General Info

File name

2.zip

Full analysis
https://app.any.run/tasks/d9fa6cb7-be3c-44c7-8990-e9afd2c4add0
Verdict
Malicious activity
Analysis date
1/11/2019, 08:30:13
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/zip
File info:
Zip archive data, at least v2.0 to extract
MD5

48158c4908ddcb2411c9e3c1613e56fc

SHA1

1b7376e407b3a84a0cc518b1cdf7ebdd87cd4479

SHA256

f2963ba302baaa602feb4a66455607c6dca15174c11264056898b24f3001d76a

SSDEEP

49152:xkHckII3rcYuJapvRcATqJ8dBMmiAMBT432JHrFK6yrQ8tI9qq8KLUGfiEmgmb:xockN7pZBD88Uj9ok9qofiBtb

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads dropped or rewritten executable
  • WinRAR.exe (PID: 2900)
  • iexplore.exe (PID: 2388)
  • sysdiag.exe (PID: 3992)
  • iexplore.exe (PID: 3788)
  • explorer.exe (PID: 116)
  • driver-setup.exe (PID: 2164)
  • Setup(password=spytech).exe (PID: 2328)
Application was dropped or rewritten from another process
  • sysdiag.exe (PID: 3992)
  • driver-setup.exe (PID: 2164)
  • npf_mgm.exe (PID: 1200)
  • Setup(password=spytech).exe (PID: 2328)
Changes the autorun value in the registry
  • sysdiag.exe (PID: 3992)
UAC/LUA settings modification
  • Setup(password=spytech).exe (PID: 2328)
Starts Internet Explorer
  • Setup(password=spytech).exe (PID: 2328)
Check for Java to be installed
  • iexplore.exe (PID: 3788)
Creates a software uninstall entry
  • Setup(password=spytech).exe (PID: 2328)
Creates files in the Windows directory
  • Setup(password=spytech).exe (PID: 2328)
  • driver-setup.exe (PID: 2164)
Creates files in the driver directory
  • driver-setup.exe (PID: 2164)
Executable content was dropped or overwritten
  • driver-setup.exe (PID: 2164)
  • Setup(password=spytech).exe (PID: 2328)
Creates files in the program directory
  • Setup(password=spytech).exe (PID: 2328)
  • driver-setup.exe (PID: 2164)
Creates executable files which already exist in Windows
  • Setup(password=spytech).exe (PID: 2328)
Changes internet zones settings
  • iexplore.exe (PID: 3788)
Application launched itself
  • iexplore.exe (PID: 3788)
Reads internet explorer settings
  • iexplore.exe (PID: 2388)
Creates files in the user directory
  • iexplore.exe (PID: 2388)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.zip
|   ZIP compressed archive (100%)
EXIF
ZIP
ZipRequiredVersion:
20
ZipBitFlag:
null
ZipCompression:
Deflated
ZipModifyDate:
2001:10:15 17:00:18
ZipCRC:
0x8ea1cfb9
ZipCompressedSize:
123
ZipUncompressedSize:
176
ZipFileName:
SpyAgent's 10 Step Guide to Total Stealth.url

Screenshots

Processes

Total processes
40
Monitored processes
8
Malicious processes
3
Suspicious processes
2

Behavior graph

+
start drop and start drop and start winrar.exe no specs setup(password=spytech).exe driver-setup.exe npf_mgm.exe no specs iexplore.exe sysdiag.exe iexplore.exe explorer.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
116
CMD
C:\Windows\Explorer.EXE
Path
C:\Windows\explorer.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Windows Explorer
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\slc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\profapi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\iconcodecservice.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sndvolsso.dll
c:\windows\system32\hid.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\timedate.cpl
c:\windows\system32\atl.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\actxprxy.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\userenv.dll
c:\windows\system32\shacct.dll
c:\windows\system32\samlib.dll
c:\windows\system32\samcli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\msftedit.dll
c:\windows\system32\msls31.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\authui.dll
c:\windows\system32\cryptui.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\gameux.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\wer.dll
c:\windows\system32\msiltcfg.dll
c:\windows\system32\version.dll
c:\windows\system32\msi.dll
c:\windows\system32\winsta.dll
c:\windows\system32\psapi.dll
c:\windows\system32\networkexplorer.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wdmaud.drv
c:\windows\system32\ksuser.dll
c:\windows\system32\avrt.dll
c:\windows\system32\audioses.dll
c:\windows\system32\msacm32.drv
c:\windows\system32\msacm32.dll
c:\windows\system32\midimap.dll
c:\windows\system32\stobject.dll
c:\windows\system32\batmeter.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\es.dll
c:\windows\system32\prnfldr.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dxp.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\syncreg.dll
c:\windows\ehome\ehsso.dll
c:\windows\system32\netshell.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\alttab.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
c:\program files\filezilla ftp client\fzshellext.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\pnidui.dll
c:\windows\system32\qutil.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\npmproxy.dll
c:\windows\system32\wlanapi.dll
c:\windows\system32\wlanutil.dll
c:\windows\system32\wwanapi.dll
c:\windows\system32\wwapi.dll
c:\windows\system32\qagent.dll
c:\windows\system32\srchadmin.dll
c:\windows\system32\sxs.dll
c:\windows\system32\bthprops.cpl
c:\windows\system32\winanr.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\synccenter.dll
c:\windows\system32\actioncenter.dll
c:\windows\system32\imapi2.dll
c:\windows\system32\hgcpl.dll
c:\windows\system32\provsvc.dll
c:\windows\system32\netprofm.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\fxsst.dll
c:\windows\system32\fxsapi.dll
c:\windows\system32\fxsresm.dll
c:\windows\system32\wscinterop.dll
c:\windows\system32\wscapi.dll
c:\windows\system32\wscui.cpl
c:\windows\system32\werconcpl.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\wercplsupport.dll
c:\windows\system32\msxml6.dll
c:\windows\system32\hcproviders.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\mpr.dll
c:\windows\system32\drprov.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\thumbcache.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\program files\winrar\winrar.exe
c:\windows\system32\zipfldr.dll
c:\program files\winrar\rarext.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\desktop\setup(password=spytech).exe
c:\windows\system32\imageres.dll
c:\windows\system32\twext.dll
c:\windows\system32\syncui.dll
c:\windows\system32\synceng.dll
c:\program files\notepad++\nppshell_06.dll
c:\windows\system32\acppage.dll
c:\windows\system32\sendmail.dll
c:\windows\system32\mydocs.dll
c:\windows\system32\wfsr.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\audiodev.dll
c:\windows\system32\wmvcore.dll
c:\windows\system32\wmasf.dll
c:\windows\system32\ehstorapi.dll
c:\windows\system32\structuredquery.dll
c:\windows\unvise32.exe
c:\program files\sysconfig\sysdiag.exe
c:\windows\system32\sinvfct.dll

PID
2900
CMD
"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\2.zip"
Path
C:\Program Files\WinRAR\WinRAR.exe
Indicators
No indicators
Parent process
explorer.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Alexander Roshal
Description
WinRAR archiver
Version
5.60.0
Modules
Image
c:\program files\winrar\winrar.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\uxtheme.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\riched20.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\mpr.dll
c:\windows\system32\drprov.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\winmm.dll
c:\windows\system32\portabledeviceapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\audiodev.dll
c:\windows\system32\wmvcore.dll
c:\windows\system32\wmasf.dll
c:\windows\system32\ehstorapi.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\url.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\sinvfct.dll

PID
2328
CMD
"C:\Users\admin\Desktop\Setup(password=spytech).exe"
Path
C:\Users\admin\Desktop\Setup(password=spytech).exe
Indicators
Parent process
explorer.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\desktop\setup(password=spytech).exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\users\admin\appdata\local\temp\~vis0000\vise32ex.dll
c:\windows\system32\comdlg32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\progra~1\syscon~1\driver-setup.exe
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sxs.dll
c:\windows\system32\actxprxy.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\windows\unvise32.exe
c:\program files\internet explorer\iexplore.exe
c:\program files\sysconfig\sysdiag.exe
c:\windows\system32\netutils.dll

PID
2164
CMD
"C:\PROGRA~1\SYSCON~1\driver-setup.exe" -s
Path
C:\PROGRA~1\SYSCON~1\driver-setup.exe
Indicators
Parent process
Setup(password=spytech).exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\clbcatq.dll
c:\users\admin\desktop\setup(password=spytech).exe
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msutb.dll
c:\windows\system32\msctf.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\winsta.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\user32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\kernelbase.dll
c:\systemroot\system32\ntdll.dll
c:\progra~1\syscon~1\driver-setup.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\version.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\users\admin\appdata\local\temp\3722ikos\unpack.dll
c:\windows\system32\crtdll.dll
c:\windows\system32\devrtl.dll
c:\program files\winconfig\npf_mgm.exe

PID
1200
CMD
"C:\Program Files\WinConfig\npf_mgm.exe" -r
Path
C:\Program Files\WinConfig\npf_mgm.exe
Indicators
No indicators
Parent process
driver-setup.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
CACE Technologies
Description
npf_mgm
Version
3, 1, 0, 27
Modules
Image
c:\program files\winconfig\npf_mgm.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
3788
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" http://www.spytech-web.com/spyagent/stealthguide
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
Setup(password=spytech).exe
User
admin
Integrity Level
HIGH
Exit code
1
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\cryptbase.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\ieui.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\url.dll
c:\windows\system32\propsys.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\msfeeds.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mlang.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\sinvfct.dll
c:\windows\system32\linkinfo.dll

PID
3992
CMD
"C:\Program Files\sysconfig\sysdiag.exe"
Path
C:\Program Files\sysconfig\sysdiag.exe
Indicators
Parent process
Setup(password=spytech).exe
User
admin
Integrity Level
HIGH
Version:
Company
Description
Version
Modules
Image
c:\program files\sysconfig\sysdiag.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\sinvfct.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\snmpapi.dll
c:\windows\system32\mpr.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\avicap32.dll
c:\windows\system32\version.dll
c:\windows\system32\msvfw32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\winspool.drv
c:\windows\system32\comdlg32.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\riched20.dll
c:\windows\system32\inetmib1.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\dciman32.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\wdmaud.drv
c:\windows\system32\ksuser.dll
c:\windows\system32\avrt.dll
c:\windows\system32\audioses.dll
c:\windows\system32\msacm32.drv
c:\windows\system32\midimap.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll

PID
2388
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3788 CREDAT:79873
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
iexplore.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\comdlg32.dll
c:\program files\internet explorer\ieshims.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mlang.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\program files\java\jre1.8.0_92\bin\ssv.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\progra~1\micros~1\office14\urlredir.dll
c:\windows\system32\secur32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\progra~1\micros~1\office14\msohev.dll
c:\program files\java\jre1.8.0_92\bin\jp2ssv.dll
c:\program files\java\jre1.8.0_92\bin\msvcr100.dll
c:\program files\java\jre1.8.0_92\bin\deploy.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\sxs.dll
c:\windows\system32\credssp.dll
c:\windows\system32\sinvfct.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\jscript.dll

Registry activity

Total events
5664
Read events
3974
Write events
1690
Delete events
0

Modification events

PID
Process
Operation
Key
Name
Value
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.zip\OpenWithList
a
WinRAR.exe
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.zip\OpenWithList
MRUList
a
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\JvaENE\JvaENE.rkr
00000000000000000000000000000000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002E0000003D000000FA3A1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\JvaENE\JvaENE.rkr
000000000000000000000000EC050000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002E0000003D000000E6401500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\Qrfxgbc\Frghc(cnffjbeq=fclgrpu).rkr
00000000010000000000000000000000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF50971B997FA9D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000003D000000E6401500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\Qrfxgbc\Frghc(cnffjbeq=fclgrpu).rkr
000000000100000000000000EF070000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF50971B997FA9D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000003D000000D5481500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\JvaENE\JvaENE.rkr
000000000000000001000000EC050000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000003E000000D5481500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\JvaENE\JvaENE.rkr
0000000000000000010000000B060000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000003E000000F4481500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\Qrfxgbc\Frghc(cnffjbeq=fclgrpu).rkr
000000000100000000000000CB1A0000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF50971B997FA9D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000003E000000D05B1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\Qrfxgbc\Frghc(cnffjbeq=fclgrpu).rkr
000000000100000000000000C21E0000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF50971B997FA9D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000003E000000C75F1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\Qrfxgbc\Frghc(cnffjbeq=fclgrpu).rkr
00000000010000000000000015260000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF50971B997FA9D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000003E0000001A671500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\Qrfxgbc\Frghc(cnffjbeq=fclgrpu).rkr
000000000100000000000000932B0000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF50971B997FA9D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000003E000000986C1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\Qrfxgbc\Frghc(cnffjbeq=fclgrpu).rkr
000000000100000000000000C6320000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF50971B997FA9D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000003E000000CB731500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\Qrfxgbc\Frghc(cnffjbeq=fclgrpu).rkr
000000000100000000000000AC460000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF50971B997FA9D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000003E000000B1871500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\Qrfxgbc\Frghc(cnffjbeq=fclgrpu).rkr
000000000100000000000000A54F0000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF50971B997FA9D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000003E000000AA901500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{C8E6F269-B90A-4053-A3BE-499AFCEC98C4}.check.0
CheckSetting
01000000D08C9DDF0115D1118C7A00C04FC297EB01000000EB52634729D5FB4CBAF3294806E5740C000000000200000000001066000000010000200000004B00A050E877EC6863131EA3513EA43D9429E64C520B259A573499FB9E00F3E8000000000E800000000200002000000020A41B4680CDD347B57E6317594A70F2EAC05FD668ECB73202F3C2E5C70D670FB0000000BF200E6EC13EEA02011D1BEEA7BCEB01F9CD1486A7992CED9C5624B4D045F78617FF439592B1A28D63CD556E089958E9389ADA119F53AC1ACE316CD6699F1D3A4775B82D0C55EA7C22D59B397DDB7ED229E5EBE06DE76D3AA60323EFC24D6D9401773916819698444CCEA0BB64E14D473A4428883543C579A3948568C788F3EC94F23312BF0883CBC23439381E78EDD0A1A248708C422728594558BCDB62FFC4E23EEC9BF31AEA575B791472294B661F40000000548757363D6F1869AFFC2E883CEB5E596F7CD66E59C7A8371EA99C84706845944A57F965A9E287AA7319D248763708E4B17B4BDB965FFE1937E82349FBFA141C
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
NodeSlots
0202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
MRUListEx
0100000000000000020000000700000006000000030000000500000004000000FFFFFFFF
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar
Locked
1
116
explorer.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell
SniffedFolderType
Generic
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\Qrfxgbc\Frghc(cnffjbeq=fclgrpu).rkr
00000000010000000000000067610000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF50971B997FA9D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000003E0000006CA21500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\Qrfxgbc\Frghc(cnffjbeq=fclgrpu).rkr
00000000010000000100000067610000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF50971B997FA9D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000003F0000006CA21500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\rkcybere.rkr
00000000060000000900000095E40300000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF6012F7D45C48D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000003F00000059AD1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\Qrfxgbc\Frghc(cnffjbeq=fclgrpu).rkr
0000000001000000010000002B6B0000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF50971B997FA9D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000003F0000001DB71500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\Qrfxgbc\Frghc(cnffjbeq=fclgrpu).rkr
0000000001000000010000008A700000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF50971B997FA9D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000003F0000007CBC1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\rkcybere.rkr
00000000060000000A00000095E40300000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF6012F7D45C48D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F000000400000007CBC1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\rkcybere.rkr
00000000060000000A00000064E70300000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF6012F7D45C48D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F000000400000004BBF1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\flfpbasvt\flfqvnt.rkr
00000000000000000000000023020000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F000000400000006EC11500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\flfpbasvt\flfqvnt.rkr
00000000000000000100000023020000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F000000410000006EC11500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Zvpebfbsg.VagreargRkcybere.Qrsnhyg
000000000100000001000000C05D0000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF7094AFE65A48D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000004100000094C51500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Zvpebfbsg.VagreargRkcybere.Qrsnhyg
000000000100000002000000C05D0000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF7094AFE65A48D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000004200000094C51500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Zvpebfbsg.VagreargRkcybere.Qrsnhyg
0000000001000000020000006C5E0000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF7094AFE65A48D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000004200000040C61500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Zvpebfbsg.VagreargRkcybere.Qrsnhyg
0000000001000000030000006C5E0000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF7094AFE65A48D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F0000004300000040C61500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\flfpbasvt\flfqvnt.rkr
00000000000000000100000072070000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F000000430000008FCB1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Zvpebfbsg.VagreargRkcybere.Qrsnhyg
000000000100000003000000DA5E0000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF7094AFE65A48D40100000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F00000043000000FDCB1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
{7P5N40RS-N0SO-4OSP-874N-P0S2R0O9SN8R}\flfpbasvt\flfqvnt.rkr
00000000000000000200000072070000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
116
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002F00000044000000FDCB1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
2900
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
ShellExtBMP
2900
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
ShellExtIcon
2900
WinRAR.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
2900
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
0
C:\Users\admin\AppData\Local\Temp\2.zip
2900
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
name
120
2900
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
size
80
2900
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
type
120
2900
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
mtime
100
2900
WinRAR.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
@C:\Windows\System32\ieframe.dll,-10046
Internet Shortcut
2900
WinRAR.exe
write
HKEY_CURRENT_USER\Software\WinRAR\Interface
ShowPassword
0
2328
Setup(password=spytech).exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
EnableLUA
0
2328
Setup(password=spytech).exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2328
Setup(password=spytech).exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2328
Setup(password=spytech).exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spytech SpyAgent
DisplayName
Spytech SpyAgent
2328
Setup(password=spytech).exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spytech SpyAgent
UninstallString
C:\Windows\unvise32.exe C:\Program Files\sysconfig\uninstal.log
2328
Setup(password=spytech).exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\unvise32.exe
1
2328
Setup(password=spytech).exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
NodeSlots
02020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
2328
Setup(password=spytech).exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
MRUListEx
0100000000000000020000000700000006000000030000000500000004000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0
MRUListEx
0400000001000000000000000200000003000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4\0\0\0\0
1
6E0031000000000000000000100053707974656368205370794167656E7400004E0008000400EFBE00000000000000002A00000000000000000000000000000000000000000000000000530070007900740065006300680020005300700079004100670065006E007400000020000000
2328
Setup(password=spytech).exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4\0\0\0\0
MRUListEx
0100000000000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
NodeSlots
0202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
2328
Setup(password=spytech).exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4\0\0\0\0\1
NodeSlot
95
2328
Setup(password=spytech).exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4\0\0\0\0\1
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell
KnownFolderDerivedFolderType
{57807898-8C4F-4462-BB63-71042380B109}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
1
14001F50E04FD020EA3A6910A2D808002B30309D0000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
2
14001F4225481E03947BC34DB131E946B44C8DD50000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
3
14001F6880531C87A0426910A2EA08002B30309D0000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
4
4C00310000000000454BB94D1000746F6F6C7300380008000400EFBE454BB94D454BB94D2A000000A844000000000200000000000000000000000000000074006F006F006C007300000014000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
5
9400310000000000000000001000303030312D363330355F56697374615F57696E375F504735333728312900680008000400EFBE00000000000000002A0000000000000000000000000000000000000000000000000030003000300031002D0036003300300035005F00560069007300740061005F00570069006E0037005F005000470035003300370028003100290000002C000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
7
14001F44471A0359723FA74489C55595FE6B30EE0000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
NodeSlot
82
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0
1
0C0001008421DE39050000000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0
NodeSlot
5
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0
2
0C0001008421DE39000000000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0
3
0C0001008421DE39030000000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0
4
0C0001008421DE39020000000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0
5
0C0001008421DE39090000000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\0
1
1E007180000000000000000000008B4355C5233C6947A71FB6D3D9B6053A0000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\0\0
NodeSlot
1
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\0\1
0
F7000000F10000EEEBBEE300040000000000510000003153505330F125B7EF471A10A5F102608C9EEBAC350000000A000000001F00000012000000530063007200650065006E0020005200650073006F006C007500740069006F006E000000000000004100000031535053537DEF0C64FAD111A2030000F81FEDEE2500000005000000001F00000009000000530065007400740069006E006700730000000000000000004D000000315350538727BF5CCF480842B90EEE5E5D4202943100000019000000001F0000000F00000044006900730070006C00610079002E0064006C006C002C002D00310000000000000000000000000000000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\0\1
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\0\1\0
NodeSlot
2
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\0\1\0
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\1
0
1E00718000000000000000000000E4C006BB93D2754F8A90CB05B6477EEE0000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\1
MRUListEx
0100000000000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\1
NodeSlot
6
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\1
1
1E007180000000000000000000002F492640692FB846B9BF5654FC07E4230000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\1\0
NodeSlot
4
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\1\0
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\1\1
NodeSlot
7
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\1\1
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\1\1
0
2B010000250100EEEBBE1701040000000000550000003153505330F125B7EF471A10A5F102608C9EEBAC390000000A000000001F0000001300000043007500730074006F006D0069007A0065002000530065007400740069006E006700730000000000000000005900000031535053537DEF0C64FAD111A2030000F81FEDEE3D00000005000000001F00000016000000500061006700650043006F006E00660069006700750072006500530065007400740069006E006700730000000000000065000000315350538727BF5CCF480842B90EEE5E5D4202944900000019000000001F0000001C0000004600690072006500770061006C006C0043006F006E00740072006F006C00500061006E0065006C002E0064006C006C002C002D0031000000000000000000000000000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\1\1\0
NodeSlot
8
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\1\1\0
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2
NodeSlot
9
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2
MRUListEx
02000000090000000100000008000000070000000600000005000000040000000300000000000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2
0
1E00718000000000000000000000DBF7EE36AD88814EAD490E313F0C35F80000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2
1
1E00718000000000000000000000C98F908ECCBEF640915BF4CA0E70D03D0000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2
2
1E00718000000000000000000000E4C006BB93D2754F8A90CB05B6477EEE0000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2
3
1E00718000000000000000000000D64E83ED5A4BFE4B8F11A626DCB6A9210000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2
4
1E007180000000000000000000008B4355C5233C6947A71FB6D3D9B6053A0000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2
5
1E007180000000000000000000005076CA67E696DD4FBB43A8E774F73A570000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2
6
1E00718000000000000000000000E5F5739CE77A324EA8E88D23B85255BF0000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2
7
1E007180000000000000000000006ABE817B2BCE7646A29EEB907A5126C50000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2
8
1E00718000000000000000000000A7F864BBE7BE1A4EAB8D7D8273F7FDB60000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2
9
1E007180000000000000000000002F492640692FB846B9BF5654FC07E4230000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\0
NodeSlot
10
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\0
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\0
0
FB000000F50000EEEBBEE7000400010000004D0000003153505330F125B7EF471A10A5F102608C9EEBAC310000000A000000001F000000100000004300680061006E00670065002000730065007400740069006E00670073000000000000004900000031535053537DEF0C64FAD111A2030000F81FEDEE2D00000005000000001F0000000D0000007000610067006500530065007400740069006E006700730000000000000000004D000000315350538727BF5CCF480842B90EEE5E5D4202943100000019000000001F0000000F0000007700750063006C007400750078002E0064006C006C002C002D00310000000000000000000000000000000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\0\0
NodeSlot
11
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\0\0
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\1
NodeSlot
22
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\1
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\1
0
0F010000090100EEEBBEFB00040000000000610000003153505330F125B7EF471A10A5F102608C9EEBAC450000000A000000001F0000001A00000041006400760061006E006300650064002000730068006100720069006E0067002000730065007400740069006E00670073000000000000004100000031535053537DEF0C64FAD111A2030000F81FEDEE2500000005000000001F0000000900000041006400760061006E00630065006400000000000000000055000000315350538727BF5CCF480842B90EEE5E5D4202943900000019000000001F0000001300000069006D006100670065007200650073002E0064006C006C002C002D00310030003100330000000000000000000000000000000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\1\0
NodeSlot
44
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\1\0
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\2
NodeSlot
25
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\2
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\3
NodeSlot
28
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\3
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\4
0
F7000000F10000EEEBBEE300040000000000510000003153505330F125B7EF471A10A5F102608C9EEBAC350000000A000000001F00000012000000530063007200650065006E0020005200650073006F006C007500740069006F006E000000000000004100000031535053537DEF0C64FAD111A2030000F81FEDEE2500000005000000001F00000009000000530065007400740069006E006700730000000000000000004D000000315350538727BF5CCF480842B90EEE5E5D4202943100000019000000001F0000000F00000044006900730070006C00610079002E0064006C006C002C002D00310000000000000000000000000000000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\4
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\4\0
NodeSlot
29
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\4\0
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\5
NodeSlot
45
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\5
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\6
NodeSlot
46
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\6
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\7
NodeSlot
52
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\7
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\8
NodeSlot
57
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\8
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\8
0
1F010000190100EEEBBE0B01040000000000690000003153505330F125B7EF471A10A5F102608C9EEBAC4D0000000A000000001F0000001E0000004300680061006E0067006500200041006300740069006F006E002000430065006E007400650072002000730065007400740069006E00670073000000000000004100000031535053537DEF0C64FAD111A2030000F81FEDEE2500000005000000001F00000009000000530065007400740069006E006700730000000000000000005D000000315350538727BF5CCF480842B90EEE5E5D4202944100000019000000001F0000001700000041006300740069006F006E00430065006E00740065007200430050004C002E0064006C006C002C002D00310000000000000000000000000000000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\8\0
NodeSlot
58
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\8\0
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\9
NodeSlot
93
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\9
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\9
0
2B010000250100EEEBBE1701040000000000550000003153505330F125B7EF471A10A5F102608C9EEBAC390000000A000000001F0000001300000043007500730074006F006D0069007A0065002000530065007400740069006E006700730000000000000000005900000031535053537DEF0C64FAD111A2030000F81FEDEE3D00000005000000001F00000016000000500061006700650043006F006E00660069006700750072006500530065007400740069006E006700730000000000000065000000315350538727BF5CCF480842B90EEE5E5D4202944900000019000000001F0000001C0000004600690072006500770061006C006C0043006F006E00740072006F006C00500061006E0065006C002E0064006C006C002C002D0031000000000000000000000000000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\9\0
NodeSlot
94
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\2\9\0
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\3
0
1E00718000000000000000000000C7AC07700232D111AAD200805FC1270E0000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\3
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\3\0
NodeSlot
23
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\3\0
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\4
NodeSlot
42
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\4
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\5
NodeSlot
55
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\5
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\5
0
1E00718000000000000000000000F1F5061269052C418FEC3204630DFB700000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\5\0
NodeSlot
56
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\0\5\0
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1
0
19002F433A5C000000000000000000000000000000000000000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1
NodeSlot
27
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0
0
7400310000000000454B804A1100557365727300600008000400EFBEEE3AA314454B804A2A0000005A01000000000100000000000000000036000000000055007300650072007300000040007300680065006C006C00330032002E0064006C006C002C002D0032003100380031003300000014000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0
MRUListEx
0400000001000000000000000200000003000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0
NodeSlot
34
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0
1
8800310000000000464BDD51110050524F4752417E310000700008000400EFBEEE3AA314464BDD512A0000003C000000000001000000000000000000460000000000500072006F006700720061006D002000460069006C0065007300000040007300680065006C006C00330032002E0064006C006C002C002D0032003100370038003100000018000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0
2
5200310000000000464BEA51100057696E646F7773003C0008000400EFBEEE3AA314464BEA512A000000FA010000000001000000000000000000000000000000570069006E0064006F0077007300000016000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0
3
5000310000000000464B9D511000414E5952554E00003A0008000400EFBE454BFD4D464B9D512A0000005545000000000200000000000000000000000000000041004E005900520055004E00000016000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0
4
5E0031000000000000000000100050726F6772616D4461746100440008000400EFBE00000000000000002A00000000000000000000000000000000000000000000000000500072006F006700720061006D00440061007400610000001A000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0
0
4C00310000000000454B854A100061646D696E00380008000400EFBE454B804A454B854A2A0000002D000000000004000000000000000000000000000000610064006D0069006E00000014000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0
NodeSlot
54
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0
0
5200310000000000454B814A122041707044617461003C0008000400EFBE454B814A454B814A2A0000007C0100000000020000000000000000000000000000004100700070004400610074006100000016000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0
0
5200310000000000454B834A1020526F616D696E67003C0008000400EFBE454B814A454B834A2A0000007D01000000000200000000000000000000000000000052006F0061006D0069006E006700000016000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0
MRUListEx
0000000001000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0
1
4C00310000000000454B645310204C6F63616C00380008000400EFBE454B814A454B64532A0000008F0100000000020000000000000000000000000000004C006F00630061006C00000014000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0
NodeSlot
73
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0
0
5800310000000000454B834A14204D4943524F537E310000400008000400EFBE454B814A454B834A2A0000007E0100000000020000000000000000000000000000004D006900630072006F0073006F0066007400000018000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0
MRUListEx
0100000000000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0
NodeSlot
72
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0
1
4C003100000000001E4DC56E102041646F626500380008000400EFBE1C4DC45E1E4DC56E2A00000020C40000000002000000000000000000000000000000410064006F0062006500000014000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\0
0
5200310000000000454B854A102057696E646F7773003C0008000400EFBE454B814A454B854A2A0000007F010000000002000000000000000000000000000000570069006E0064006F0077007300000016000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\0
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\0\0
0
8200310000000000454B854A110053544152544D7E3100006A0008000400EFBE454B814A454B854A2A000000810100000000020000000000000000004000000000005300740061007200740020004D0065006E007500000040007300680065006C006C00330032002E0064006C006C002C002D0032003100370038003600000018000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\0\0
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\0\0\0
NodeSlot
3
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\0\0\0
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1
NodeSlot
86
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1
0
52003100000000001E4DC16E10204163726F626174003C0008000400EFBE1E4DC16E1E4DC16E2A000000D73D00000000160000000000000000000000000000004100630072006F00620061007400000016000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1\0
NodeSlot
87
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1\0
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1\0
0
4400310000000000294D747C102044430000320008000400EFBE1E4DC16E294D747C2A0000000D3E000000001000000000000000000000000000000044004300000012000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1\0\0
NodeSlot
88
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1\0\0
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1\0\0
0
5600310000000000294D747C1020536563757269747900003E0008000400EFBE294D747C294D747C2A00000033DA000000000400000000000000000000000000000053006500630075007200690074007900000018000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1\0\0\0
NodeSlot
89
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1\0\0\0
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1\0\0\0
0
5600310000000000294D747C102043524C436163686500003E0008000400EFBE294D747C294D747C2A00000034DA0000000003000000000000000000000000000000430052004C0043006100630068006500000018000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1\0\0\0\0
NodeSlot
90
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\0\1\0\0\0\0
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1
0
4A00310000000000464B2D52102054656D700000360008000400EFBE454B814A464B2D522A00000090010000000002000000000000000000000000000000540065006D007000000014000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1
MRUListEx
03000000020000000100000000000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1
NodeSlot
74
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1
1
50003100000000001D4D1D691020476F6F676C6500003A0008000400EFBE1C4D7C591D4D1D692A000000E9A1000000000A00000000000000000000000000000047006F006F0067006C006500000016000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1
2
58003100000000001C4D8265102046494C455A497E310000400008000400EFBE1C4D43621C4D82652A000000A6C80000000003000000000000000000000000000000460069006C0065005A0069006C006C006100000018000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1
3
58003100000000001D4DB67D10204D4943524F537E310000400008000400EFBE454B814A1D4DB67D2A000000910100000000020000000000000000000000000000004D006900630072006F0073006F0066007400000018000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\0
NodeSlot
39
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\0
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1
NodeSlot
75
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1
MRUListEx
0100000000000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1
0
72003100000000001D4D1D691020534F465457417E3100005A0008000400EFBE1D4D1D691D4D1D692A0000004BFC000000000100000000000000000000000000000053006F0066007400770061007200650020005200650070006F007200740065007200200054006F006F006C00000018000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1
1
50003100000000001C4D7C5910204368726F6D6500003A0008000400EFBE1C4D7C591C4D7C592A000000ECA100000000070000000000000000000000000000004300680072006F006D006500000016000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\0
NodeSlot
76
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\0
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\0
0
52003100000000001D4D1D6910207265706F727473003C0008000400EFBE1D4D1D691D4D1D692A0000004EFC00000000010000000000000000000000000000007200650070006F00720074007300000016000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\0\0
NodeSlot
77
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\0\0
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\1
NodeSlot
78
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\1
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\1
0
5800310000000000294DE58210205553455244417E310000400008000400EFBE1C4D7C59294DE5822A000000EEA10000000005000000000000000000000000000000550073006500720020004400610074006100000018000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\1\0
NodeSlot
79
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\1\0
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\1\0
0
5A003100000000001D4D1D69102053575245504F7E310000420008000400EFBE1C4D7D591D4D1D692A00000092BC0000000003000000000000000000000000000000530077005200650070006F007200740065007200000018000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\1\0\0
NodeSlot
80
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\1\0\0
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\1\0\0
0
5C003100000000001D4D1D69102033333137307E312E32303100420008000400EFBE1D4D1D691D4D1D692A000000BBFB0000000002000000000000000000000000000000330033002E003100370030002E0032003000310000001A000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\1\0\0\0
NodeSlot
81
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\1\1\0\0\0
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\2
NodeSlot
83
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\2
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\3
NodeSlot
84
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\3
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\3
0
5200310000000000294DE38310204F75746C6F6F6B003C0008000400EFBE1B4D1560294DE3832A000000A61B00000000030000000000000000000000000000004F00750074006C006F006F006B00000016000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\3\0
NodeSlot
85
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0\0\1\3\0
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1
NodeSlot
35
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1
MRUListEx
010000000000000002000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1
0
50003100000000001C4D54591000476F6F676C6500003A0008000400EFBE1C4D4F591C4D54592A000000FCB0000000000200000000000000000000000000000047006F006F0067006C006500000016000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1
1
5E003100000000001C4DA6691000434F4D4D4F4E7E310000460008000400EFBEEE3AA3141C4DA6692A0000003D00000000000100000000000000000000000000000043006F006D006D006F006E002000460069006C0065007300000018000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1
2
56003100000000001C4D7C60100043436C65616E657200003E0008000400EFBE1C4D7B601C4D7C602A00000069C40000000003000000000000000000000000000000430043006C00650061006E0065007200000018000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0
NodeSlot
59
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0
MRUListEx
000000000200000001000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0
0
50003100000000001C4D595910004368726F6D6500003A0008000400EFBE1C4D54591C4D59592A0000007AB500000000020000000000000000000000000000004300680072006F006D006500000016000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0
1
50003100000000001C4D5259100055706461746500003A0008000400EFBE1C4D4F591C4D52592A00000011B10000000002000000000000000000000000000000550070006400610074006500000016000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0
2
5E003100000000001C4D4F5910004352415348527E310000460008000400EFBE1C4D4F591C4D4F592A000000FFB00000000002000000000000000000000000000000430072006100730068005200650070006F00720074007300000018000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0\0
NodeSlot
60
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0\0
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0\0
0
5C003100000000001C4D595910004150504C49437E310000440008000400EFBE1C4D59591C4D59592A00000001BB00000000020000000000000000000000000000004100700070006C00690063006100740069006F006E00000018000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0\0\0
NodeSlot
71
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0\0\0
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0\1
NodeSlot
61
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0\1
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0\2
NodeSlot
70
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\0\2
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1
NodeSlot
62
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1
0
4C003100000000001C4D5866100041646F626500380008000400EFBE1C4D4A661C4D58662A000000E9D90000000003000000000000000000000000000000410064006F0062006500000014000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1\0
NodeSlot
63
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1\0
MRUListEx
000000000100000002000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1\0
0
46003100000000001C4D4A66100041524D00340008000400EFBE1C4D4A661C4D4A662A000000F6D90000000003000000000000000000000000000000410052004D00000012000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1\0
1
52003100000000001C4D4A6610004163726F626174003C0008000400EFBE1C4D4A661C4D4A662A000000EAD900000000030000000000000000000000000000004100630072006F00620061007400000016000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1\0
2
50003100000000001C4D4B66100052656164657200003A0008000400EFBE1C4D4B661C4D4B662A0000009DDA0000000002000000000000000000000000000000520065006100640065007200000016000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1\0\0
NodeSlot
64
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1\0\0
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1\0\0
0
4600310000000000294D7A791000312E3000340008000400EFBE1C4D4A66294D7A792A000000F7D9000000000300000000000000000000000000000031002E003000000012000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1\0\0\0
NodeSlot
65
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1\0\0\0
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1\0\1
NodeSlot
91
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1\0\1
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1\0\2
NodeSlot
92
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\1\0\2
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\2
NodeSlot
69
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1\2
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\2
NodeSlot
36
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\2
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\2
0
5200310000000000464BDD511000437572736F7273003C0008000400EFBEEE3AA414464BDD512A0000001305000000000100000000000000000000000000000043007500720073006F0072007300000016000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\2\0
NodeSlot
37
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\2\0
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\3
NodeSlot
38
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\3
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4
0
58003100000000000000000010004D6963726F736F667400400008000400EFBE00000000000000002A000000000000000000000000000000000000000000000000004D006900630072006F0073006F0066007400000018000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4\0
0
520031000000000000000000100057696E646F7773003C0008000400EFBE00000000000000002A00000000000000000000000000000000000000000000000000570069006E0064006F0077007300000016000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4\0
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4\0\0
0
5C003100000000000000000010005374617274204D656E750000420008000400EFBE00000000000000002A000000000000000000000000000000000000000000000000005300740061007200740020004D0065006E00750000001A000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4\0\0
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4\0\0\0
0
560031000000000000000000100050726F6772616D7300003E0008000400EFBE00000000000000002A00000000000000000000000000000000000000000000000000500072006F006700720061006D007300000018000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4\0\0\0
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4\0\0\0\0
0
500031000000000000000000100057696E52415200003A0008000400EFBE00000000000000002A00000000000000000000000000000000000000000000000000570069006E00520041005200000016000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4\0\0\0\0
MRUListEx
0100000000000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4\0\0\0\0
1
6E0031000000000000000000100053707974656368205370794167656E7400004E0008000400EFBE00000000000000002A00000000000000000000000000000000000000000000000000530070007900740065006300680020005300700079004100670065006E007400000020000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4\0\0\0\0\0
NodeSlot
51
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4\0\0\0\0\0
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4\0\0\0\0\1
NodeSlot
95
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4\0\0\0\0\1
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\2
NodeSlot
12
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\2
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\2
0
9E0000001A00EEBBFE23000010007DB10D7BD29C934A973346CC89022E7C00002A0000000000EFBE000000200000000000000000000000000000000000000000000000000100000020002A0000000000EFBE7E47B3FBE4C93B4BA2BAD3F5D3CD46F98207BA827A5B6945B5D7EC83085F08CC20002A0000000000EFBE000000200000000000000000000000000000000000000000000000000100000020000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\2\0
NodeSlot
50
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\2\0
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3
0
5200610348000301000004000000082B0074BE3DD301FFFFFFFF00000000000000000000000015000000100000003133362E3234332E35332E323335000004000000000000000400000000000000667470000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3
MRUListEx
010000000000000002000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3
1
5E00610354000327000004000000082B0074BE3DD3010000000000000000000000000000000015000000100000003133362E3234332E35332E32333500000800000066747075736572000C000000000000000000000000000000667470000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3
2
520061034800030100000400000028083CD18B3ED301FFFFFFFF00000000000000000000000015000000100000003133362E3234332E35332E323336000004000000000000000400000000000000667470000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\0
NodeSlot
13
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\0
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1
NodeSlot
14
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1
MRUListEx
000000000200000001000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1
0
320000000000050003001000000000100000000000000050F9D0BC35D3015507000000000000616E790061006E00790000000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1
1
3A000000000005000300100000000010000000000000000046EF03F6CE0177070000000000006F6C6C79000000006F006C006C007900000000000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1
2
3200000000000500030010000000001000000000000000822CC8FC3DD40175070000000000005737000057003700000000000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\0
NodeSlot
15
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\0
MRUListEx
050000000400000003000000020000000100000000000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\0
0
3200000000000500030010000000001000000000000000260B4FC035D30155070000000000007167610071006700610000000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\0
1
3A000000000005000300100000000010000000000000008833631E39D301550700000000000063657274000000006300650072007400000000000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\0
2
3E00000000000500030010000000001000000000000000884A1B0727D301550700000000000076697274696F0000760069007200740069006F00000000000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\0
3
3E00000000000500030010000000001000000000000000082186E72AD30155070000000000006472697665720000640072006900760065007200000000000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\0
4
3A00000000000500030010000000001000000000000000DE89991E38D3015507000000000000746F6F6C7300000074006F006F006C00730000000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\0
5
4A00000000000500030010000000001000000000000000B2B0DF80EED30177070000000000006465706C6F79736F667400006400650070006C006F00790073006F0066007400000000000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\0\0
NodeSlot
16
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\0\0
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\0\1
NodeSlot
17
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\0\1
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\0\2
NodeSlot
18
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\0\2
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\0\2
0
4600000000000500030010000000001000000000000000884A1B0727D301000700000000000076696F73657269616C000000760069006F00730065007200690061006C0000000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\0\2\0
NodeSlot
19
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\0\2\0
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\0\2\0
0
3200000000000500030010000000001000000000000000884A1B0727D30100070000000000007737000077003700000000000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\0\2\0\0
NodeSlot
20
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\0\2\0\0
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\0\2\0\0
0
3200000000000500030010000000001000000000000000884A1B0727D30100070000000000007838360078003800360000000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\0\2\0\0\0
NodeSlot
21
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\0\2\0\0\0
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\0\3
NodeSlot
26
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\0\3
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\0\4
NodeSlot
30
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\0\4
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\0\4
0
4600000000000500030010000000001000000000000000841B241DB4D201550700000000000063636C65616E657200000000630063006C00650061006E0065007200000000000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\0\4\0
NodeSlot
31
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\0\4\0
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\0\5
NodeSlot
48
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\0\5
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\0\5
0
5E00000000000500030010000000001000000000000000EE6EB1D13AD40175070000000000006D6963726F736F66745F6F6666696365000000006D006900630072006F0073006F00660074005F006F0066006600690063006500000000000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\0\5\0
NodeSlot
49
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\0\5\0
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\1
NodeSlot
33
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\1
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\2
NodeSlot
47
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\1\2
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\2
NodeSlot
32
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\3\2
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\4
NodeSlot
24
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\4
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\5
NodeSlot
40
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\5
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\5
0
6600310000000000614C03651000363330355F567E3100004E0008000400EFBE614C0265614C03652A0000006141000000000600000000000000000000000000000036003300300035005F00560069007300740061005F0050004700350033003700000018000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\5\0
NodeSlot
41
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\5\0
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\6
NodeSlot
43
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\6
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\7
0
200000001A00EEBBFE230000100090E24D373F126545916439C4925E467B00000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\7
MRUListEx
0100000000000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\7
1
7E0074001C00434653461600310000000000454B814A122041707044617461000000741A595E96DFD3488D671733BCEE28BAC5CDFADF9F6756418947C5C76BC0B67F3C0008000400EFBE454B814A454B814A2A0000007C0100000000020000000000000000000000000000004100700070004400610074006100000042000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\7\0
NodeSlot
53
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\7\0
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\7\1
0
4C00310000000000294D987B10204C6F63616C00380008000400EFBE454B814A294D987B2A0000008F0100000000020000000000000000000000000000004C006F00630061006C00000014000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\7\1
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\7\1\0
0
50003100000000001D4D1D691020476F6F676C6500003A0008000400EFBE1C4D7C591D4D1D692A000000E9A1000000000A00000000000000000000000000000047006F006F0067006C006500000016000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\7\1\0
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\7\1\0\0
0
50003100000000001C4D7C5910204368726F6D6500003A0008000400EFBE1C4D7C591C4D7C592A000000ECA100000000070000000000000000000000000000004300680072006F006D006500000016000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\7\1\0\0
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\7\1\0\0\0
0
5800310000000000294DC98210205553455244417E310000400008000400EFBE1C4D7C59294DC9822A000000EEA10000000005000000000000000000000000000000550073006500720020004400610074006100000018000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\7\1\0\0\0
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\7\1\0\0\0\0
0
5A003100000000001D4D1D69102053575245504F7E310000420008000400EFBE1C4D7D591D4D1D692A00000092BC0000000003000000000000000000000000000000530077005200650070006F007200740065007200000018000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\7\1\0\0\0\0
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\7\1\0\0\0\0
NodeSlot
68
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\7\1\0\0\0\0\0
0
5C003100000000001D4D1D69102033333137307E312E32303100420008000400EFBE1D4D1D691D4D1D692A000000BBFB0000000002000000000000000000000000000000330033002E003100370030002E0032003000310000001A000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\7\1\0\0\0\0\0
MRUListEx
00000000FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\7\1\0\0\0\0\0
NodeSlot
67
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\7\1\0\0\0\0\0\0
NodeSlot
66
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\7\1\0\0\0\0\0\0
MRUListEx
FFFFFFFF
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\1\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Rev
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\1\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
18874385
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\1\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Vid
{65F125E5-7BE1-4810-BA9D-D271C8432CE3}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\1\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Mode
6
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\1\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
LogicalViewMode
2
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\1\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
IconSize
48
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\1\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
ColInfo
00000000000000000000000000000000FDDFDFFD100000000000000000000000010000001800000030F125B7EF471A10A5F102608C9EEBAC0A000000A0000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\1\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Sort
000000000000000000000000000000000100000030F125B7EF471A10A5F102608C9EEBAC0A00000001000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\1\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupView
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\1\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:FMTID
{00000000-0000-0000-0000-000000000000}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\1\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:PID
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\1\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByDirection
1
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\10\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Rev
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\10\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
18874369
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\10\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Vid
{65F125E5-7BE1-4810-BA9D-D271C8432CE3}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\10\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Mode
6
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\10\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
LogicalViewMode
2
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\10\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
IconSize
48
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\10\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
ColInfo
00000000000000000000000000000000FDDFDFFD100000000000000000000000010000001800000030F125B7EF471A10A5F102608C9EEBAC0A000000A0000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\10\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Sort
000000000000000000000000000000000100000030F125B7EF471A10A5F102608C9EEBAC0A00000001000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\10\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupView
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\10\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:FMTID
{00000000-0000-0000-0000-000000000000}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\10\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:PID
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\10\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByDirection
1
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\11\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Rev
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\11\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
18874369
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\11\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Vid
{65F125E5-7BE1-4810-BA9D-D271C8432CE3}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\11\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Mode
6
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\11\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
LogicalViewMode
2
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\11\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
IconSize
48
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\11\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
ColInfo
00000000000000000000000000000000FDDFDFFD100000000000000000000000010000001800000030F125B7EF471A10A5F102608C9EEBAC0A000000A0000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\11\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Sort
000000000000000000000000000000000100000030F125B7EF471A10A5F102608C9EEBAC0A00000001000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\11\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupView
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\11\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:FMTID
{00000000-0000-0000-0000-000000000000}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\11\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:PID
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\11\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByDirection
1
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\12\Shell\{C4D98F09-6124-4FE0-9942-826416082DA9}
Rev
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\12\Shell\{C4D98F09-6124-4FE0-9942-826416082DA9}
FFlags
1092616209
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\12\Shell\{C4D98F09-6124-4FE0-9942-826416082DA9}
Vid
{65F125E5-7BE1-4810-BA9D-D271C8432CE3}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\12\Shell\{C4D98F09-6124-4FE0-9942-826416082DA9}
Mode
6
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\12\Shell\{C4D98F09-6124-4FE0-9942-826416082DA9}
LogicalViewMode
2
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\12\Shell\{C4D98F09-6124-4FE0-9942-826416082DA9}
IconSize
48
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\12\Shell\{C4D98F09-6124-4FE0-9942-826416082DA9}
ColInfo
00000000000000000000000000000000FDDFDFFD100000000000000000000000040000001800000030F125B7EF471A10A5F102608C9EEBAC0A000000A000000030F125B7EF471A10A5F102608C9EEBAC0E0000007800000030F125B7EF471A10A5F102608C9EEBAC040000007800000030F125B7EF471A10A5F102608C9EEBAC0C00000050000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\12\Shell\{C4D98F09-6124-4FE0-9942-826416082DA9}
Sort
000000000000000000000000000000000100000030F125B7EF471A10A5F102608C9EEBAC0A00000001000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\12\Shell\{C4D98F09-6124-4FE0-9942-826416082DA9}
GroupView
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\12\Shell\{C4D98F09-6124-4FE0-9942-826416082DA9}
GroupByKey:FMTID
{00000000-0000-0000-0000-000000000000}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\12\Shell\{C4D98F09-6124-4FE0-9942-826416082DA9}
GroupByKey:PID
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\12\Shell\{C4D98F09-6124-4FE0-9942-826416082DA9}
GroupByDirection
1
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\13\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Rev
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\13\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
18874369
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\13\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Vid
{65F125E5-7BE1-4810-BA9D-D271C8432CE3}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\13\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Mode
6
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\13\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
LogicalViewMode
2
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\13\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
IconSize
48
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\13\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
ColInfo
00000000000000000000000000000000FDDFDFFD100000000000000000000000060000001800000030F125B7EF471A10A5F102608C9EEBAC0A000000F000000030F125B7EF471A10A5F102608C9EEBAC0C0000005000000030F125B7EF471A10A5F102608C9EEBAC04000000A000000030F125B7EF471A10A5F102608C9EEBAC0E000000A000000030F125B7EF471A10A5F102608C9EEBAC0F000000A000000030F125B7EF471A10A5F102608C9EEBAC10000000A0000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\13\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Sort
000000000000000000000000000000000100000030F125B7EF471A10A5F102608C9EEBAC0A00000001000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\13\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupView
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\13\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:FMTID
{00000000-0000-0000-0000-000000000000}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\13\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:PID
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\13\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByDirection
1
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\14\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Rev
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\14\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
18874369
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\14\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Vid
{65F125E5-7BE1-4810-BA9D-D271C8432CE3}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\14\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Mode
6
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\14\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
LogicalViewMode
2
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\14\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
IconSize
48
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\14\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
ColInfo
00000000000000000000000000000000FDDFDFFD100000000000000000000000060000001800000030F125B7EF471A10A5F102608C9EEBAC0A000000F000000030F125B7EF471A10A5F102608C9EEBAC0C0000005000000030F125B7EF471A10A5F102608C9EEBAC04000000A000000030F125B7EF471A10A5F102608C9EEBAC0E000000A000000030F125B7EF471A10A5F102608C9EEBAC0F000000A000000030F125B7EF471A10A5F102608C9EEBAC10000000A0000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\14\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Sort
000000000000000000000000000000000100000030F125B7EF471A10A5F102608C9EEBAC0A00000001000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\14\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupView
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\14\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:FMTID
{00000000-0000-0000-0000-000000000000}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\14\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:PID
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\14\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByDirection
1
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\15\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Rev
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\15\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
18874369
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\15\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Vid
{65F125E5-7BE1-4810-BA9D-D271C8432CE3}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\15\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Mode
6
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\15\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
LogicalViewMode
2
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\15\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
IconSize
48
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\15\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
ColInfo
00000000000000000000000000000000FDDFDFFD100000000000000000000000060000001800000030F125B7EF471A10A5F102608C9EEBAC0A000000F000000030F125B7EF471A10A5F102608C9EEBAC0C0000005000000030F125B7EF471A10A5F102608C9EEBAC04000000A000000030F125B7EF471A10A5F102608C9EEBAC0E000000A000000030F125B7EF471A10A5F102608C9EEBAC0F000000A000000030F125B7EF471A10A5F102608C9EEBAC10000000A0000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\15\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Sort
000000000000000000000000000000000100000030F125B7EF471A10A5F102608C9EEBAC0A00000001000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\15\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupView
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\15\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:FMTID
{00000000-0000-0000-0000-000000000000}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\15\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:PID
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\15\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByDirection
1
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\16\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Rev
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\16\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
18874369
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\16\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Vid
{65F125E5-7BE1-4810-BA9D-D271C8432CE3}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\16\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Mode
6
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\16\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
LogicalViewMode
2
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\16\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
IconSize
48
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\16\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
ColInfo
00000000000000000000000000000000FDDFDFFD100000000000000000000000060000001800000030F125B7EF471A10A5F102608C9EEBAC0A000000F000000030F125B7EF471A10A5F102608C9EEBAC0C0000005000000030F125B7EF471A10A5F102608C9EEBAC04000000A000000030F125B7EF471A10A5F102608C9EEBAC0E000000A000000030F125B7EF471A10A5F102608C9EEBAC0F000000A000000030F125B7EF471A10A5F102608C9EEBAC10000000A0000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\16\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Sort
000000000000000000000000000000000100000030F125B7EF471A10A5F102608C9EEBAC0A00000001000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\16\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupView
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\16\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:FMTID
{00000000-0000-0000-0000-000000000000}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\16\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:PID
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\16\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByDirection
1
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\17\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Rev
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\17\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
18874369
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\17\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Vid
{65F125E5-7BE1-4810-BA9D-D271C8432CE3}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\17\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Mode
6
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\17\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
LogicalViewMode
2
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\17\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
IconSize
48
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\17\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
ColInfo
00000000000000000000000000000000FDDFDFFD100000000000000000000000060000001800000030F125B7EF471A10A5F102608C9EEBAC0A000000F000000030F125B7EF471A10A5F102608C9EEBAC0C0000005000000030F125B7EF471A10A5F102608C9EEBAC04000000A000000030F125B7EF471A10A5F102608C9EEBAC0E000000A000000030F125B7EF471A10A5F102608C9EEBAC0F000000A000000030F125B7EF471A10A5F102608C9EEBAC10000000A0000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\17\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Sort
000000000000000000000000000000000100000030F125B7EF471A10A5F102608C9EEBAC0A00000001000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\17\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupView
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\17\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:FMTID
{00000000-0000-0000-0000-000000000000}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\17\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:PID
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\17\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByDirection
1
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\18\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Rev
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\18\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
18874369
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\18\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Vid
{65F125E5-7BE1-4810-BA9D-D271C8432CE3}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\18\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Mode
6
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\18\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
LogicalViewMode
2
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\18\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
IconSize
48
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\18\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
ColInfo
00000000000000000000000000000000FDDFDFFD100000000000000000000000060000001800000030F125B7EF471A10A5F102608C9EEBAC0A000000F000000030F125B7EF471A10A5F102608C9EEBAC0C0000005000000030F125B7EF471A10A5F102608C9EEBAC04000000A000000030F125B7EF471A10A5F102608C9EEBAC0E000000A000000030F125B7EF471A10A5F102608C9EEBAC0F000000A000000030F125B7EF471A10A5F102608C9EEBAC10000000A0000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\18\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Sort
000000000000000000000000000000000100000030F125B7EF471A10A5F102608C9EEBAC0A00000001000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\18\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupView
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\18\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:FMTID
{00000000-0000-0000-0000-000000000000}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\18\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:PID
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\18\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByDirection
1
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\19\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Rev
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\19\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
18874369
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\19\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Vid
{65F125E5-7BE1-4810-BA9D-D271C8432CE3}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\19\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Mode
6
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\19\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
LogicalViewMode
2
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\19\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
IconSize
48
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\19\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
ColInfo
00000000000000000000000000000000FDDFDFFD100000000000000000000000060000001800000030F125B7EF471A10A5F102608C9EEBAC0A000000F000000030F125B7EF471A10A5F102608C9EEBAC0C0000005000000030F125B7EF471A10A5F102608C9EEBAC04000000A000000030F125B7EF471A10A5F102608C9EEBAC0E000000A000000030F125B7EF471A10A5F102608C9EEBAC0F000000A000000030F125B7EF471A10A5F102608C9EEBAC10000000A0000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\19\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Sort
000000000000000000000000000000000100000030F125B7EF471A10A5F102608C9EEBAC0A00000001000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\19\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupView
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\19\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:FMTID
{00000000-0000-0000-0000-000000000000}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\19\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:PID
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\19\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByDirection
1
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\2\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Rev
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\2\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
18874385
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\2\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Vid
{65F125E5-7BE1-4810-BA9D-D271C8432CE3}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\2\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Mode
6
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\2\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
LogicalViewMode
2
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\2\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
IconSize
48
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\2\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
ColInfo
00000000000000000000000000000000FDDFDFFD100000000000000000000000010000001800000030F125B7EF471A10A5F102608C9EEBAC0A000000A0000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\2\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Sort
000000000000000000000000000000000100000030F125B7EF471A10A5F102608C9EEBAC0A00000001000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\2\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupView
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\2\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:FMTID
{00000000-0000-0000-0000-000000000000}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\2\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:PID
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\2\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByDirection
1
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\20\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Rev
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\20\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
18874369
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\20\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Vid
{65F125E5-7BE1-4810-BA9D-D271C8432CE3}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\20\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Mode
6
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\20\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
LogicalViewMode
2
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\20\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
IconSize
48
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\20\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
ColInfo
00000000000000000000000000000000FDDFDFFD100000000000000000000000060000001800000030F125B7EF471A10A5F102608C9EEBAC0A000000F000000030F125B7EF471A10A5F102608C9EEBAC0C0000005000000030F125B7EF471A10A5F102608C9EEBAC04000000A000000030F125B7EF471A10A5F102608C9EEBAC0E000000A000000030F125B7EF471A10A5F102608C9EEBAC0F000000A000000030F125B7EF471A10A5F102608C9EEBAC10000000A0000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\20\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Sort
000000000000000000000000000000000100000030F125B7EF471A10A5F102608C9EEBAC0A00000001000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\20\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupView
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\20\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:FMTID
{00000000-0000-0000-0000-000000000000}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\20\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:PID
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\20\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByDirection
1
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\21\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Rev
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\21\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
18874369
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\21\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Vid
{65F125E5-7BE1-4810-BA9D-D271C8432CE3}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\21\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Mode
6
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\21\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
LogicalViewMode
2
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\21\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
IconSize
48
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\21\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
ColInfo
00000000000000000000000000000000FDDFDFFD100000000000000000000000060000001800000030F125B7EF471A10A5F102608C9EEBAC0A000000F000000030F125B7EF471A10A5F102608C9EEBAC0C0000005000000030F125B7EF471A10A5F102608C9EEBAC04000000A000000030F125B7EF471A10A5F102608C9EEBAC0E000000A000000030F125B7EF471A10A5F102608C9EEBAC0F000000A000000030F125B7EF471A10A5F102608C9EEBAC10000000A0000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\21\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Sort
000000000000000000000000000000000100000030F125B7EF471A10A5F102608C9EEBAC0A00000001000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\21\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupView
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\21\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:FMTID
{00000000-0000-0000-0000-000000000000}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\21\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:PID
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\21\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByDirection
1
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\22\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Rev
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\22\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
18874385
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\22\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Vid
{65F125E5-7BE1-4810-BA9D-D271C8432CE3}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\22\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Mode
6
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\22\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
LogicalViewMode
2
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\22\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
IconSize
48
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\22\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
ColInfo
00000000000000000000000000000000FDDFDFFD100000000000000000000000010000001800000030F125B7EF471A10A5F102608C9EEBAC0A000000A0000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\22\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Sort
000000000000000000000000000000000100000030F125B7EF471A10A5F102608C9EEBAC0A00000001000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\22\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupView
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\22\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:FMTID
{00000000-0000-0000-0000-000000000000}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\22\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:PID
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\22\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByDirection
1
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\23\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Rev
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\23\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
18874369
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\23\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Vid
{65F125E5-7BE1-4810-BA9D-D271C8432CE3}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\23\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Mode
6
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\23\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
LogicalViewMode
2
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\23\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
IconSize
48
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\23\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
ColInfo
00000000000000000000000000000000FDDFDFFD100000000000000000000000080000001800000030F125B7EF471A10A5F102608C9EEBAC0A00000040010000AC055E9E3619754A94F74704B8B0192301000000C0000000AC055E9E3619754A94F74704B8B0192302000000C0000000AC055E9E3619754A94F74704B8B0192303000000C0000000AC055E9E3619754A94F74704B8B0192304000000C0000000AC055E9E3619754A94F74704B8B0192305000000C0000000AC055E9E3619754A94F74704B8B0192306000000C0000000AC055E9E3619754A94F74704B8B0192307000000C0000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\23\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Sort
000000000000000000000000000000000100000030F125B7EF471A10A5F102608C9EEBAC0A00000001000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\23\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupView
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\23\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:FMTID
{00000000-0000-0000-0000-000000000000}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\23\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:PID
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\23\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByDirection
1
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\24\Shell
KnownFolderDerivedFolderType
{57807898-8C4F-4462-BB63-71042380B109}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\24\Shell
SniffedFolderType
Generic
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\24\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Rev
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\24\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
1092616209
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\24\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Vid
{137E7700-3573-11CF-AE69-08002B2E1262}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\24\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Mode
4
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\24\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
LogicalViewMode
1
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\24\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
IconSize
16
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\24\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
ColInfo
00000000000000000000000000000000FDDFDFFD100000000000000000000000040000001800000030F125B7EF471A10A5F102608C9EEBAC0A0000001001000030F125B7EF471A10A5F102608C9EEBAC0E0000007800000030F125B7EF471A10A5F102608C9EEBAC040000007800000030F125B7EF471A10A5F102608C9EEBAC0C00000050000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\24\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Sort
000000000000000000000000000000000100000030F125B7EF471A10A5F102608C9EEBAC0A00000001000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\24\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupView
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\24\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:FMTID
{00000000-0000-0000-0000-000000000000}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\24\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:PID
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\24\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByDirection
1
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\25\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Rev
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\25\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
18874385
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\25\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Vid
{65F125E5-7BE1-4810-BA9D-D271C8432CE3}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\25\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Mode
6
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\25\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
LogicalViewMode
2
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\25\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
IconSize
48
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\25\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
ColInfo
00000000000000000000000000000000FDDFDFFD100000000000000000000000010000001800000030F125B7EF471A10A5F102608C9EEBAC0A000000A0000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\25\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Sort
000000000000000000000000000000000100000030F125B7EF471A10A5F102608C9EEBAC0A00000001000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\25\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupView
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\25\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:FMTID
{00000000-0000-0000-0000-000000000000}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\25\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:PID
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\25\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByDirection
1
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\26\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Rev
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\26\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
18874369
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\26\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Vid
{65F125E5-7BE1-4810-BA9D-D271C8432CE3}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\26\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Mode
6
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\26\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
LogicalViewMode
2
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\26\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
IconSize
48
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\26\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
ColInfo
00000000000000000000000000000000FDDFDFFD100000000000000000000000060000001800000030F125B7EF471A10A5F102608C9EEBAC0A000000F000000030F125B7EF471A10A5F102608C9EEBAC0C0000005000000030F125B7EF471A10A5F102608C9EEBAC04000000A000000030F125B7EF471A10A5F102608C9EEBAC0E000000A000000030F125B7EF471A10A5F102608C9EEBAC0F000000A000000030F125B7EF471A10A5F102608C9EEBAC10000000A0000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\26\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Sort
000000000000000000000000000000000100000030F125B7EF471A10A5F102608C9EEBAC0A00000001000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\26\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupView
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\26\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:FMTID
{00000000-0000-0000-0000-000000000000}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\26\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:PID
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\26\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByDirection
1
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\27\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Rev
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\27\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
1092616209
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\27\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Vid
{65F125E5-7BE1-4810-BA9D-D271C8432CE3}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\27\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Mode
6
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\27\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
LogicalViewMode
2
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\27\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
IconSize
48
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\27\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
ColInfo
00000000000000000000000000000000FDDFDFFD100000000000000000000000040000001800000030F125B7EF471A10A5F102608C9EEBAC0A000000A000000030F125B7EF471A10A5F102608C9EEBAC04000000C8000000354B179BFF40D211A27E00C04FC308710300000080000000354B179BFF40D211A27E00C04FC308710200000080000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\27\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Sort
000000000000000000000000000000000100000030F125B7EF471A10A5F102608C9EEBAC0A00000001000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\27\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupView
4294967295
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\27\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:FMTID
{B725F130-47EF-101A-A5F1-02608C9EEBAC}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\27\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:PID
4
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\27\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByDirection
1
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\27\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupCollapseState
000000000000000000000000000000000000000000000000000000000000000001000000110000000000000011000000480061007200640020004400690073006B0020004400720069007600650073000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\28\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Rev
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\28\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
18874385
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\28\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Vid
{65F125E5-7BE1-4810-BA9D-D271C8432CE3}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\28\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Mode
6
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\28\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
LogicalViewMode
2
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\28\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
IconSize
48
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\28\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
ColInfo
00000000000000000000000000000000FDDFDFFD100000000000000000000000010000001800000030F125B7EF471A10A5F102608C9EEBAC0A000000A0000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\28\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Sort
000000000000000000000000000000000100000030F125B7EF471A10A5F102608C9EEBAC0A00000001000000
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\28\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupView
0
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\28\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:FMTID
{00000000-0000-0000-0000-000000000000}
2328
Setup(password=spytech).exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\28\Shell\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:P