbdaa18dba092c885f77e013d37da159ca8
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\MozCompressor.dll
executable
MD5: bfb28bdcdb48b32fbf8558766dc54a32
SHA256: 6acc2517940104dfd6e7679a1b72dfb4c24f747de3c157cbc928561fb138b9d3
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\fr-CA\WebCompanionInstaller.resources.dll
executable
MD5: 01f5f27c52adb66a29a816d8ff1513e2
SHA256: 263726ebfb080d7423b29a26843eae1f21af7395aa7bea62a44440ca675a1f76
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\Interop.SHDocVw.dll
executable
MD5: dc2bdc3cecbfee622cf783163221ed61
SHA256: 8368d58b05db541a6444d635f73f13e57fca4816835ffd432a48874f075da260
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\Lavasoft.WCAssistant.WinService.exe.config
xml
MD5: aed25c4bb45d63f367ac309da2d91716
SHA256: 534ff170605c383fa723b662e49daf7683c560727fd71211b28799c5a6af11af
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\WebcompaionReimageIcon.ico
image
MD5: 9932f44f84f0693ad7d3b7f5e41b5c3f
SHA256: 8e10edc1e341c0b89232811bf8b71ca1a1eedc8ca78b79432c4ad702591b2de5
3428
WebCompanion.exe
C:\ProgramData\Lavasoft\Web Companion\Logs\Webcompanion\webcompanion.log
text
MD5: e36582f0b4e60ff4b62984ba812931be
SHA256: 7cecca57ea7320843c19a6bb36e294df76a01ffa2d706b9c903c0dab69794ea5
3796
WebCompanionInstaller.exe
C:\Users\admin\AppData\Local\Temp\WcInstaller.log
text
MD5: 4ada9ba73663861ae62e0f7eb405b523
SHA256: f384bffb49f7360f0c893ed146012e660cafd4bd101f7065c2a1db5d0a88f2cb
3428
WebCompanion.exe
C:\ProgramData\Lavasoft\Web Companion\Logs\Webcompanion\webcompanion.log
text
MD5: b628089d3b5f6524729440580898049d
SHA256: 305f8a17403448bca70701125928cad4c9138a38e8bb8ab98c07c0f77e802742
3428
WebCompanion.exe
C:\ProgramData\Lavasoft\Web Companion\Logs\Webcompanion\webcompanion.log
text
MD5: e15d7c2908ba44520544de6d4766eb90
SHA256: 4f233540c26501b8e1663e1bd4c17531ca90913514da0e1c2791dbece24091a7
3428
WebCompanion.exe
C:\ProgramData\Lavasoft\Web Companion\Options\ActiveFeatures.zip
compressed
MD5: 60ebb0ad956a6eb3a83b5060226d1cde
SHA256: 66a87b955918154ababd58d1856b612fc3d54bb98dff5b7eeb6ea1ff382fa8a7
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\WebCompanionInstaller.exe.config
xml
MD5: 1d0d9d32fb69c7f2f33b4e56d93e2c6d
SHA256: c022a2b126c1bad1774e7f9d3a5f50f30cb6b3758a2f870fc676160275f69eac
3428
WebCompanion.exe
C:\ProgramData\Lavasoft\Web Companion\Logs\Webcompanion\webcompanion.log
text
MD5: cb596e06b02bd06fd002469b408ea41b
SHA256: 6290529d9346e7b90944ae7c1c122f03a94a646667acc64905296f680433f5fa
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\Extension\@wcextensionff.xpi
compressed
MD5: 8da01c7329c1af3202d93c8631e0df35
SHA256: a30d0aa074214f7c6d8e82fe36e6ea4fc17c95f6c772c11d03667911c0475a03
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\WebCompanionIcon.ico
image
MD5: 1dd04466644e96e0ad308d1e637e9621
SHA256: 9733ed5e1e2caeb0986f1d46a052b2d4bd8cd6b041b9f57216f12410605e8455
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\WebCompanionInstaller.pdb
pdb
MD5: 79012da28909224ab304c04b56997bd1
SHA256: dbdedba9d5e7bdb998b01ac94b3d82294d1c3c45a3f242d31dd1b4569395ee68
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\WebCompanionIcon_Pro.ico
image
MD5: bbd842a6e91d908141de6fa59d3a9868
SHA256: d5a8246ef2075dad3b3d582477cf757fe673a3a793ef3de60de82bf8581da19f
3736
WinRAR.exe
C:\Users\admin\Desktop\WebCompanion-4.5.1957.3838-prod\WebCompanion.exe.config
xml
MD5: 0c68d37417aba406450f829ae6353c8a
SHA256: ebaa878c71314520307d5e259c93ded3857113112fe102255a4b19c262033a76
3428
WebCompanion.exe
C:\ProgramData\Lavasoft\Web Companion\Logs\Webcompanion\webcompanion.log
text
MD5: 22a4f9ff26aacef7c030e505dcd53e82
SHA256: 4932cbce8be041b8d9e9957171761d4e53896a5a0af00c7e728a2c81a5a79ac6
3428
WebCompanion.exe
C:\Users\admin\AppData\Local\Lavasoft\WebCompanion.exe_Url_3lb0thka4i14jeujqhdrafyqpuv5x0wc\4.5.1957.3838\user.config
xml
MD5: 0a35fbae99f45bc0dccdb777ecfd0436
SHA256: 19af84c48a15820c94367390d58588ddad8164b0ac4056c258a766c726329550
3360
dw20.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\WER\ReportArchive\AppCrash_webcompanioninst_f88b5ab7541c3660767dc48fff7aa9a58f2fd367_0d3ade99\Report.wer
binary
MD5: 6644b499fa230c8ff2d676498bb01afd
SHA256: 968613bfe6bed9fdda8476eba5d2fb16cefd9eb7cfabd7e2b723278ea4c17249
3428
WebCompanion.exe
C:\Users\admin\AppData\Local\Lavasoft\WebCompanion.exe_Url_3lb0thka4i14jeujqhdrafyqpuv5x0wc\4.5.1957.3838\trahhg4j.newcfg
––
MD5:  ––
SHA256:  ––
116
explorer.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019021020190211\index.dat
dat
MD5: f12c51b12b7e0c73b085489c285bc75a
SHA256: 0ea5e76d5b2d630c27b2fefa08a7f94d8b1bc1ea215763c186e95739d6e089ab
116
explorer.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\WebCompanion-4.5.1957.3838-prod.zip.lnk
lnk
MD5: 77dd6a3d469d7533d7f4a26ec0eadd05
SHA256: 673e99df65a0c6629fccd87ca2715cfaaca37ab87e1f8c62f20b8069f76d52f7
116
explorer.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\1b4dd67f29cb1962.automaticDestinations-ms
automaticdestinations-ms
MD5: 095a93b69956320d95db8400f74e2c2d
SHA256: 0015427e7a3f9f2cdb3985e187f59ab7d33bb40f2acbcf3280bccd1dd758b5e6
116
explorer.exe
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\290532160612e071.automaticDestinations-ms
automaticdestinations-ms
MD5: 66d4d18c2900d06c74c84f82a73f455b
SHA256: de24ff0ee8c95b706be7fd31eae739d57db18c0e3427530b72e74c4412e58576

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
2
TCP/UDP connections
2
DNS requests
2
Threats
0

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
3428 WebCompanion.exe GET 200 104.17.177.102:80 http://webcompanion.com/version_logs?json=true&version=4.5.1957.3838 US
text
malicious
3428 WebCompanion.exe GET 200 104.17.177.102:80 http://rt.webcompanion.com/notifications/download/rt/ActiveFeatures.zip US
compressed
malicious

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
3428 WebCompanion.exe 104.17.177.102:80 Cloudflare Inc US suspicious

DNS requests

Domain IP Reputation
webcompanion.com 104.17.177.102
104.17.178.102
malicious
rt.webcompanion.com 104.17.177.102
104.17.178.102
malicious

Threats

No threats detected.

Debug output strings

Process Message
WebCompanionInstaller.exe Detecting windows culture