General Info

File name

iguana2

Full analysis
https://app.any.run/tasks/ca44ad38-0e46-455e-8cfd-42fb53d41a1d
Verdict
Malicious activity
Analysis date
5/19/2020, 13:24:12
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
text/plain
File info:
ASCII text, with very long lines, with no line terminators
MD5

b1f0093b89561c6123070165bd2261e2

SHA1

aac57162dc1311f07a869f7163bd30e0d62dcc0e

SHA256

f4656a9af30e98ed2103194f798fa00fd1686618e3e62fba6b15c9959135b7be

SSDEEP

24576:3lWHR7hoxn6yTYo1oc8UcMIh/MuwL+zn4ltC3O+wXCwNLaLRcfIAM1Bq9p0IQWwS:l

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
300 seconds
Additional time used
240 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 11.0.9600.17843 KB3058515
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (75.0.3770.100)
  • Google Update Helper (1.3.34.7)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.7.2 (4.7.03062)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Access MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Excel MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Groove MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Groove MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office IME (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office IME (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office InfoPath MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Language Pack 2010 - French/Français (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - German/Deutsch (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Italian/Italiano (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Japanese/日本語 (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Korean/한국어 (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Portuguese/Português (Brasil) (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Russian/русский (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Spanish/Español (14.0.4763.1000)
  • Microsoft Office Language Pack 2010 - Turkish/Türkçe (14.0.4763.1013)
  • Microsoft Office O MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office O MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office OneNote MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Outlook MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office PowerPoint MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Arabic) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Basque) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Catalan) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Dutch) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Galician) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (German) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Proof (Ukrainian) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (French) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (German) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Proofing (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Publisher MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office SharePoint Designer MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office SharePoint Designer MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Shared MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office Word MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Office X MUI (French) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (German) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Italian) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Japanese) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Korean) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Portuguese (Brazil)) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Russian) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Spanish) 2010 (14.0.4763.1000)
  • Microsoft Office X MUI (Turkish) 2010 (14.0.4763.1013)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (14.21.27702.2)
  • Microsoft Visual C++ 2019 X86 Additional Runtime - 14.21.27702 (14.21.27702)
  • Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.21.27702 (14.21.27702)
  • Mozilla Firefox 68.0.1 (x86 en-US) (68.0.1)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • QGA (2.10.63)
  • Skype version 8.29 (8.29)
  • Update for Microsoft .NET Framework 4.7.2 (KB4087364) (1)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Hyphenation Parent Package English
  • IE Spelling Parent Package English
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • InternetExplorer Package TopLevel
  • KB2533623
  • KB2534111
  • KB2639308
  • KB2729094
  • KB2731771
  • KB2786081
  • KB2834140
  • KB2882822
  • KB2888049
  • KB2999226
  • KB4019990
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • PlatformUpdate Win7 SRV08R2 Package TopLevel
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Actions looks like stealing of personal data
  • rundll32.exe (PID: 4008)
  • rundll32.exe (PID: 3748)
Uses RUNDLL32.EXE to load library
  • powershell.exe (PID: 2600)
  • powershell.exe (PID: 3220)
Starts Internet Explorer
  • rundll32.exe (PID: 4012)
Executes PowerShell scripts
  • rundll32.exe (PID: 4008)
  • rundll32.exe (PID: 3748)
Creates files in the user directory
  • powershell.exe (PID: 3220)
  • powershell.exe (PID: 2600)
Reads Internet Cache Settings
  • iexplore.exe (PID: 2828)
  • iexplore.exe (PID: 2364)
Application launched itself
  • iexplore.exe (PID: 2828)
  • iexplore.exe (PID: 3232)
Modifies the open verb of a shell class
  • rundll32.exe (PID: 3748)
Changes internet zones settings
  • iexplore.exe (PID: 2828)
Reads internet explorer settings
  • iexplore.exe (PID: 3232)
Creates files in the user directory
  • iexplore.exe (PID: 2828)
Manual execution by user
  • rundll32.exe (PID: 4088)
Reads settings of System Certificates
  • iexplore.exe (PID: 2828)
Changes settings of System certificates
  • iexplore.exe (PID: 2828)
Adds / modifies Windows certificates
  • iexplore.exe (PID: 2828)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

Screenshots

Processes

Total processes
52
Monitored processes
9
Malicious processes
3
Suspicious processes
0

Behavior graph

+
start rundll32.exe powershell.exe no specs rundll32.exe powershell.exe no specs rundll32.exe no specs iexplore.exe iexplore.exe no specs iexplore.exe no specs rundll32.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3748
CMD
"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\iguana2
Path
C:\Windows\system32\rundll32.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows host process (Rundll32)
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\imagehlp.dll
c:\windows\system32\mpr.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\winspool.drv
c:\windows\system32\sechost.dll
c:\windows\system32\imm32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\rundll32.exe
c:\windows\system32\ole32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\profapi.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\usp10.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\uxtheme.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\gdi32.dll
c:\systemroot\system32\ntdll.dll
c:\windows\system32\userenv.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\imageres.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\slc.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\program files\adobe\acrobat reader dc\reader\acrord32.exe
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\version.dll
c:\windows\system32\mspaint.exe
c:\windows\ehome\ehshell.exe
c:\program files\internet explorer\iexplore.exe
c:\program files\windows photo viewer\photoviewer.dll
c:\windows\notepad.exe
c:\progra~1\micros~1\office14\ois.exe
c:\program files\opera\opera.exe
c:\program files\microsoft office\office14\winword.exe
c:\program files\videolan\vlc\vlc.exe
c:\program files\windows media player\wmplayer.exe
c:\program files\windows nt\accessories\wordpad.exe
c:\windows\system32\wmploc.dll
c:\windows\system32\comdlg32.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\duser.dll
c:\windows\system32\msftedit.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\dui70.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\msls31.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\structuredquery.dll
c:\windows\system32\secur32.dll
c:\windows\system32\wmasf.dll
c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
c:\windows\system32\thumbcache.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
c:\windows\system32\winsta.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\searchfolder.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\winmm.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\netutils.dll
c:\windows\system32\portabledeviceapi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\shdocvw.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\audiodev.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
c:\windows\system32\wmvcore.dll
c:\windows\system32\actxprxy.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\drprov.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\networkexplorer.dll
c:\windows\system32\ehstorapi.dll
c:\windows\explorer.exe
c:\windows\fveupdate.exe
c:\windows\hh.exe
c:\windows\bfsvc.exe
c:\windows\helppane.exe
c:\windows\alcrmv.exe
c:\windows\system32\acppage.dll
c:\windows\system32\aitagent.exe
c:\windows\system32\atbroker.exe
c:\windows\system32\at.exe
c:\windows\system32\arp.exe
c:\windows\system32\adaptertroubleshooter.exe
c:\windows\system32\appidpolicyconverter.exe
c:\windows\system32\alg.exe
c:\windows\system32\appidcertstorecheck.exe
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\windowspowershell\v1.0\powershell_ise.exe
c:\windows\system32\urlmon.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
c:\windows\system32\wininet.dll
c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll

PID
2600
CMD
"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "C:\Users\admin\Desktop\iguana2"
Path
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
Indicators
No indicators
Parent process
rundll32.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows PowerShell
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\atl.dll
c:\windows\system32\propsys.dll
c:\windows\system32\sechost.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\shell32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\userenv.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\lpk.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\wldap32.dll
c:\systemroot\system32\ntdll.dll
c:\windows\system32\ole32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\devobj.dll
c:\windows\assembly\gac_msil\system.management.automation\1.0.0.0__31bf3856ad364e35\system.management.automation.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.powershel#\4bdde288f147e3b3f2c090ecdf704e6d\microsoft.powershell.consolehost.ni.dll
c:\windows\system32\slc.dll
c:\windows\system32\cscapi.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system\9e0a3b9b9f457233a335d7fba8f95419\system.ni.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.management.a#\a8e3a41ecbcc4bb1598ed5719f965110\system.management.automation.ni.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\rsaenh.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\version.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorjit.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\wininet.dll
c:\windows\assembly\gac_msil\microsoft.wsman.runtime\1.0.0.0__31bf3856ad364e35\microsoft.wsman.runtime.dll
c:\windows\system32\psapi.dll
c:\windows\assembly\gac_32\system.transactions\2.0.0.0__b77a5c561934e089\system.transactions.dll
c:\windows\microsoft.net\framework\v2.0.50727\culture.dll
c:\windows\assembly\gac_32\system.data\2.0.0.0__b77a5c561934e089\system.data.dll
c:\windows\system32\msasn1.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.powershel#\e112e4460a0c9122de8c382126da4a2f\microsoft.powershell.commands.diagnostics.ni.dll
c:\windows\system32\netutils.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.xml\461d3b6b3f43e6fbe6c897d5936e17e4\system.xml.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.management\6f3b99ed0b791ff4d8aa52f2f0cd0bcf\system.management.ni.dll
c:\windows\system32\secur32.dll
c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.powershel#\583c7b9f52114c026088bdb9f19f64e8\microsoft.powershell.commands.management.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.powershel#\6c5bef3ab74c06a641444eff648c0dde\microsoft.powershell.security.ni.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.transactions\ad18f93fc713db2c4b29b25116c13bd8\system.transactions.ni.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.configuratio#\f02737c83305687a68c088927a6c5a98\system.configuration.install.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.wsman.man#\f1865caa683ceb3d12b383a94a35da14\microsoft.wsman.management.ni.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\rundll32.exe
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\nsi.dll
c:\windows\system32\crypt32.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.core\fbc05b5b05dc6366b02b8e2f77d080f1\system.core.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.powershel#\82d7758f278f47dc4191abab1cb11ce3\microsoft.powershell.commands.utility.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.directoryser#\45ec12795950a7d54691591c615a9e3c\system.directoryservices.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.data\1e85062785e286cd9eae9c26d2c61f73\system.data.ni.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll

PID
4008
CMD
"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\iguana2
Path
C:\Windows\system32\rundll32.exe
Indicators
Parent process
powershell.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows host process (Rundll32)
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\gdi32.dll
c:\windows\system32\mpr.dll
c:\windows\system32\usp10.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\userenv.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\winspool.drv
c:\windows\system32\shlwapi.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
c:\windows\system32\user32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\imageres.dll
c:\program files\videolan\vlc\vlc.exe
c:\program files\opera\opera.exe
c:\progra~1\micros~1\office14\ois.exe
c:\windows\system32\mspaint.exe
c:\windows\system32\cryptbase.dll
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\program files\windows photo viewer\photoviewer.dll
c:\windows\system32\windowscodecs.dll
c:\program files\adobe\acrobat reader dc\reader\acrord32.exe
c:\windows\ehome\ehshell.exe
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\version.dll
c:\windows\notepad.exe
c:\windows\system32\clbcatq.dll
c:\program files\microsoft office\office14\winword.exe
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\advapi32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\windows\system32\wldap32.dll
c:\program files\windows media player\wmplayer.exe
c:\program files\windows nt\accessories\wordpad.exe
c:\windows\system32\comdlg32.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\msftedit.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\secur32.dll
c:\windows\system32\duser.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
c:\windows\system32\searchfolder.dll
c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
c:\windows\system32\thumbcache.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\actxprxy.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\psapi.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\msls31.dll
c:\windows\system32\structuredquery.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\dui70.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\audiodev.dll
c:\windows\system32\davhlpr.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\drprov.dll
c:\windows\system32\netutils.dll
c:\windows\system32\winmm.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\portabledeviceapi.dll
c:\windows\system32\networkexplorer.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\winsta.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\wmvcore.dll
c:\windows\system32\ehstorapi.dll
c:\windows\system32\wmasf.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll

PID
3220
CMD
"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "C:\Users\admin\Desktop\iguana2"
Path
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
Indicators
No indicators
Parent process
rundll32.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows PowerShell
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\atl.dll
c:\windows\system32\shell32.dll
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\usp10.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\userenv.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\systemroot\system32\ntdll.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\imm32.dll
c:\windows\system32\propsys.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\user32.dll
c:\windows\system32\cscapi.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.wsman.man#\f1865caa683ceb3d12b383a94a35da14\microsoft.wsman.management.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.management\6f3b99ed0b791ff4d8aa52f2f0cd0bcf\system.management.ni.dll
c:\windows\assembly\gac_msil\system.management.automation\1.0.0.0__31bf3856ad364e35\system.management.automation.dll
c:\windows\system32\cryptsp.dll
c:\windows\microsoft.net\framework\v2.0.50727\culture.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.xml\461d3b6b3f43e6fbe6c897d5936e17e4\system.xml.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.powershel#\6c5bef3ab74c06a641444eff648c0dde\microsoft.powershell.security.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.management.a#\a8e3a41ecbcc4bb1598ed5719f965110\system.management.automation.ni.dll
c:\windows\system32\ntshrui.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.powershel#\4bdde288f147e3b3f2c090ecdf704e6d\microsoft.powershell.consolehost.ni.dll
c:\windows\assembly\gac_msil\microsoft.wsman.runtime\1.0.0.0__31bf3856ad364e35\microsoft.wsman.runtime.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.powershel#\583c7b9f52114c026088bdb9f19f64e8\microsoft.powershell.commands.management.ni.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\psapi.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system\9e0a3b9b9f457233a335d7fba8f95419\system.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.core\fbc05b5b05dc6366b02b8e2f77d080f1\system.core.ni.dll
c:\windows\assembly\gac_32\system.transactions\2.0.0.0__b77a5c561934e089\system.transactions.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\slc.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.powershel#\e112e4460a0c9122de8c382126da4a2f\microsoft.powershell.commands.diagnostics.ni.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\srvcli.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.configuratio#\f02737c83305687a68c088927a6c5a98\system.configuration.install.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.directoryser#\45ec12795950a7d54691591c615a9e3c\system.directoryservices.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.transactions\ad18f93fc713db2c4b29b25116c13bd8\system.transactions.ni.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\version.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\microsoft.powershel#\82d7758f278f47dc4191abab1cb11ce3\microsoft.powershell.commands.utility.ni.dll
c:\windows\assembly\gac_32\system.data\2.0.0.0__b77a5c561934e089\system.data.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\wininet.dll
c:\windows\system32\rundll32.exe
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorjit.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.data\1e85062785e286cd9eae9c26d2c61f73\system.data.ni.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\nsi.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
c:\windows\system32\secur32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll

PID
4012
CMD
"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\iguana2
Path
C:\Windows\system32\rundll32.exe
Indicators
No indicators
Parent process
powershell.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows host process (Rundll32)
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\kernel32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\userenv.dll
c:\program files\microsoft office\office14\winword.exe
c:\windows\system32\lpk.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\devobj.dll
c:\windows\system32\imageres.dll
c:\program files\windows nt\accessories\wordpad.exe
c:\windows\system32\user32.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\mspaint.exe
c:\windows\system32\shell32.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\apphelp.dll
c:\windows\system32\sspicli.dll
c:\windows\ehome\ehshell.exe
c:\program files\videolan\vlc\vlc.exe
c:\program files\windows media player\wmplayer.exe
c:\windows\system32\usp10.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\slc.dll
c:\program files\adobe\acrobat reader dc\reader\acrord32.exe
c:\windows\system32\msctf.dll
c:\program files\opera\opera.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\profapi.dll
c:\program files\internet explorer\iexplore.exe
c:\windows\notepad.exe
c:\windows\system32\wldap32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\winspool.drv
c:\progra~1\micros~1\office14\ois.exe
c:\program files\windows photo viewer\photoviewer.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\mpr.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\version.dll
c:\windows\system32\rundll32.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\cscui.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\wininet.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
c:\windows\system32\secur32.dll
c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\netutils.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll

PID
2828
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" C:\Users\admin\Desktop\iguana2
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
rundll32.exe
User
admin
Integrity Level
MEDIUM
Exit code
1
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Image
c:\windows\system32\normaliz.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\imm32.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
c:\windows\system32\ntmarta.dll
c:\systemroot\system32\ntdll.dll
c:\windows\system32\lpk.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\wininet.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wship6.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\propsys.dll
c:\windows\system32\version.dll
c:\program files\internet explorer\ieshims.dll
c:\windows\system32\webio.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
c:\windows\system32\msctf.dll
c:\windows\system32\shell32.dll
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\ole32.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\usp10.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\devobj.dll
c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
c:\windows\system32\secur32.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\dui70.dll
c:\windows\system32\duser.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\ieui.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\sxs.dll
c:\windows\system32\macromed\flash\flash32_26_0_0_131.ocx
c:\windows\system32\ntshrui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\imageres.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\ehstorshell.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\slc.dll
c:\windows\system32\cscui.dll
c:\windows\system32\mlang.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\schannel.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\credssp.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\tquery.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\structuredquery.dll
c:\windows\system32\netutils.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\wpc.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\sensapi.dll

PID
3232
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2828 CREDAT:144385 /prefetch:2
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
No indicators
Parent process
iexplore.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Image
c:\windows\system32\kernelbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\ieui.dll
c:\windows\system32\devobj.dll
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\iertutil.dll
c:\program files\internet explorer\ieproxy.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\dwrite.dll
c:\windows\system32\cfgmgr32.dll
c:\program files\internet explorer\ieshims.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\webio.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
c:\windows\system32\userenv.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\lpk.dll
c:\windows\system32\imm32.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\shell32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\ole32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\d2d1.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\nsi.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
c:\windows\system32\wininet.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\wship6.dll
c:\systemroot\system32\ntdll.dll
c:\windows\system32\version.dll
c:\windows\system32\usp10.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\jscript9.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\propsys.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\d3d10warp.dll
c:\windows\system32\mlang.dll
c:\windows\system32\d3d11.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\sxs.dll

PID
2364
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2828 CREDAT:333057 /prefetch:2
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
No indicators
Parent process
iexplore.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
11.00.9600.16428 (winblue_gdr.131013-1700)
Modules
Image
c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\usp10.dll
c:\windows\system32\profapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\user32.dll
c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
c:\program files\internet explorer\ieshims.dll
c:\windows\system32\version.dll
c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\userenv.dll
c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
c:\windows\system32\ole32.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\gdi32.dll
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\systemroot\system32\ntdll.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\webio.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\ws2_32.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\wship6.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mswsock.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll

PID
4088
CMD
"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\iguana2
Path
C:\Windows\system32\rundll32.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Windows host process (Rundll32)
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\apphelp.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\usp10.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\rundll32.exe
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\kernel32.dll
c:\windows\apppatch\aclayers.dll
c:\systemroot\system32\ntdll.dll
c:\windows\system32\shell32.dll
c:\windows\system32\winspool.drv
c:\windows\system32\rpcrt4.dll
c:\windows\system32\profapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\mpr.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\propsys.dll
c:\windows\system32\devobj.dll
c:\windows\system32\imageres.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\cscui.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\ehome\ehshell.exe
c:\program files\adobe\acrobat reader dc\reader\acrord32.exe
c:\program files\internet explorer\iexplore.exe
c:\windows\system32\version.dll
c:\windows\system32\mspaint.exe
c:\windows\notepad.exe
c:\program files\opera\opera.exe
c:\progra~1\micros~1\office14\ois.exe
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\program files\windows photo viewer\photoviewer.dll
c:\program files\videolan\vlc\vlc.exe
c:\program files\microsoft office\office14\winword.exe
c:\program files\windows media player\wmplayer.exe
c:\program files\windows nt\accessories\wordpad.exe

Registry activity

Total events
10345
Read events
3053
Write events
5049
Delete events
2243

Modification events

PID
Process
Operation
Key
Name
Value
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Program Files\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe
Adobe Acrobat Reader DC
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Windows\eHome\ehshell.exe
Windows Media Center
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Windows\system32\mspaint.exe
Paint
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Windows\system32\NOTEPAD.EXE
Notepad
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\PROGRA~1\MICROS~1\Office14\OIS.EXE
Microsoft Office 2010
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Program Files\Opera\Opera.exe
Opera Internet Browser
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Program Files\Windows Photo Viewer\PhotoViewer.dll
Windows Photo Viewer
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Program Files\VideoLAN\VLC\vlc.exe
VLC media player
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Program Files\Microsoft Office\Office14\WINWORD.EXE
Microsoft Word
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12D\52C64B7E
LanguageList
en-US
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Program Files\Windows Media Player\wmplayer.exe
Windows Media Player
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
WordPad
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12D\52C64B7E
@wmploc.dll,-102
Windows Media Player
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0
MRUListEx
0100000004000000000000000200000003000000FFFFFFFF
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
NodeSlots
02020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
MRUListEx
0100000002000000000000000A00000007000000090000000800000006000000030000000500000004000000FFFFFFFF
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\35\Shell
SniffedFolderType
Generic
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12D\52C64B7E
@C:\Windows\system32\NetworkExplorer.dll,-1
Network
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\35\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
LogicalViewMode
1
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\35\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
IconSize
16
3748
rundll32.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CIDOpen\Modules\GlobalSettings\ProperTreeModuleInner
ProperTreeModuleInner
9C000000980000003153505305D5CDD59C2E1B10939708002B2CF9AE3B0000002A000000004E0061007600500061006E0065005F004300460044005F0046006900720073007400520075006E0000000B000000000000004100000030000000004E0061007600500061006E0065005F00530068006F0077004C00690062007200610072007900500061006E00650000000B000000FFFF00000000000000000000
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\35\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
ColInfo
00000000000000000000000000000000FDDFDFFD100000000000000000000000040000001800000030F125B7EF471A10A5F102608C9EEBAC0A0000001001000030F125B7EF471A10A5F102608C9EEBAC0E0000007800000030F125B7EF471A10A5F102608C9EEBAC040000007800000030F125B7EF471A10A5F102608C9EEBAC0C00000050000000
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\35\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
1092616257
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\34\Shell
SniffedFolderType
Generic
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\35\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Mode
4
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\35\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByDirection
1
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\35\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupView
0
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\35\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:FMTID
{00000000-0000-0000-0000-000000000000}
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\35\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
1
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\35\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Sort
000000000000000000000000000000000100000030F125B7EF471A10A5F102608C9EEBAC0A00000001000000
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\35\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:PID
0
3748
rundll32.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Modules\NavPane
ExpandedState
06000000160014001F8080A63C324DC29940B94D446DD2D7249E0000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000160014001F4225481E03947BC34DB131E946B44C8DD50000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000160014001F43983FFBB4EAC18D42A78AD1F5659CBA930000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D0000000000000000002000000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000160014001F580D1A2CF021BE504388B07367FC96EF3C0000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B00000000000000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000160014001F50E04FD020EA3A6910A2D808002B30309D0000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\34\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByDirection
1
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\36\Shell
SniffedFolderType
Generic
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\34\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Sort
000000000000000000000000000000000100000030F125B7EF471A10A5F102608C9EEBAC0A00000001000000
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\34\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Mode
4
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\34\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupView
0
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\34\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
ColInfo
00000000000000000000000000000000FDDFDFFD100000000000000000000000040000001800000030F125B7EF471A10A5F102608C9EEBAC0A0000001001000030F125B7EF471A10A5F102608C9EEBAC0E0000007800000030F125B7EF471A10A5F102608C9EEBAC040000007800000030F125B7EF471A10A5F102608C9EEBAC0C00000050000000
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\34\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:FMTID
{00000000-0000-0000-0000-000000000000}
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\34\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
LogicalViewMode
1
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\34\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:PID
0
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\34\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
1092616257
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\34\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
IconSize
16
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\34\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
1
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0
MRUListEx
0200000001000000040000000000000003000000FFFFFFFF
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12D\52C64B7E
@C:\Windows\System32\acppage.dll,-6005
Shortcut to MS-DOS Program
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\36\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Mode
4
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\36\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
LogicalViewMode
1
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\36\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Sort
000000000000000000000000000000000100000030F125B7EF471A10A5F102608C9EEBAC0A00000001000000
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\Shell
SniffedFolderType
Generic
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\36\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByDirection
1
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\36\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
ColInfo
00000000000000000000000000000000FDDFDFFD100000000000000000000000040000001800000030F125B7EF471A10A5F102608C9EEBAC0A0000001001000030F125B7EF471A10A5F102608C9EEBAC0E0000007800000030F125B7EF471A10A5F102608C9EEBAC040000007800000030F125B7EF471A10A5F102608C9EEBAC0C00000050000000
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\36\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupView
0
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\36\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:PID
0
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\36\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:FMTID
{00000000-0000-0000-0000-000000000000}
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\36\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
IconSize
16
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\36\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
1
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\36\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
1092616257
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
IconSize
16
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
1
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
NodeSlots
0202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\119\Shell
SniffedFolderType
Generic
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
LogicalViewMode
1
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Sort
000000000000000000000000000000000100000030F125B7EF471A10A5F102608C9EEBAC0A00000001000000
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:FMTID
{00000000-0000-0000-0000-000000000000}
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupView
0
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\2\1
2
6800310000000000EE3A9026100057494E444F577E310000500008000400EFBEEE3A9026EE3A90262A000000FD0A0000000001000000000000000000000000000000570069006E0064006F007700730050006F007700650072005300680065006C006C00000018000000
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\119\Shell
KnownFolderDerivedFolderType
{57807898-8C4F-4462-BB63-71042380B109}
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Mode
4
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
ColInfo
00000000000000000000000000000000FDDFDFFD100000000000000000000000040000001800000030F125B7EF471A10A5F102608C9EEBAC0A0000001001000030F125B7EF471A10A5F102608C9EEBAC0E0000007800000030F125B7EF471A10A5F102608C9EEBAC040000007800000030F125B7EF471A10A5F102608C9EEBAC0C00000050000000
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\2\1\2
MRUListEx
FFFFFFFF
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\2\1\2
NodeSlot
119
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByDirection
1
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:PID
0
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\2\1
MRUListEx
020000000100000000000000FFFFFFFF
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\95\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
1092616257
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\2\1\2
MRUListEx
00000000FFFFFFFF
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\119\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
1
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
NodeSlots
020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\119\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Mode
4
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\119\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByDirection
1
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\2\1\2\0
NodeSlot
120
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\2\1\2
0
4A003100000000008C3E0112100076312E300000360008000400EFBEEE3A90268C3E01122A000000FE0A0000000001000000000000000000000000000000760031002E003000000014000000
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\120\Shell
KnownFolderDerivedFolderType
{57807898-8C4F-4462-BB63-71042380B109}
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\119\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Sort
000000000000000000000000000000000100000030F125B7EF471A10A5F102608C9EEBAC0A00000001000000
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\119\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupView
0
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\119\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:FMTID
{00000000-0000-0000-0000-000000000000}
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\119\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:PID
0
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\2\1\2\0
MRUListEx
FFFFFFFF
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\119\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
LogicalViewMode
1
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\119\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
1092616257
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\119\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
IconSize
16
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\119\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
ColInfo
00000000000000000000000000000000FDDFDFFD100000000000000000000000040000001800000030F125B7EF471A10A5F102608C9EEBAC0A0000001001000030F125B7EF471A10A5F102608C9EEBAC0E0000007800000030F125B7EF471A10A5F102608C9EEBAC040000007800000030F125B7EF471A10A5F102608C9EEBAC0C00000050000000
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\120\Shell
SniffedFolderType
Generic
3748
rundll32.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedPidlMRU
MRUListEx
0100000000000000FFFFFFFF
3748
rundll32.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedPidlMRU
1
720075006E0064006C006C00330032002E00650078006500000014001F50E04FD020EA3A6910A2D808002B30309D19002F433A5C000000000000000000000000000000000000005200310000000000374FE466100057696E646F7773003C0008000400EFBEEE3AA314374FE4662A000000FA010000000001000000000000000000000000000000570069006E0064006F0077007300000016005600310000000000374F8D86100053797374656D333200003E0008000400EFBEEE3AA414374F8D862A000000F8060000000001000000000000000000000000000000530079007300740065006D0033003200000018006800310000000000EE3A9026100057494E444F577E310000500008000400EFBEEE3A9026EE3A90262A000000FD0A0000000001000000000000000000000000000000570069006E0064006F007700730050006F007700650072005300680065006C006C00000018004A003100000000008C3E0112100076312E300000360008000400EFBEEE3A90268C3E01122A000000FE0A0000000001000000000000000000000000000000760031002E003000000014000000
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\120\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
1092616257
3748
rundll32.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU
1
720075006E0064006C006C00330032002E006500780065000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000006601000087000000E603000067020000000000000000000000000000000000000100000000000000
3748
rundll32.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU
1
720075006E0064006C006C00330032002E006500780065000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000063010000710000009C03000042020000000000000000000000000000000000006601000087000000E603000067020000000000000000000000000000000000000100000000000000
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\120\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Mode
4
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\120\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
IconSize
16
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Applications\powershell.exe\shell\open\command
"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "%1"
3748
rundll32.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\*
MRUListEx
0100000000000000FFFFFFFF
3748
rundll32.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\exe
MRUListEx
00000000FFFFFFFF
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\120\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
LogicalViewMode
1
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
Windows PowerShell
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\120\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:FMTID
{00000000-0000-0000-0000-000000000000}
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\120\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByDirection
1
3748
rundll32.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\*
1
14001F50E04FD020EA3A6910A2D808002B30309D19002F433A5C000000000000000000000000000000000000005200310000000000374FE466100057696E646F7773003C0008000400EFBEEE3AA314374FE4662A000000FA010000000001000000000000000000000000000000570069006E0064006F0077007300000016005600310000000000374F8D86100053797374656D333200003E0008000400EFBEEE3AA414374F8D862A000000F8060000000001000000000000000000000000000000530079007300740065006D0033003200000018006800310000000000EE3A9026100057494E444F577E310000500008000400EFBEEE3A9026EE3A90262A000000FD0A0000000001000000000000000000000000000000570069006E0064006F007700730050006F007700650072005300680065006C006C00000018004A003100000000008C3E0112100076312E300000360008000400EFBEEE3A90268C3E01122A000000FE0A0000000001000000000000000000000000000000760031002E003000000014006800320000E80600EE3ACD092000706F7765727368656C6C2E65786500004A0008000400EFBEED3A13BCED3A13BC2A0000006C74000000000100000000000000000000000000000070006F007700650072007300680065006C006C002E0065007800650000001E000000
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\120\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:PID
0
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\120\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
1
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\120\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
ColInfo
00000000000000000000000000000000FDDFDFFD100000000000000000000000040000001800000030F125B7EF471A10A5F102608C9EEBAC0A0000001001000030F125B7EF471A10A5F102608C9EEBAC0E0000007800000030F125B7EF471A10A5F102608C9EEBAC040000007800000030F125B7EF471A10A5F102608C9EEBAC0C00000050000000
3748
rundll32.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU
MRUListEx
0100000000000000FFFFFFFF
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\120\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Sort
000000000000000000000000000000000100000030F125B7EF471A10A5F102608C9EEBAC0A00000001000000
3748
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\120\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupView
0
3748
rundll32.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\exe
0
14001F50E04FD020EA3A6910A2D808002B30309D19002F433A5C000000000000000000000000000000000000005200310000000000374FE466100057696E646F7773003C0008000400EFBEEE3AA314374FE4662A000000FA010000000001000000000000000000000000000000570069006E0064006F0077007300000016005600310000000000374F8D86100053797374656D333200003E0008000400EFBEEE3AA414374F8D862A000000F8060000000001000000000000000000000000000000530079007300740065006D0033003200000018006800310000000000EE3A9026100057494E444F577E310000500008000400EFBEEE3A9026EE3A90262A000000FD0A0000000001000000000000000000000000000000570069006E0064006F007700730050006F007700650072005300680065006C006C00000018004A003100000000008C3E0112100076312E300000360008000400EFBEEE3A90268C3E01122A000000FE0A0000000001000000000000000000000000000000760031002E003000000014006800320000E80600EE3ACD092000706F7765727368656C6C2E65786500004A0008000400EFBEED3A13BCED3A13BC2A0000006C74000000000100000000000000000000000000000070006F007700650072007300680065006C006C002E0065007800650000001E000000
3748
rundll32.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3748
rundll32.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2600
powershell.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12D\52C64B7E
LanguageList
en-US
2600
powershell.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2600
powershell.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
4008
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
NodeSlots
020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
4008
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
MRUListEx
0100000002000000000000000A00000007000000090000000800000006000000030000000500000004000000FFFFFFFF
4008
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0
MRUListEx
0100000002000000040000000000000003000000FFFFFFFF
4008
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\35\Shell
SniffedFolderType
Generic
4008
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12D\52C64B7E
LanguageList
en-US
4008
rundll32.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU
1
720075006E0064006C006C00330032002E006500780065000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000063010000710000009C03000042020000000000000000000000000000000000006601000087000000E603000067020000000000000000000000000000000000000100000000000000
4008
rundll32.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU
MRUListEx
0100000000000000FFFFFFFF
4008
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\35\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Mode
4
4008
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\35\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
IconSize
16
4008
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\35\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
Sort
000000000000000000000000000000000100000030F125B7EF471A10A5F102608C9EEBAC0A00000001000000
4008
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\35\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
LogicalViewMode
1
4008
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\35\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
ColInfo
00000000000000000000000000000000FDDFDFFD100000000000000000000000040000001800000030F125B7EF471A10A5F102608C9EEBAC0A0000001001000030F125B7EF471A10A5F102608C9EEBAC0E0000007800000030F125B7EF471A10A5F102608C9EEBAC040000007800000030F125B7EF471A10A5F102608C9EEBAC0C00000050000000
4008
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\35\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
1092616257
4008
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\35\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
FFlags
1
4008
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\35\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupView
0
4008
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\35\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:FMTID
{00000000-0000-0000-0000-000000000000}
4008
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\35\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByKey:PID
0
4008
rundll32.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\CIDOpen\Modules\GlobalSettings\ProperTreeModuleInner
ProperTreeModuleInner
9C000000980000003153505305D5CDD59C2E1B10939708002B2CF9AE3B0000002A000000004E0061007600500061006E0065005F004300460044005F0046006900720073007400520075006E0000000B000000000000004100000030000000004E0061007600500061006E0065005F00530068006F0077004C00690062007200610072007900500061006E00650000000B000000FFFF00000000000000000000
4008
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\35\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7}
GroupByDirection
1
4008
rundll32.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Modules\NavPane
ExpandedState
06000000160014001F8080A63C324DC29940B94D446DD2D7249E0000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000160014001F4225481E03947BC34DB131E946B44C8DD50000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000160014001F43983FFBB4EAC18D42A78AD1F5659CBA930000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D0000000000000000002000000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000160014001F580D1A2CF021BE504388B07367FC96EF3C0000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B00000000000000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000160014001F50E04FD020EA3A6910A2D808002B30309D0000010000004D0000002D00000031535053357EC777E31B5043A48C7563D727776D1100000002000000000B000000FFFF0000000000001C00000031535053A66A63283D95D211B5D600C04FD918D00000000000000000
4008
rundll32.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
4008
rundll32.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3220
powershell.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12D\52C64B7E
LanguageList
en-US
3220
powershell.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3220
powershell.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
4012
rundll32.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
{17FE9752-0B5A-4665-84CD-569794602F5C} {7F9185B0-CB92-43C5-80A9-92277A4F7B54} 0xFFFF
0100000000000000AA684360D02DD601
4012
rundll32.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
4012
rundll32.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
4012
rundll32.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12D\52C64B7E
LanguageList
en-US
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
NextCheckForUpdateHighDateTime
30813648
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager
NextCheckForUpdateLowDateTime
1917842942
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
CachePrefix
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
CachePrefix
Cookie:
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
CachePrefix
Visited:
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
CompatibilityFlags
0
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
46000000A1000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
SecuritySafe
1
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
{9E00A4FB-99C3-11EA-972D-5254004A04AF}
0
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
FullScreen
no
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Window_Placement
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF20000000200000004003000078020000
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\PendingRecovery
Active
0
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\WindowsSearch
UpgradeTime
D614B160D02DD601
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Time
E4070500020013000B001A002D00A701
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Blocked
5
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Type
3
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Count
6
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Time
E4070500020013000B001A002D00A701
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Time
E4070500020013000B001A002D00A701
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Blocked
5
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Count
6
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Blocked
5
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Count
6
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Type
3
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Type
3
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\EUPP\DSP
ChangeNotice
0
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\User Preferences
88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977
01000000D08C9DDF0115D1118C7A00C04FC297EB0100000054FAE316B5732B46BA5B8BA73243A3FB0000000002000000000010660000000100002000000011E5432C7401B1B9EF75B2272EDE0E79E01793AE92CB771705B5DC4386244FDA000000000E8000000002000020000000523397598CBA9E95DA9EEFD49F61DB7F4FAD79815531BABE2B6B6FC7F595A659500000005D1861DDC8F12BC78A2F561CFB7FFB7DE09D9A1FF4C417BDBF54F04457AAA38E106D775B33B4387E7569CCE123B684C45182823B58C00800525F710FFDB3CC8CF92B146B66155166805C3CF644168742400000004B07515F06CA3C51256CCD41C7D736A869C5BABA407C88D5C67D354F1E18E699CF08E45C498F7A3B5C5C8E74446A510DF3D348FDED932EE4B892BC9E6FB51A10
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\User Preferences
2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81
01000000D08C9DDF0115D1118C7A00C04FC297EB0100000054FAE316B5732B46BA5B8BA73243A3FB00000000020000000000106600000001000020000000B49428C766015EDC8F9F65379F2124A276B011CA0534A691AE7EC65DE593E23F000000000E800000000200002000000099FCDDC4DF018A2D18E3E69BF2EC12670BF0AE613700132093A9DC4567CB15FC10000000B6B09B287526BA7A6DB8BD5ADD604FE940000000063F28B9EF298A08668D3138AFB07CEB8A124BB7FAFFBC4A7A916FAECB796A98241BBA38FA5DDFBE1503CE38FBB6748D1F9C046890CDF279F76A1D1A1F7AD22E
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Count
7
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Time
E4070500020013000B001A0034002E03
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Blocked
6
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Time
E4070500020013000B001A0034002E03
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Count
7
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Blocked
6
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Blocked
6
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Count
7
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Time
E4070500020013000B001A0034003D03
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing\NewTabPage
DecayDateQueue
01000000D08C9DDF0115D1118C7A00C04FC297EB0100000054FAE316B5732B46BA5B8BA73243A3FB00000000020000000000106600000001000020000000220A2675BF8C3DCE7A154F1E7C81893AF00A447BD3B51B1D3C3E79D16F682591000000000E8000000002000020000000D09D7639483621188C930AB9B1C6B4137285F67D26776928AC89C05798D0381430000000C6D4034C67193E890F54E72129B594C0877B7DB5037DE38F9BEC68BB7AF5F590F8337784482B65429C31D21D546E74E140000000B8BD4C0CD434DE193E2EC31989B0CB0452DB805DC12C65A8717CFE03E23FCC323B961EE6BC056D7A900F3968F8B64ADAA58FD3A51F8CA3F0D21FA22719A4C9D1
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing\NewTabPage
LastProcessed
30CD85D5D82DD601
2828
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MINIE
TabBandWidth
500
2828
iexplore.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12D\52C64B7E
LanguageList
en-US
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072
Blob
0F0000000100000014000000391BE92883D52509155BFEAE27B9BD340170B76B030000000100000014000000CDD4EEAE6000AC7F40C3802C171E30148030C0720B000000010000004A0000004D006900630072006F0073006F0066007400200052006F006F007400200043006500720074006900660069006300610074006500200041007500740068006F007200690074007900000069000000010000000E000000300C060A2B0601040182373C030220000000010000009D0500003082059930820381A003020102021079AD16A14AA0A5AD4C7358F407132E65300D06092A864886F70D0101050500305F31133011060A0992268993F22C6401191603636F6D31193017060A0992268993F22C64011916096D6963726F736F6674312D302B060355040313244D6963726F736F667420526F6F7420436572746966696361746520417574686F72697479301E170D3031303530393233313932325A170D3231303530393233323831335A305F31133011060A0992268993F22C6401191603636F6D31193017060A0992268993F22C64011916096D6963726F736F6674312D302B060355040313244D6963726F736F667420526F6F7420436572746966696361746520417574686F7269747930820222300D06092A864886F70D01010105000382020F003082020A0282020100F35DFA8067D45AA7A90C2C9020D035083C7584CDB707899C89DADECEC360FA91685A9E94712918767CC2E0C82576940E58FA043436E6DFAFF780BAE9580B2B93E59D05E3772291F734643C22911D5EE10990BC14FEFC755819E179B70792A3AE885908D89F07CA0358FC68296D32D7D2A8CB4BFCE10B48324FE6EBB8AD4FE45C6F139499DB95D575DBA81AB79491B4775BF5480C8F6A797D1470047D6DAF90F5DA70D847B7BF9B2F6CE705B7E11160AC7991147CC5D6A6E4E17ED5C37EE592D23C00B53682DE79E16DF3B56EF89F33C9CB527D739836DB8BA16BA295979BA3DEC24D26FF0696672506C8E7ACE4EE1233953199C835084E34CA7953D5B5BE6332594036C0A54E044D3DDB5B0733E458BFEF3F5364D842593557FD0F457C24044D9ED6387411972290CE684474926FD54B6FB086E3C73642A0D0FCC1C05AF9A361B9304771960A16B091C04295EF107F286AE32A1FB1E4CD033F777104C720FC490F1D4588A4D7CB7E88AD8E2DEC45DBC45104C92AFCEC869E9A11975BDECE5388E6E2B7FDAC95C22840DBEF0490DF813339D9B245A5238706A5558931BB062D600E41187D1F2EB597CB11EB15D524A594EF151489FD4B73FA325BFCD13300F95962700732EA2EAB402D7BCADD21671B30998F16AA23A841D1B06E119B36C4DE40749CE15865C1601E7A5B38C88FBB04267CD41640E5B66B6CAA86FD00BFCEC1350203010001A351304F300B0603551D0F0404030201C6300F0603551D130101FF040530030101FF301D0603551D0E041604140EAC826040562797E52513FC2AE10A539559E4A4301006092B06010401823715010403020100300D06092A864886F70D01010505000382020100C5114D033A60DD5D5211778FB2BB36C8B205BFB4B7A8D8209D5C1303B61C22FA061335B6C863D49A476F2657D255F104B1265FD6A95068A0BCD2B86ECCC3E9ACDF19CD78AC5974AC663436C41B3E6C384C330E30120DA326FE515300FFAF5A4E840D0F1FE46D052E4E854B8D6C336F54D264ABBF50AF7D7A39A037ED63030FFC1306CE1636D4543B951B51623AE54D17D40539929A27A85BAABDECBBBEE3208960716C56B3A513D06D0E237E9503ED683DF2D863B86B4DB6E830B5E1CA944BF7A2AA5D9930B23DA7C2516C28200124272B4B00B79D116B70BEB21082BC0C9B68D08D3B2487AA9928729D335F5990BDF5DE939E3A625A3439E288551DB906B0C1896B2DD769C319123684D0C9A0DAFF2F6978B2E57ADAEBD70CC0F7BD6317B8391338A2365B7BF285566A1D6462C138E2AABF5166A294F5129C6622106BF2B730922DF229F03D3B144368A2F19C2937CBCE3820256D7C67F37E24122403088147ECA59E97F518D7CFBBD5EF7696EFFDCEDB569D95A042F99758E1D73122D35F59E63E6E2200EA4384B625DBD9F3085668C0646B1D7CECB693A262576E2ED8E7588FC4314926DDDE293587F53071705B143C69BD89127DEB2EA3FED87F9E825A520A2BC1432BD930889FC810FB898DE6A18575337E6C9EDB7313646269A52F7DCA966D9FF8044D30923D6E211421C93DE0C3FD8A6B9D4AFDD1A19D9943773FB0DA
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\CDD4EEAE6000AC7F40C3802C171E30148030C072
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419
Blob
0F00000001000000100000008B3C3087B7056F5EC5DDBA91A1B901F069000000010000000E000000300C060A2B0601040182373C03020B00000001000000320000004D006900630072006F0073006F0066007400200052006F006F007400200041007500740068006F0072006900740079000000030000000100000014000000A43489159A520F0D93D032CCAF37E7FE20A8B41920000000010000001604000030820412308202FAA003020102020F00C1008B3C3C8811D13EF663ECDF40300D06092A864886F70D01010405003070312B3029060355040B1322436F70797269676874202863292031393937204D6963726F736F667420436F72702E311E301C060355040B13154D6963726F736F667420436F72706F726174696F6E3121301F060355040313184D6963726F736F667420526F6F7420417574686F72697479301E170D3937303131303037303030305A170D3230313233313037303030305A3070312B3029060355040B1322436F70797269676874202863292031393937204D6963726F736F667420436F72702E311E301C060355040B13154D6963726F736F667420436F72706F726174696F6E3121301F060355040313184D6963726F736F667420526F6F7420417574686F7269747930820122300D06092A864886F70D01010105000382010F003082010A0282010100A902BDC170E63BF24E1B289F97785E30EAA2A98D255FF8FE954CA3B7FE9DA2203E7C51A29BA28F60326BD1426479EEAC76C954DAF2EB9C861C8F9F8466B3C56B7A6223D61D3CDE0F0192E896C4BF2D669A9A682699D03A2CBF0CB55826C146E70A3E38962CA92839A8EC498342E3840FBB9A6C5561AC827CA1602D774CE999B4643B9A501C310824149FA9E7912B18E63D986314605805659F1D375287F7A7EF9402C61BD3BF5545B38980BF3AEC54944EAEFDA77A6D744EAF18CC96092821005790606937BB4B12073C56FF5BFBA4660A08A6D2815657EFB63B5E16817704DAF6BEAE8095FEB0CD7FD6A71A725C3CCABCF008A32230B30685C9B320771385DF0203010001A381A83081A53081A20603551D0104819A30819780105BD070EF69729E23517E14B24D8EFFCBA1723070312B3029060355040B1322436F70797269676874202863292031393937204D6963726F736F667420436F72702E311E301C060355040B13154D6963726F736F667420436F72706F726174696F6E3121301F060355040313184D6963726F736F667420526F6F7420417574686F72697479820F00C1008B3C3C8811D13EF663ECDF40300D06092A864886F70D0101040500038201010095E80BC08DF3971835EDB80124D87711F35C60329F9E0BCB3E0591888FC93AE621F2F057932CB5A047C862EFFCD7CC3B3B5AA9365469FE246D3FC9CCAADE057CDD318D3D9F10706ABBFE124F1869C0FCD043E3115A204FEA627BAFAA19C82B37252DBE65A1128A250F63A3F7541CF921C9D615F352AC6E433207FD8217F8E5676C0D51F6BDF152C7BDE7C430FC203109881D95291A4DD51D02A5F180E003B45BF4B1DDC857EE6549C75254B6B4032812FF90D6F0088F7EB897C5AB372CE47AE4A877E376A000D06A3FC1D2368AE04112A8356A1B6ADB35E1D41C04E4A84504C85A33386E4D1C0D62B70AA28CD3D5543F46CD1C55A670DB123A8793759FA7D2A0
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\A43489159A520F0D93D032CCAF37E7FE20A8B419
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247
Blob
0F0000000100000010000000D67576F5521D1CCAB52E9215E0F9F7430B00000001000000400000004D006900630072006F0073006F00660074002000410075007400680065006E007400690063006F0064006500280074006D002900200052006F006F0074000000090000000100000016000000301406082B0601050507030406082B060105050703030300000001000000140000007F88CD7223F3C813818C994614A89C99FA3B52472000000001000000DA030000308203D6308202BEA003020102020101300D06092A864886F70D01010405003050310B3009060355040613025553310D300B060355040A13044D53465431323030060355040313294D6963726F736F66742041757468656E7469636F646528746D2920526F6F7420417574686F72697479301E170D3935303130313038303030315A170D3939313233313233353935395A3050310B3009060355040613025553310D300B060355040A13044D53465431323030060355040313294D6963726F736F66742041757468656E7469636F646528746D2920526F6F7420417574686F7269747930820122300D06092A864886F70D01010105000382010F003082010A0282010100DF08BAE33F6E649BF589AF28964A078F1B2E8B3E1DFCB88069A3A1CEDBDFB08E6C8976294FCA603539AD7232E00BAE293D4C16D94B3C9DDAC5D3D109C92C6FA6C2605345DD4BD155CD031CD2595624F3E578D807CCD8B31F903FC01A71501D2DA712086D7CB0866CC7BA853207E1616FAF03C56DE5D6A18F36F6C10BD13E69974872C97FA4C8C24A4C7EA1D194A6D7DCEB05462EB818B4571D8649DB694A2C21F55E0F542D5A43A97A7E6A8E504D2557A1BF1B1505437B2C058DBD3D038C93227D63EA0A5705060ADB6198652D4749A8E7E656755CB8640863A9304066B2F9B6E334E86730E1430B87FFC9BE72105E23F09BA74865BF09887BCD72BC2E799B7B0203010001A381BA3081B7300D0603551D0A040630040302078030320603550403042B13294D6963726F736F66742041757468656E7469636F646528746D2920526F6F7420417574686F7269747930720603551D01046B306980101A1BE75B9FFD8C2AC339AE0C622E5332A1523050310B3009060355040613025553310D300B060355040A13044D53465431323030060355040313294D6963726F736F66742041757468656E7469636F646528746D2920526F6F7420417574686F72697479820101300D06092A864886F70D010104050003820101002DC9E2F6129E5D5667FAFA4B9A7EDC29565C80140228856E26F3CD58DA5080C5F819B3A67CE29D6B5F3B8F2274E61804FC4740D87A3F3066F012A4D1EB1DE7B6F498AB5322865158EE230976E41D455C4BFF4CE302500113CC41A45297D486D5C4FE8383657DEABEA2683BC1B12998BFA2A5FC9DD384EE701750F30BFA3CEFA9278B91B448C845A0E101424B4476041CC219A28E6B2098C4DD02ACB4D2A20E8D5DB9368E4A1B5D6C1AE2CB007F10F4B295EFE3E8FFA17358A9752CA2499585FECCDA448AC21244D244C8A5A21FA95A8E56C2C37BCF4260DC821FFBCE74067ED6F1AC196A4F745CC51566316CC16271910F595B7D2A821ADFB1B4D81D37DE0D0F
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\7F88CD7223F3C813818C994614A89C99FA3B5247
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3B1EFD3A66EA28B16697394703A72CA340A05BD5
Blob
0F000000010000002000000008FBA831C08544208F5208686B991CA1B2CFC510E7301784DDF1EB5BF039323969000000010000000E000000300C060A2B0601040182373C03020B00000001000000540000004D006900630072006F0073006F0066007400200052006F006F007400200043006500720074006900660069006300610074006500200041007500740068006F0072006900740079002000320030003100300000000300000001000000140000003B1EFD3A66EA28B16697394703A72CA340A05BD52000000001000000F1050000308205ED308203D5A003020102021028CC3A25BFBA44AC449A9B586B4339AA300D06092A864886F70D01010B0500308188310B3009060355040613025553311330110603550408130A57617368696E67746F6E3110300E060355040713075265646D6F6E64311E301C060355040A13154D6963726F736F667420436F72706F726174696F6E31323030060355040313294D6963726F736F667420526F6F7420436572746966696361746520417574686F726974792032303130301E170D3130303632333231353732345A170D3335303632333232303430315A308188310B3009060355040613025553311330110603550408130A57617368696E67746F6E3110300E060355040713075265646D6F6E64311E301C060355040A13154D6963726F736F667420436F72706F726174696F6E31323030060355040313294D6963726F736F667420526F6F7420436572746966696361746520417574686F72697479203230313030820222300D06092A864886F70D01010105000382020F003082020A0282020100B9089E28E4E4EC064E5068B341C57BEBAEB68EAF81BA22441F6534694CBE704017F2167BE279FD86ED0D39F41BA8AD92901ECB3D768F5AD9B591102E3C058D8A6D2454E71FED56AD83B4509C15A51774885920FC08C58476D368D46F2878CE5CB8F3509044FFE3635FBEA19A2C961504D607FE1E8421E0423111C4283694CF50A4629EC9D6AB7100B25B0CE696D40A2496F5FFC6D5B71BD7CBB72162AF12DCA15D37E31AFB1A4698C09BC0E7631F2A0893027E1E6A8EF29F1889E42285A2B1845740FFF50ED86F9CEDE2453101CD17E97FB08145E3AA214026A172AAA74F3C01057EEE8358B15E06639962917882B70D930C246AB41BDB27EC5F95043F934A30F59718B3A7F919A793331D01C8DB22525CD725C946F9A2FB875943BE9B62B18D2D86441A46AC78617E3009FAAE89C4412A2266039139459CC78B0CA8CA0D2FFB52EA0CF76333239DFEB01FAD67D6A75003C6047063B52CB1865A43B7FBAEF96E296E21214126068CC9C3EEB0C28593A1B985D9E6326C4B4C3FD65DA3E5B59D77C39CC055B77400E3B838AB839750E19A42241DC6C0A330D11A5AC85234F773F1C7181F33AD7AECCB4160F3239420C24845AC5C51C62E80C2E27715BD8587ED369D9691EE00B5A370EC9FE38D80688376BAAF5D70522216E266FBBAB3C5C2F73E2F77A6CADEC1A6C6484CC3375123D327D7B84E7096F0A14476AF78CF9AE166130203010001A351304F300B0603551D0F040403020186300F0603551D130101FF040530030101FF301D0603551D0E04160414D5F656CB8FE8A25C6268D13D94905BD7CE9A18C4301006092B06010401823715010403020100300D06092A864886F70D01010B05000382020100ACA5968CBFBBAEA6F6D7718743315688FD1C32715B35B7D4F091F2AF37E214F1F30226053E16147F14BAB84FFB89B2B2E7D409CC6DB95B3B64657066B7F2B15ADF1A02F3F551B8676D79F3BF567BE484B92B1E9B409C2634F947189869D81CD7B6D1BF8F61C267C4B5EF60438E101B3649E420CAADA7C1B1276509F8CDF55B2AD08433F3EF1FF2F59C0B589337A075A0DE72DE6C752A6622F58C0630569F40B930AA40771582D78BECC0D3B2BD83C5770C1EAEAF1953A04D79719F0FAF30CE67F9D62CCC22417A07F2974218CE59791055DE6F10E4B8DA836640160968235B972E269A02BB578CC5B8BA69623280899EA1FDC0927C7B2B3319842A63C5006862FA9F478D997A453AA7E9EDEE6942B5F3819B4756107BFC7036841873EAEFF9974D9E3323DD260BBA2AB73F44DC8327FFBD61592B11B7CA4FDBC58B0C1C31AE32F8F8B942F77FDC619A76B15A04E1113D6645B71871BEC92485D6F3D4BA41345D122D25B98DA613486D4BB0077D99930961817457268AAB69E3E4D9C788CC24D8EC52245C1EBC9114E296DEEB0ADA9EDD5FB35BDBD482ECC620508725403AFBC7EECDFE33E56EC3840955032539C0E9355D6531A8F6BFA009CD29C7B336322EDC95F383C15ACF8B8DF6EAB321F8A4ED1E310EB64C11AB600BA412232217A3366482910412E0AB6F1ECB500561B440FF598671D1D533697CA9738A38D7640CF169
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\3B1EFD3A66EA28B16697394703A72CA340A05BD5
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\245C97DF7514E7CF2DF8BE72AE957B9E04741E85
Blob
0F00000001000000100000009DF0D13100123AECA770130F4AD8D209030000000100000014000000245C97DF7514E7CF2DF8BE72AE957B9E04741E8509000000010000000C000000300A06082B060105050703080B00000001000000320000004D006900630072006F0073006F00660074002000540069006D0065007300740061006D007000200052006F006F00740000002000000001000000B1020000308202AD30820216020101300D06092A864886F70D010104050030819E3120301E060355040A13174D6963726F736F6674205472757374204E6574776F726B311E301C060355040B13154D6963726F736F667420436F72706F726174696F6E312D302B060355040B13244D6963726F736F66742054696D65205374616D70696E67205365727669636520526F6F74312B3029060355040B1322436F70797269676874202863292031393937204D6963726F736F667420436F72702E301E170D3937303531333136313235395A170D3939313233303233353935395A30819E3120301E060355040A13174D6963726F736F6674205472757374204E6574776F726B311E301C060355040B13154D6963726F736F667420436F72706F726174696F6E312D302B060355040B13244D6963726F736F66742054696D65205374616D70696E67205365727669636520526F6F74312B3029060355040B1322436F70797269676874202863292031393937204D6963726F736F667420436F72702E30819F300D06092A864886F70D010101050003818D0030818902818100B75A38F51F37CCA943C4DC2418BEF28552B41D5B5F18B90B8F4B6DA8FFCD40506CD3A0D35C47C2B9F786E4CD7D350569371FAF3DDD1FFD8F1534C2C479CC59748A6F8C0EC3E811EB8438479853E1F10C0DE4010CF01B1E20DA2A7A3DC215528E8AFF7B32BF581E25988326CB8AC9C4071424BC499ED77AB3871A2533BC6D08470203010001300D06092A864886F70D010104050003818100505BC56B6F8D525B0DC9BDAC347398CA0A87CAAE4C4ABA14A4EB52709521E0B5A1604EF743025101AF1E3A70CEBF18B686289967EB08E897405C1682FDB825FB366F6F763EC54C8EE2A751FACAC163BA5E8324470B9372F6449ACEA7953A8F50109E1DB15916ABCF3EDF838BC7FAC36BDC649F402B1F452404AE492FF6DF0C91
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25
Blob
0F000000010000001000000065FC47520F66383962EC0B7B88A0821D03000000010000001400000018F7C1FCC3090203FD5BAA2F861A754976C8DD2509000000010000000C000000300A06082B060105050703080B000000010000003400000056006500720069005300690067006E002000540069006D00650020005300740061006D00700069006E00670020004300410000002000000001000000C0020000308202BC3082022502104A19D2388C82591CA55D735F155DDCA3300D06092A864886F70D010104050030819E311F301D060355040A1316566572695369676E205472757374204E6574776F726B31173015060355040B130E566572695369676E2C20496E632E312C302A060355040B1323566572695369676E2054696D65205374616D70696E67205365727669636520526F6F7431343032060355040B132B4E4F204C494142494C4954592041434345505445442C20286329393720566572695369676E2C20496E632E301E170D3937303531323030303030305A170D3034303130373233353935395A30819E311F301D060355040A1316566572695369676E205472757374204E6574776F726B31173015060355040B130E566572695369676E2C20496E632E312C302A060355040B1323566572695369676E2054696D65205374616D70696E67205365727669636520526F6F7431343032060355040B132B4E4F204C494142494C4954592041434345505445442C20286329393720566572695369676E2C20496E632E30819F300D06092A864886F70D010101050003818D0030818902818100D32E20F0687C2C2D2E811CB106B2A70BB7110D57DA53D875E3C9332AB2D4F6095B34F3E990FE090CD0DB1B5AB9CDE7F688B19DC08725EB7D5810736A78CB7115FDC658F629AB585E9604FD2D621158811CCA7194D522582FD5CC14058436BA94AAB44D4AE9EE3B22AD56997E219C6C86C04A47976AB4A636D5FC092DD3B4399B0203010001300D06092A864886F70D01010405000381810061550E3E7BC792127E11108E22CCD4B3132B5BE844E40B789EA47EF3A707721EE259EFCC84E389944CDB4E61EFB3A4FB463D50340B9F7056F68E2A7F17CEE563BF796907732EB095288AF5EDAAA9D25DCD0ACA10098FCEB3AF2896C479298492DCFFBA674248A69010E4BF61F89C53E593D1733FF8FD9D4F84AC55D1FD116363
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FFBDCDE782C8435E3C6F26865CCAA83A455BC30A
Blob
0F000000010000002000000091655B012CB919746D6127AA24E54BA90B2F15A01927DC1DC88E54365D126363030000000100000014000000FFBDCDE782C8435E3C6F26865CCAA83A455BC30A1D00000001000000100000008229307CFB16C4A269DB1E9BB9FAE94D140000000100000014000000EE6B493C7A3F0DE3B109B78AC8AB199F733350E7090000000100000020000000301E06082B0601050507030206082B0601050507030406082B06010505070301620000000100000020000000D40E9C86CD8FE468C1776959F49EA774FA548684B6C406F3909261F4DCE2575C0B000000010000002E0000005400720075007300740043006F007200200052006F006F00740043006500720074002000430041002D00310000002000000001000000340400003082043030820318A003020102020900DA9BEC71F303B019300D06092A864886F70D01010B05003081A4310B3009060355040613025041310F300D06035504080C0650616E616D613114301206035504070C0B50616E616D61204369747931243022060355040A0C1B5472757374436F722053797374656D7320532E20646520522E4C2E31273025060355040B0C1E5472757374436F7220436572746966696361746520417574686F72697479311F301D06035504030C165472757374436F7220526F6F74436572742043412D31301E170D3136303230343132333231365A170D3239313233313137323331365A3081A4310B3009060355040613025041310F300D06035504080C0650616E616D613114301206035504070C0B50616E616D61204369747931243022060355040A0C1B5472757374436F722053797374656D7320532E20646520522E4C2E31273025060355040B0C1E5472757374436F7220436572746966696361746520417574686F72697479311F301D06035504030C165472757374436F7220526F6F74436572742043412D3130820122300D06092A864886F70D01010105000382010F003082010A0282010100BF8EB795E2C226126B3319C740580AAB59AA8D00A3FC80C7507B8ED42026BA3212D8235449251022989D46D2C1C99E4E1B2E2C0E38F31A25681CA65A05E61E8B48BF9896743E69CAE9B578A506BCD5005E090AF2277A52FC2DD5B1EAB4896124F31A13DBA9CF52ED0C24BAB99EEC7E0074FA93AD6C2992AE51B4BBD357BFB3F3A88D9CF4244B2AD6999EF49EFEC07E423AE70B9553DAB7680E904CFB703F8F4A2C94F326DD6369A994D8104EC5470890991B174DB96C6EEF6095118E2180B5BDA073D8D0B277C445EA5A26FB667676F8061F616D0F55C583B71056720607A5F3B11A0305640E9D5A8AD686701B24DEFE288A2BD06AB0FC7AA2DCB2790E8B650F0203010001A3633061301D0603551D0E04160414EE6B493C7A3F0DE3B109B78AC8AB199F733350E7301F0603551D23041830168014EE6B493C7A3F0DE3B109B78AC8AB199F733350E7300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020186300D06092A864886F70D01010B050003820101002518D4918F13EE8F1E1D1153DA2D442919A01E6B319E4D0E9EAD3D5C416F952B24A179983A3836FBBB669E48FF9090EF3DD4B89BB487753F209BCE72CFA155C14D64A21906A107330C0B29E5F1EAABA3ECB50A7490C77D72F2D75C9F91EF918BB7DCED66A2CF8E663BBC9F3A02E027DD1698C095D40AA4E4819A7594359C905F883706AD59950AB0D167D319CA89E7325A361C3E82A85A93BEC6D06491B6CFD9B618CFDB7ED265A3A6C48E1731C1FB7E76DBD385E358B2777A763B6C2F501CE7DBF667791FF582959A07A714AF8FDC28216709D2D64D5A1C191C8E775CC394243D326B4B7ED4789483BE374DCE5FC71E4E3CE08933950B0FA532D63C5A792C19
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FFBDCDE782C8435E3C6F26865CCAA83A455BC30A
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FFB7E08F66E1D0C2582F0245C4970292A46E8803
Blob
0F00000001000000200000004E3F084ED3C4B0D20C5D5E2E1D33F6096C65162DE9D58F866D8BC6B79EDC39FB030000000100000014000000FFB7E08F66E1D0C2582F0245C4970292A46E88031D000000010000001000000054ECC7F7A10FC6E709B361B583617D40140000000100000014000000D5A8510E7930725EB4AC160DD3B5EBEAC14BDC3A620000000100000020000000C2157309D9AEE17BF34F4DF5E88DBAEBA57E0361EB814CBC239F4D54D329A38D090000000100000042000000304006082B0601050507030106082B0601050507030206082B0601050507030406082B06010505070308060A2B0601040182370A0304060A2B0601040182370A030C0B000000010000007200000046005101740061006E00FA007300ED0074007600E1006E0079006B00690061006400F30020002D0020004B006F0072006D00E1006E0079007A00610074006900200048006900740065006C0065007300ED007400E9007300200053007A006F006C006700E1006C00740061007400F30000002000000001000000440600003082064030820428A003020102020874F860F1E8A38F41300D06092A864886F70D01010B05003081AB310B30090603550406130248553111300F06035504070C084275646170657374313C303A060355040A0C334E49535A204E656D7A65746920496E666F6B6F6D6D756E696BC3A16369C3B37320537A6F6C67C3A16C746174C3B3205A72742E314B304906035504030C4246C59174616EC3BA73C3AD7476C3A16E796B696164C3B3202D204B6F726DC3A16E797A61746920486974656C6573C3AD74C3A97320537A6F6C67C3A16C746174C3B3301E170D3133303931333130323730345A170D3333303931333130323730345A3081AB310B30090603550406130248553111300F06035504070C084275646170657374313C303A060355040A0C334E49535A204E656D7A65746920496E666F6B6F6D6D756E696BC3A16369C3B37320537A6F6C67C3A16C746174C3B3205A72742E314B304906035504030C4246C59174616EC3BA73C3AD7476C3A16E796B696164C3B3202D204B6F726DC3A16E797A61746920486974656C6573C3AD74C3A97320537A6F6C67C3A16C746174C3B330820222300D06092A864886F70D01010105000382020F003082020A0282020100B542A56448DB64A537F82CB8990251B9A228C4FB7004C4D96C8A86F70F8917A484C22E6C4EF5FF44EF5B430E897F3735A55BC8E4235BAF199C5BEDACD6002EDB63CAC354D8AF67D4CB6044A24FCFA4DEFC1F316656B7E1DD388A53FCCF23158B8A87FD0930E59847040E1669AF0905BCC7D490458F6863BE825837FBD84C6FA5AC157775A58864385CD2650F5305CE9430976F7A81E9649812D11E4A9FC1F317DB19361039B801B3B7784DB50C7B5EAA4E9DB9CD5D38FF7F49FEB748AF03426CBE641B61F9CE6B7A9B507100F35797C501741BABC926596C7ABF0A976796B580454801469C4014E46138215B8964E2053613A02ACEDB8804864435DC933459576AED5363FA8BC218163CF471C73E0C1A11E4CE0F20C31723ABA37F1355ACB4FF96D8C02F7A099BDB1C968DA68CFCA16AA66BD10C9D31AC9A31FA52F98939FA2F53F3E9912E508EAAB8A425AF1B8BD96A5288570AC30B9A719FBCCA458AE9B9D595C1B6C2CED10D694A363CAE8DACCB75F69021C30997CE2D1276625EEB0E8F725F2B9BB0C90A15F3FECFF744844601FDCF66ECD030977C6DACD138C1467207170E3EFB30E6CB34D5B5731345210E1D196B4816DAE891A906D0E83D6FFA8CD1B8F59903F1EBD8B569BBB8894F5202A77E3EDBECC5970695FB53EBE0D3E7C88F8899FF2EB797997D84F351FD8E8343DEF3AFE03374C4151C2917A74973DCC04EDD0203010001A3663064301D0603551D0E04160414D5A8510E7930725EB4AC160DD3B5EBEAC14BDC3A30120603551D130101FF040830060101FF020103301F0603551D23041830168014D5A8510E7930725EB4AC160DD3B5EBEAC14BDC3A300E0603551D0F0101FF040403020106300D06092A864886F70D01010B0500038202010061F6644EEA7B97C2C202D95932806D8292A2FA4D8273665A9D82D2556230F820CDA7D389C1C673C4D85D493DCEBE0C7A1DC8696C3DFAEF00F6819A8D3B554F0C9D56D9A7E64DE66BB0A2B5A0FEDF5D835BAB11F26B18AFAB66DB1BC94B1AF744DDF19C82AC9A5EA8A8A8319EDE9CC142228CC41384E52C43061B296933D7E007021FABEE499ED7C388AE591B97CBF81B656001CC6DE140202D4B2101EC1E2CB1816BDEC68CF534B08CC39BDE583E114DE8484C8796EE5A474B426F9EE8834882B99AE93C44F9519354AB9445F9A895AEA68879F5E692A858222ED4944C18BAADFDA7855A82136ABDAE5BC02C195DD893C0DD75403369D94E260A3687A4010CE1DFAD0C19185F88CA35B10A7B810766F97F0F2D6D198AE4E483BB431D5E4FD2E12938C11FF55CA35460EBF843DEE695049987E1CBA9243A792D1A70659F11275D382E450D5BF811592E0E35136AD7A75404FE52F84C15E603995CB287FCAA4608F8D36807601C2F2752759302D8DDD3B187D4FD99767CC1FC03AAEFC782497AFAFA4BDA87DB059F58E26FBE63FA1AA334C1CFBA4C22000705805F05E6017357D491E1D061EF8628E37DCCCA3297E3B36DBCBFF009A02DC40054336D0587F487241D85CDDEC33B37A0E508AFE38B011DB81D3663A210E1252B6C52E01DC6C7F66D9DE0C722E4DDB0862EA6A3986533207656DB67F0C65E4382C20A6D64D5DE8C6C
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FFB7E08F66E1D0C2582F0245C4970292A46E8803
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FEB8C432DCF9769ACEAE3DD8908FFD288665647D
Blob
0F0000000100000014000000CF5C65CD58EBB3D31A6618C3D42BE79BB5DE72E8030000000100000014000000FEB8C432DCF9769ACEAE3DD8908FFD288665647D6800000001000000080000000080D10BBAC7D3017E00000001000000080000000000DC6F269AD3011D00000001000000100000007BFEBE9D00E942574DF1E0052D4409CD140000000100000014000000354AF54DAF3FD78238ACAB716517758C9D5593E6620000000100000020000000A22DBA681E97376E2D397D728AAE3A9B6296B9FDBA60BC2E11F647F2C675FB3753000000010000002400000030223020060A2A83088C9B1B6485510130123010060A2B0601040182373C0101030200C0090000000100000034000000303206082B0601050507030106082B0601050507030206082B0601050507030306082B0601050507030406082B060105050703080B00000001000000360000005300450043004F004D002000540072007500730074002000530079007300740065006D007300200043004F0020004C005400440000002000000001000000810300003082037D30820265A003020102020100300D06092A864886F70D01010505003060310B3009060355040613024A5031253023060355040A131C5345434F4D2054727573742053797374656D7320434F2E2C4C54442E312A3028060355040B1321536563757269747920436F6D6D756E69636174696F6E20455620526F6F74434131301E170D3037303630363032313233325A170D3337303630363032313233325A3060310B3009060355040613024A5031253023060355040A131C5345434F4D2054727573742053797374656D7320434F2E2C4C54442E312A3028060355040B1321536563757269747920436F6D6D756E69636174696F6E20455620526F6F7443413130820122300D06092A864886F70D01010105000382010F003082010A0282010100BC7FEC579B24E0FE9CBA4279A9888AFA80E0F5072943EA8E0A34368D1CFAA7B53978FF9775F72FE4AA6B048444CAA6E2688EFD5550620FA4710ECE07382D428550AD3C966F8BD5A20ECFDE49893DD6642E38E51E6CB5578A9EEF480ECD7A69168744B590E4069DAEA104975879EF204A826B8C22BFEC1F0FE98471EDF10EE4B81813CC56365DD19A1E516B396E607688340BF3B3D1B09DCA61E2641DC14607B863DD1E3365B38E0955523DB5BDFF07EBAD6155182CA969984AAA40C53314657400F991DEAF0348C54054DC0F84906820C59296DC2EE50245AAC05F54F86DEA49CF5D6C4BAFEF9AC2565CC63556426A305FC2ABF6E23D3FB3C9118F314CD79F490203010001A3423040301D0603551D0E04160414354AF54DAF3FD78238ACAB716517758C9D5593E6300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF300D06092A864886F70D01010505000382010100A887E9ECF840675DC3C166C7404B97FC8713905AC4EFA0CA5F8BB7A7B7F1D6B564B78AB3B81BCCDAFBAC668841CEE8FCE4DB1E88A6ED27501B0230244679FE048770974073D1C0C157199A69A52799AB9D6284F651C12CC92315D828B7AB2513B546E18602FF268CC488921D56FE1967F255E480A36B9CAB77E151710D20DB109ADBBD767907779928AD9A5EDAB14F442C358EA596C7FD83F058C679D6987CA88DFE863E071692E17BE71DEC33767E422E4A85F9918968840381A59B9ABEE337C554AB563B182D41A40CF842DB99A0E0726FBB5DE1164F530A64F94EF4BF4E54BD786C88EABF9C1324C27069A27F0FC83CAD08C9B09840A32AE78883ED778F74
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FEB8C432DCF9769ACEAE3DD8908FFD288665647D
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FE45659B79035B98A161B5512EACDA580948224D
Blob
0F0000000100000014000000953FBDAEE03FD0A1F4527440A14940A3FD2CBB6C030000000100000014000000FE45659B79035B98A161B5512EACDA580948224D1D00000001000000100000002E99DC403E88799295E4141302C67BDA140000000100000014000000A69142FD13614A239E08A429E5D8130423EE4125620000000100000020000000BC104F15A48BE709DCA542A7E1D4B9DF6F054527E802EAA92D595444258AFE71090000000100000040000000303E06082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B06010505070308060A2B0601040182370A030C0B0000000100000070000000480065006C006C0065006E00690063002000410063006100640065006D0069006300200061006E006400200052006500730065006100720063006800200049006E0073007400690074007500740069006F006E007300200052006F006F007400430041002000320030003100310000002000000001000000350400003082043130820319A003020102020100300D06092A864886F70D0101050500308195310B300906035504061302475231443042060355040A133B48656C6C656E69632041636164656D696320616E6420526573656172636820496E737469747574696F6E7320436572742E20417574686F726974793140303E0603550403133748656C6C656E69632041636164656D696320616E6420526573656172636820496E737469747574696F6E7320526F6F7443412032303131301E170D3131313230363133343935325A170D3331313230313133343935325A308195310B300906035504061302475231443042060355040A133B48656C6C656E69632041636164656D696320616E6420526573656172636820496E737469747574696F6E7320436572742E20417574686F726974793140303E0603550403133748656C6C656E69632041636164656D696320616E6420526573656172636820496E737469747574696F6E7320526F6F744341203230313130820122300D06092A864886F70D01010105000382010F003082010A0282010100A95300E32EA6F68EFA60D82D953EF82C2A544ECDB9846194584F8F3D8BE443F375898D51E4C337D28A884D791EB712DD43784A8A92E6D748D50FA43A294435B807F6681D55CD3851F08C243185AF83C97DE977AFED1A7B9D17F9B39D38500FA65A799180AF37AEA6D331FBB526099D3C5AEF51C52BDF965DEB321E02DA7049EC6E0CC89A378DF7F136604B262C829ED078F30D0F63A45130E1F92B271207D8EABD186298B059377DBEEEF32051425A83EF93BA6915F1629D9F993982A1B7742E8BD4C50B7B2FF0C80ADA3D790A9A931CA528727391439AA7D14D8584B9A9748F1440C7DCDEAC41646CB4199B02636D24648F44B225EACE5D740C63325C8D87E50203010001A38189308186300F0603551D130101FF040530030101FF300B0603551D0F040403020106301D0603551D0E04160414A69142FD13614A239E08A429E5D8130423EE412530470603551D1E0440303EA03C300582032E6772300582032E6575300682042E656475300682042E6F7267300581032E6772300581032E6575300681042E656475300681042E6F7267300D06092A864886F70D010105050003820101001FEF7941E17B6E3FB28C8637424A4E1C371E8D66BA2481C94F120F21C0039786256D5DD32229A86CA20DA9EB3D065B993AC7CCC39A347FAB0EC84E1CE1FAE4DCCD0DBEBF24FE6CE76BC20DC8069E4E8D6128A66AFDE5F662EA183C4EA0539DB23A9CEBA59C9116B64D82E00C0548A96CF5CCF8CB9D49B4F002A5FD7003ED8A21A5AE138649C33373BE873B748B1745264C169183FE677DCD4D6367FAF303129678068DB167ED8E3FBE9F4F02F5B3092FF34C87DF2ACB957C01CCAC367ABFA2737AF78FC1B59AA114B28F339F0DEF22DC667B84BD4517063D3CCAB977348FCAEACF3F313EE388E3804925C897B59D9A994DB03CF84A009B64DD9F394BD127D7B8
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FE45659B79035B98A161B5512EACDA580948224D
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FDE7C6FDB32BB8E63939840D6AE052C3D8B73B87
Blob
0F00000001000000200000006945FF71C59580E108533160A7D990B06C089ECEF8715CE8CF858EC29D2143C6030000000100000014000000FDE7C6FDB32BB8E63939840D6AE052C3D8B73B871D000000010000001000000094B026932176A0AA02C8ACC22001D53B1400000001000000140000001A26014F23F10FA00FDC55213BDE93BBCCFE2E1E0B00000001000000180000005200430053004300200052006F006F0074004300410000006200000001000000200000007707BB2BE9F7CE057060B8308C3BC087B56529B3638EAF5B2A8049C8E15ED7200900000001000000220000003020060A2B0601040182370A030C06082B0601050507030106082B060105050703022000000001000000A20500003082059E30820386A00302010202104F001BA124BDCB8848BEBD3F2B62C7C5300D06092A864886F70D01010B05003060310B3009060355040613024C54310D300B060355040B130452435343312C302A060355040A132356492052656769737472752063656E747261732D20692E6B2E20313234313130323436311430120603550403130B5243534320526F6F744341301E170D3137303532333038333635315A170D3434303532333038333635315A3060310B3009060355040613024C54310D300B060355040B130452435343312C302A060355040A132356492052656769737472752063656E747261732D20692E6B2E20313234313130323436311430120603550403130B5243534320526F6F74434130820222300D06092A864886F70D01010105000382020F003082020A0282020100CE6AAA480A439759C6F2ACF61DEE12DA7E3688E7F3489BF9B86E43ADBBD71142D61E9D6808DAEAB8A27AE57D3D32CF9480EEBF3EE64EA99E1DC7493F2706FC19EFB7D88F1992C142389B4D40CB8601BFAD91398C8B1FA3AB6E68A1B3D37AD96C2803745B4907C840A156ADB5414B25A5B953738146615504E027B3AB50E41F08B2E5F3927EAC851CDB9DFA677A30FFEE2FF231B3839082A519EACBCAED41E98062AF30D0851C35AD22591855D61438809B9AAF8A0408C6ED89B5BF08167FB16D5B18D93A88C4191734E24A45C34AA105897784CFEC243F21F04DC2BBD2730B4BAB8BF75A905F4C16A5A84FC8E9BE720EBCCDB80C2CCE80BA05F6E449C79E6F3C504E3A144554AA7028646472431A56C5C9335E79EF788BC394EF253BE53BCB53DBB36CFB9E0542FF793AF3B539FFCE3E631AFB17EBBD3C8E853817E4049ADA53E2993935AC987D8583B5A38B09E939F87F3D9031C3167EDCAFBF29F44379A5C4FD5F5BD2F5CB56F3DB16D71AACF3E660FD51D33C8C55281100D544CECCD19D2DE3066AC259CB742EE2835864569FFE0E002D4D25F0528B58DE667AEFC0543F53DF116D67B2C92EB8C2A9169CC4348749EF43F9B110C3D82E9B30DB432AC98F4A03108377CE33D61671CE22B01608C997B3D529D04D0E2C42AD2EFDD7D775BE31FAD85F27B56BBD0030CE729CBB401220A01645AF2D62C697195D43384FB4FAC10203010001A3543052300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E041604141A26014F23F10FA00FDC55213BDE93BBCCFE2E1E301006092B06010401823715010403020100300D06092A864886F70D01010B05000382020100A818E78DC509670F5B8D67D7FC1291752F92464753675EB5CE5FB17F0F22778CA02B4E38EDBAA46CD8BA5867C0FBB9952074086136247E25A9EE49274AE1D19B154A8AC92B82842EB06F9BE2B0D0C196D7343596DC545F8DA9834271092851B529BDA13BB2BA7D71CFC21F88E01A548DE3114432A790F003C3F8BE72B65BE0B4BCBF6B36938EA101AC595149C89E2C88934270D71DE78AC5C3482869C5E5C521DBC8EF6B62143D2F6C53F7B115323C80144316E0B93916DD8C10DB396D80B2FF7E97CF4C995B6A1918B0E749C47F5A06EF89F8880138B5E9D620973B7EC6149505B2D8FB672AF8EFEA2311A7EDEA07EABD688FB3832C8B73BAF61BE16A2E74CA3929A621F55778785B263FF1D036BAF0365EBEBFD2B2A74F5DF1D44A8D7757C01870C7A61627B8EC82DAA3E864F59C854691A0A0B516FB8E651C4DF681DB729A43CC991A7A97D26B369F52EF75682C4246885944D64F921B05B98F0B9AD071D24EA11BAC811C01118913CE2ED89F55E01EFE7814C341A74EF1BB1D08BE750B756CFD76CF9C654D371E224B357298F4F11FDA3F12464510137954331F8A6DF37B22E6673C337EBDE8D38A0D0B980BBDCDF4B0BE91C221EB00284E128092DC2BA30026C29BDBC95DFA17671DB806AD6661521C9A49598BDB0E54A158E28D3734A17B8DC5BCDA8AA8D25870B162F6B05CC01277B276867F2FA8D41DD17CA7E29AF0
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FDE7C6FDB32BB8E63939840D6AE052C3D8B73B87
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FD1ED1E2021B0B9F73E8EB75CE23436BBCC746EB
Blob
0F00000001000000140000001BD29F89F6A79A0F673E9187C11BD86985B03260030000000100000014000000FD1ED1E2021B0B9F73E8EB75CE23436BBCC746EB680000000100000008000000008024EED112D2011D000000010000001000000051F86B39EAA788610ACD3F2A0547ACFB140000000100000014000000822F362349782042D7B05258A0D674541578BFAA0B000000010000001A00000044002D0054005200550053005400200047006D0062004800000062000000010000002000000090F3E05396995FF20922C44592DB62D7845E1BF64AEF512CCA75BC669CAA2479090000000100000034000000303206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B06010505070308200000000100000099040000308204953082037DA0030201020203030E96300D06092A864886F70D0101050500304B310B300906035504061302444531153013060355040A0C0C442D547275737420476D62483125302306035504030C1C442D545255535420526F6F7420436C61737320332043412032303037301E170D3037303531363035323034375A170D3232303531363035323034375A304B310B300906035504061302444531153013060355040A0C0C442D547275737420476D62483125302306035504030C1C442D545255535420526F6F7420436C6173732033204341203230303730820122300D06092A864886F70D01010105000382010F003082010A0282010100BA8DCD355332EEA6BD48909AF2EAE8580F4766A8CC6E0912E4A1CB5BDF93B8F6E93939F8C6D8E9CF1A86BCA6AE0F8CAF0845E3F28E2BC25C592BFA8C36B3701DC8503CA556BEEAAEE947F6E7490FAF7F9426D4021A07B8BA3955CE9FBB223929D835C5990321D8A73863F1E434DF47AE9F37F16CA099C222B06D72DC22C93139E856D7A08F3A215B869A4F28F91C76F7CC4F3FF94E778B2A9C8AAA79418AD51CD9396F98C95E45971D099419D95051857273BFAC4B9D7434718721160F7EEED2497ECA49D3F9922A47484F0F5D5AA1CBD528ECF092C5724346EBB303A6F357254A0A61840A26D6EFA6B8D8148D78B9D3B725D14EE35A16AAEC9F07EE23107DB50203010001A38201803082017C300F0603551D130101FF040530030101FF301D0603551D0E04160414822F362349782042D7B05258A0D674541578BFAA303906082B06010505070101042D302B302906082B06010505073001861D687474703A2F2F75736572732E6F6373702E642D74727573742E6E657430330603551D11042C302A8110696E666F40642D74727573742E6E65748616687474703A2F2F7777772E642D74727573742E6E6574300E0603551D0F0101FF0404030201063081C90603551D1F0481C13081BE3081BBA081B8A081B586766C6461703A2F2F6469726563746F72792E642D74727573742E6E65742F434E3D442D5452555354253230526F6F74253230436C617373253230332532304341253230323030372C4F3D442D5472757374253230476D62482C433D44453F63657274696669636174657265766F636174696F6E6C697374863B687474703A2F2F7777772E642D74727573742E6E65742F63726C2F642D74727573745F726F6F745F636C6173735F335F63615F323030372E63726C300D06092A864886F70D01010505000382010100550E680A8DDCD9A886600269798D7DE990C2D91D1DB50EBB7392646314464CD06ABBA3755D86193861861DB88A2234A3B43515B3A9604C54179FB1DE5B32E27E6BDE4F22F02D1D22049EB64A4FAB2C569DE3DDECB1264E2AD755C23EBD82D7BE55BB45C8295B863C9D3F68444444360D68BFAE01A219B54C97FFF2963C67B242DE0FE1A0974ECAE73465AE9582616726732DDD7BE7954B0E21AA92AE4CFCC6B3A9E599833239F060C24C51A8C147143589A54D360F9F1B0271418D424A24F8AF6E9D0D70868DAA62131E038B24F9C3549349851B7576627F22FF49BD76730C3F98AD2AB2FAE7C5DF74F5FF6931550A3AC0196235C449B92B191DF47099EED8DC
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FD1ED1E2021B0B9F73E8EB75CE23436BBCC746EB
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FBEDDC9065B7272037BC550C9C56DEBBF27894E1
Blob
0F000000010000002000000063B2F71DF462D039ECBE4D03E68B1F1C6B005547D4E5EDFB57E9232EBEA34E2E030000000100000014000000FBEDDC9065B7272037BC550C9C56DEBBF27894E168000000010000000800000000800C13C1B9D4017E000000010000000800000000C00C0F7F39D3011D00000001000000100000000FA92B26CAEAFA47402786392FCF29840B000000010000001400000057006F005300690067006E002000470032000000140000000100000014000000FA60A9EB65C5DD1614084E0C0F8D9BE0F764AF67620000000100000020000000D487A56F83B07482E85E963394C1ECC2C9E51D0903EE946B02C301581ED99E165300000001000000230000003021301F06092B06010401829B510230123010060A2B0601040182373C0101030200C0090000000100000034000000303206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B060105050703082000000001000000800300003082037C30820264A00302010202106B25DA8A889D7CBC0F05B3B17A614544300D06092A864886F70D01010B05003058310B300906035504061302434E311A3018060355040A1311576F5369676E204341204C696D69746564312D302B0603550403132443657274696669636174696F6E20417574686F72697479206F6620576F5369676E204732301E170D3134313130383030353835385A170D3434313130383030353835385A3058310B300906035504061302434E311A3018060355040A1311576F5369676E204341204C696D69746564312D302B0603550403132443657274696669636174696F6E20417574686F72697479206F6620576F5369676E20473230820122300D06092A864886F70D01010105000382010F003082010A0282010100BEC5C4A02280494FBFD98711C653E1BB0FBD607FAFF6820E1FDCB08E3D97E0503C8F3AEF663B45079B20F8E3D72586359016A25D6F301908870B7F06B29D628FDEAF92A560D42B809A523FF59A83E9345ACBD9D5625CE60EE0DF06980E807CCAB41D13886B0EA8247703D0EE5BF3CA6991353956C56DE3F73D4F5E933824CA18E924CB9203DDCC1C3D0970E420E4F1AEACBB7369A3633A0F450FA14A9AC2D163ACCB10F83DE64E28B7EBC495B1ACFD5EABFA41CB5D9D4BDCF47C76EF677F007A8DD2A01A5C4D22E1B5DADD76B3D476DF5EB88B98C81454CC6B1792B7E04ABF4994610B38908F5D246C257B3B79D9E27E9DAD9F98A106FC78146057F8EE8077B10203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E04160414FA60A9EB65C5DD1614084E0C0F8D9BE0F764AF67300D06092A864886F70D01010B0500038201010057C37A36829C8D98E2AB40AA478FC7A75BED7CE73D665A3B31BBDFF3163391FC7C7BA5C2A666E3AAB0B727983F49D76067673F364F4ACBF114FA5A87281CED8F4132C695F97DDABD7B5BC2B021E38F46DC213843744CFB30F81772C132FCC89117C4CC58374E0BCC5AF7213528836C602D44EB528C503DB56C12D7FA09BB6CB24AB1C589E4FCD352D86117FE7A94848F79B63359BA0FC40BE270A04B782EFAC89FFDAF91650A783815E5971714DDF9E02C34F838D0842200C01451182B02DC305AF0E8017C353A23AF08E4AFAA8E2842492EF0F59934BEED0F4B18E1D2243CBB5D47B721F28DD10A998EE36E3EAD70E08FB9CACC6E8131F67B9C7A79E4677118
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FBEDDC9065B7272037BC550C9C56DEBBF27894E1
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FAB7EE36972662FB2DB02AF6BF03FDE87C4B2F9B
Blob
0F0000000100000014000000FB3C6AB2DE9A3F0B74E5C372ED86A52B25385A6C030000000100000014000000FAB7EE36972662FB2DB02AF6BF03FDE87C4B2F9B7E000000010000000800000000809EF40C18D5017F000000010000000C000000300A06082B060105050703031D000000010000001000000061E02D8843C4B370E6B163FC9776C017140000000100000014000000E08C9BDB2549B3F17C86D6B242870BD06BA0D9E4620000000100000020000000EAA962C4FA4A6BAFEBE415196D351CCD888D4F53F3FA8AE6D7C466A94E6042BB0B000000010000002200000063006500720074005300490047004E00200052006F006F0074002000430041000000090000000100000054000000305206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B06010505070308060A2B0601040182370A030406082B0601050507030606082B0601050507030720000000010000003C0300003082033830820220A0030201020206200605167002300D06092A864886F70D0101050500303B310B300906035504061302524F3111300F060355040A1308636572745349474E31193017060355040B1310636572745349474E20524F4F54204341301E170D3036303730343137323030345A170D3331303730343137323030345A303B310B300906035504061302524F3111300F060355040A1308636572745349474E31193017060355040B1310636572745349474E20524F4F5420434130820122300D06092A864886F70D01010105000382010F003082010A0282010100B733B97EC8254A8EB5DBB4281BAA5790E8D122D364BAD393E8D4AC8661406A60576854844DBC6A540205FFDF9B9A2AAE5D078F4AC3287FEFFB2BFA79F1C7ADF0105324908B66C9A888ABAF5AA300E9BEBA46EE5B737B2C1782815E622CA10265B3BDC52B007EC4FC0333570DEDE2FACE5D45D638CD35B6B2C1D09C814AAAE4B2015C1D8F5F99C4B1ADDB8821EB90088280F330A343E69082AE552849ED5BD7A910380EFE8F4C5B9B46EA41F5B00874C3D08833B67CD774DFDC84D1430E7539A1254028EA78CB0E2C2E399D8C8B6E161C2F268210E2E365940A04C05EF75D5BF810E2D0BA7A4BFBDE3700001A5B28E3D29C733E328798A1C9512FD7DEAC33B34F0203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF0404030201C6301D0603551D0E04160414E08C9BDB2549B3F17C86D6B242870BD06BA0D9E4300D06092A864886F70D010105050003820101003ED21C892E35FCF875DDE67F6588F4724CC92CD7324EF3DD197947BD8E3B5B930F504924136B140672EF09D3A1A1E34084C9E71832743C486E0F9F4BD4F71ED39386645497637250D555CFFA209302A29BC323934E165576A070796DCD211FCF2F2DBC19E38831F8591A8109C897A674C760C45BCC578EB275FD1B0209DB596F729369F73141D68838BF87B2BD1679F9AAE4BE8825DD6127231CB531070436B41A90BDA0747150896DBC14E30F86AEF1AB3EC7A009CCA348D1E0DB64E792B5CFAF7243708BF9C3843C13AA7E929B575393FA70C2910E31F99B675DE996385E5FB3734E881567DE9E76106220BE5569954300394DF6EEB05A4E494454585F4283
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FAB7EE36972662FB2DB02AF6BF03FDE87C4B2F9B
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FAAA27B8CAF5FDF5CDA98AC3378572E04CE8F2E0
Blob
0F0000000100000014000000B0770DB83E3CB35AD27859BCA9527E320711BC3C030000000100000014000000FAAA27B8CAF5FDF5CDA98AC3378572E04CE8F2E009000000010000002A000000302806082B0601050507030106082B0601050507030206082B0601050507030406082B060105050703090B00000001000000500000005300700061006E006900730068002000500072006F007000650072007400790020002600200043006F006D006D00650072006300650020005200650067006900730074007200790020004300410000002000000001000000DE050000308205DA308204C2A00302010202043CCE73D0300D06092A864886F70D01010505003082010C310B300906035504061302657331453043060355040A133C536572766963696F2064652043657274696669636163696F6E2064656C20436F6C6567696F206465205265676973747261646F726573202853435229311B3019060355040B1312436572746966696361646F2050726F70696F31193017060355040B1310436572746966696361646F205261697A312A302806035504031321436572746966696361646F206465206C6120436C617665205072696E636970616C312C302A060355040913235072696E636970652064652056657267617261203732203238303036204D61647269643124302206092A864886F70D0109011615736372407265676973747261646F7265732E6F7267301E170D3032303433303130333935305A170D3132303432373039333935305A3082010C310B300906035504061302657331453043060355040A133C536572766963696F2064652043657274696669636163696F6E2064656C20436F6C6567696F206465205265676973747261646F726573202853435229311B3019060355040B1312436572746966696361646F2050726F70696F31193017060355040B1310436572746966696361646F205261697A312A302806035504031321436572746966696361646F206465206C6120436C617665205072696E636970616C312C302A060355040913235072696E636970652064652056657267617261203732203238303036204D61647269643124302206092A864886F70D0109011615736372407265676973747261646F7265732E6F726730820122300D06092A864886F70D01010105000382010F003082010A0282010100A9142B9008FD1080BCDEA9083F0B99C99076108D155BE19F44B645E89120E0FF6B697C25F95600770C3841D7C19BCBF7D1802839A7D542719A8299F152CA8072E1AD44768512E2F78AE01B9B511DCF645B3E614864BFAFB5FE5944704C0B50C74CC14C6DB10878E68720C8AB9FB40971F6CD4569ED7762F02A84DB87183706B9A20A7377BC4EF019A6F82A13DFD56E30342824339AE731521AEA103BEA62CC4A2E6D38963523782A38D7170DC03A25F87757690B3D7C54FC02ADD9ACEDF5C1FAB37C9DC5562BDAA93FE7AA1B90CF16886F47CCF8ED0797D5C2077AEA00F7E3C4BC4AF9360A88E5074DB0759EBBE50406156B8D2D96AEBE4DBE2083D76096C1E30203010001A382013E3082013A300F0603551D130101FF040530030101FF308201250603551D200482011C30820118308201140604551D20003082010A3081C506082B060105050702023081B81A81B54573746520636572746966696361646F20657320656D697469646F20792064656265207574696C697A6172736520736567756E206C6F2064697370756573746F20656E2073757320436F6E646963696F6E65732064652043657274696669636163696F6E207920656E20656C205265676C616D656E746F2064656C205343522E20687474703A2F2F7777772E7265676973747261646F7265732E6F72672F7363722F6E6F726D61746976612F63705F66322E68746D304006082B060105050702011634687474703A2F2F7777772E7265676973747261646F7265732E6F72672F7363722F6E6F726D61746976612F63705F66322E68746D300D06092A864886F70D01010505000382010100702BCB0474667EE70D228B1256EB16637758B0DB09FA97F5DBBD34D08F6849E0CDDFEE5CB5B193859EC2741E92994A729A07A02B48A0499BBA7B20442E71F866815BB9B8ACA4A4A5C19AA4B471091EE62890B112D69EAF76DDE200F2AE7ECA7741731B2297DCAC27C217979F52F4967167977D48905E7171E39F51E887D3974FEA3F77509D8805F351EA2EDB1303B57E3FC4040E96FE259BB09C5B9E72AA8621654F65C8903B1A105D2D4985436869B62C67A352A8687BAE4F3A70F195E0B3EA2312525332C264A168A65450A28378718008FCBC48934C5C5E9BE578E1DC8333B18E16A79D11FC4AD72F62FA032F1FAC00F6E8774546BF1FF2A109E8DB0D02B9
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FAAA27B8CAF5FDF5CDA98AC3378572E04CE8F2E0
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FAA7D9FB31B746F200A85E65797613D816E063B5
Blob
0F0000000100000014000000A1D0B0B2415CED2D6CAE1FBA721B5FC4089ECE8F030000000100000014000000FAA7D9FB31B746F200A85E65797613D816E063B51D00000001000000100000008A11CBDCEE909A825FB1EB5B53194E2E140000000100000014000000DBE9E19BD2D1240BFCABE3A067EAAE9C4B77F4B0620000000100000020000000F008733EC500DC498763CC9264C6FCEA40EC22000E927D053CE9C90BFA046CB20B0000000100000022000000560052004B00200047006F0076002E00200052006F006F0074002000430041000000090000000100000036000000303406082B0601050507030106082B0601050507030206082B06010505070304060A2B0601040182370A030C06082B0601050507030820000000010000001E0400003082041A30820302A00302010202030186A0300D06092A864886F70D01010505003081A3310B30090603550406130246493110300E0603550408130746696E6C616E643121301F060355040A131856616573746F72656B6973746572696B65736B757320434131293027060355040B132043657274696669636174696F6E20417574686F7269747920536572766963657331193017060355040B13105661726D656E6E6570616C76656C7574311930170603550403131056524B20476F762E20526F6F74204341301E170D3032313231383133353330305A170D3233313231383133353130385A3081A3310B30090603550406130246493110300E0603550408130746696E6C616E643121301F060355040A131856616573746F72656B6973746572696B65736B757320434131293027060355040B132043657274696669636174696F6E20417574686F7269747920536572766963657331193017060355040B13105661726D656E6E6570616C76656C7574311930170603550403131056524B20476F762E20526F6F7420434130820122300D06092A864886F70D01010105000382010F003082010A0282010100B08515DAC80337D0A346376C1B1E9630C25A85126723F2BB9FE78A816027F813A93CBCF786AAAAF4F32529B4FE75AE1E81868A05B21D65B238E8B4CC289AFB1736F193D579CEC1838B214FC30DAD41DF789D48E31F4244FC3C6D21206BAD228424428F174DC2501F64CD2D39225688FDB2639D54DA4269C0C84FD718E23EC86984943D2C80C67CCEBDD7531FEB88B9A6CBBB8557EF57765D0C8BD35E12419F21C039F4266D08FA38B3A177B1EE16D8D068DAB498A5A065464A6B8D7EAA4D60B8F8C80DFC713EEE398781B4D9F86E90EE3F0E61D71D2B68E62EE1424426782C58F27D167F61C049242A8987B65D2F2919F8A6E78E529E414B5A0EAAB8C26642530203010001A3553053300F0603551D130101FF040530030101FF301106096086480186F8420101040403020007300E0603551D0F0101FF0404030201C6301D0603551D0E04160414DBE9E19BD2D1240BFCABE3A067EAAE9C4B77F4B0300D06092A864886F70D01010505000382010100AD7D480F54119E58EEAF0D9B122F21A4CD9BBA8447E6C9255523E3DF18582A2CDB5EF7CD54F551247B6267E1B11F49AF34D0EBB1CCD9A20D527F424B886097CF2572B74F292D629F4FA1C05557560EC46897911F9C64C2293201E9D4C8DAB88198282E18C72CFCEB9B5296DFF4C890192D23F3F1BB71DA9E8523BD1AEF2EE47A79B7C39D86492D63B92D74CF650F326689DF3B21EE296F3963D915C16EF6DF803E5078198ADD03A314A537A7B52C7CB61187E705F2BCB6DED4FF97812884FEFE6C468510419F4D758C07D499676F758A6FE45092F699D510B8C4A97BF7178D4BBFD7959F09DC440F1E32C3C0CFD3790DE4C73B87F09034882162499204041FBC
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FAA7D9FB31B746F200A85E65797613D816E063B5
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FA0882595F9CA6A11ECCBEAF65C764C0CCC311D0
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\FA0882595F9CA6A11ECCBEAF65C764C0CCC311D0
Blob
0F0000000100000014000000A6D522610F3DE3265F9E64E8EB7E0E26A1AA7B42030000000100000014000000FA0882595F9CA6A11ECCBEAF65C764C0CCC311D01400000001000000080000004BC94EB967B198356800000001000000080000000040D10FFC47D5017E0000000100000008000000000010C51E92D2011D000000010000001000000023E9E251ED12A313067097A076B80A530B000000010000001600000043006500720074004500750072006F0070006500000062000000010000002000000042143A511A3AFCDD80D555DEBB4191EC6BB285EE66E62EC657ED20ADF7D55FAA09000000010000002A000000302806082B0601050507030106082B0601050507030206082B0601050507030406082B06010505070308200000000100000003070000308206FF308204E7A00302010202027119300D06092A864886F70D0101050500305A310B300906035504061302465231133011060355040A130A436572746575726F706531173015060355040B130E3030303220343334323032313830311D301B06035504031314436572746575726F706520526F6F742043412032301E170D3037303332373232303030305A170D3337303332373233303030305A305A310B300906035504061302465231133011060355040A130A436572746575726F706531173015060355040B130E3030303220343334323032313830311D301B06035504031314436572746575726F706520526F6F74204341203230820222300D06092A864886F70D01010105000382020F003082020A0282020100C3FC56B52B068BED9E46CFC300791C8039A2CACA1B106D21F9C71F0AACF3AD7982979EC6B16888527138C4AA4C476F77FDE71FF794F672579F443C6B5FD0D9CE2228CD702301142250100E1A7B4B1BF486578FEA2F6940BA457A02405A5F35DBA0B99E3FF03F75CD3A45911355C34829F3B7D714F20386A3C9B0577B3DD92AAC5EE1DF953A85C6054C31A2DA2DB1008EAF51579EC18B454D29078BA0E5E5DF310C7F066C614F6BE22332C1E58C2B0DD8960670B32627CACFB3A82300C0122481BFAC443D17988388CE0990372EA2801949D9A0081786996ADD1E409FD202E7B39856477617AA4EA1D7DBEAA4BAD5526769732EA0275473AC8BD0BBF0615826A86A7918C10CE77C56CCCFCDD7068622075E73B8D0E60C253562BA04C4F1002CCE9D489D5BB4F6D16298437757AB72FE3380102A311BDB19502992AC81E008695FE64E3E5EAD5C48799EC55DB09791179E16DF07FA6AE1ABBC257C3800E1D6D87A9CFCDCD722005267A897BB6C0D67999710B8793867686188296E94BF52078836C2F22FC6466A211EF19AE8BB9FEDB626B386A7304A9B3063BCE4E8425644273C5AA10E7DCEAAC31B5E68EC733F3FB3FBC4852C0415FBAC0A3866331995034BCAB4047DE77E0F0D98563ED8575FB799BE7A14ADC5A7DB940E059E25ABB2ABF9099578AA078B6C051CEE5A8061E8DFBE36FBB3E323DC3D8C7566EFA3E455D09AEF0203010001A38201CD308201C9300F0603551D130101FF040530030101FF30110603551D0E040A04084BC94EB967B1983530530603551D20044C304A304806072A817A01690401303D303B06082B06010505070201162F687474703A2F2F7777772E636572746575726F70652E66722F7265666572656E63652F70632D726F6F74322E706466300B0603551D0F0404030201063082013F0603551D1F04820136308201323032A030A02E862C687474703A2F2F7777772E636572746575726F70652E66722F7265666572656E63652F726F6F74322E63726C307DA07BA07986776C6461703A2F2F6C6372312E636572746575726F70652E66722F636E3D436572746575726F7065253230526F6F742532304341253230322C6F753D303030322532303433343230323138302C6F3D436572746575726F70652C633D46523F63657274696669636174655265766F636174696F6E4C697374307DA07BA07986776C6461703A2F2F6C6372322E636572746575726F70652E66722F636E3D436572746575726F7065253230526F6F742532304341253230322C6F753D303030322532303433343230323138302C6F3D436572746575726F70652C633D46523F63657274696669636174655265766F636174696F6E4C697374300D06092A864886F70D010105050003820201001B449660245A3E6BAADECDD3D85B52C04BFA5125E3EECDBC8C3ED3B51DF6FC4083AC7EE5D706432D6C2773FEBFDAA48222516EFE8C0CA611526068065E334CFA48F85B4821D60C9BBE38B9E1C04C13A153EF22396EEE4650650B1A1F057E77D9CE25CDF4AFC67C9D8C976C6A1DF664ED94E1CE5DEF401D96CB71D54AAD795839454DAB6F07BB337CAE3EA5E9C728DA68A09E572766EF7D97EE69A842EB73AA4BB159C68D379CA9C046506F8C4953D5E52DE1A24DCBE75BBFA5BB3CAC52CE199364C3109A7942ABA8FB8483C2465FBB28CC0E694F7C5FBB3C67E60D961E844C5E20155B3943E58B2B822489A3A0F71065D3C989DAA4C1457D895990EB419E8ED0C409605F972D216D04A61181304C93C25860B86BD67AA0E5B1119F62B8307146A77764663A42591F556347D71DA0348E81726248D997AEA1F1BE40E2A0317F6B00D9C702D069020EF1CE1E2DA49DEFCC813B639EF7541BCEBEC40A579BCDB16BE2A7E0AB1E1E83D8C0521CAA3A514692D09FDB21DF69A80B154D5EE489FC5B5348796BAD619F1EE5B8B132B2DB7DE8476AD8A2E065F5CE5617A01290BAF04B2D011AA969D2A7E7C7AC349B6DA290C186264AB22FBDFB6F686B55BBC56338C17760632DAD0C9C3CAA98B243A3D446DC0DDC361F322E68BA7C6521419796906714D6A42FFD213F7FFC227B2A3558F546F1930ED9EDE03A267F6E2E8F98B84FD499
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F9DD19266B2043F1FE4B3DCB0190AFF11F31A69D
Blob
0F0000000100000014000000D7D56CCEB4FC8EDDB3C2BB0F4924DAA3D9AA9C8A030000000100000014000000F9DD19266B2043F1FE4B3DCB0190AFF11F31A69D6800000001000000080000000040D10FFC47D5017E000000010000000800000000C0A06C6128D4011D00000001000000100000009FF8A5BFCB34629A5B6ECF686C255A621400000001000000140000007DBB69EB8861E140CF4723640086A2666BDC849562000000010000002000000046273285615D96E52DA9FC2ED8C036F10AF3D9F6280F8D288706C52B2011B4DA090000000100000034000000303206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B060105050703080B000000010000003400000043006F007200720065006F00200055007200750067007500610079006F0020002D00200052006F006F007400200043004100000020000000010000001E0600003082061A30820402A003020102021000CA227908232AF0F582B885D363DDF1300D06092A864886F70D0101050500307F310B3009060355040613025559312B3029060355040A0C2241444D494E495354524143494F4E204E4143494F4E414C20444520434F5252454F53311F301D060355040B0C16534552564943494F5320454C454354524F4E49434F533122302006035504030C19436F7272656F20557275677561796F202D20526F6F74204341301E170D3038303731343136353231355A170D3330313233313032353935395A307F310B3009060355040613025559312B3029060355040A0C2241444D494E495354524143494F4E204E4143494F4E414C20444520434F5252454F53311F301D060355040B0C16534552564943494F5320454C454354524F4E49434F533122302006035504030C19436F7272656F20557275677561796F202D20526F6F7420434130820222300D06092A864886F70D01010105000382020F003082020A0282020100B13DD2A725709783780ED732C9660E7823E42A1BECC3EF538583BBCACF7EEA53996D2755C8D13821406E494DC33DF6092B061943A998C9014EF4AA80300755F3F5B77D99B77385D51C65566C0D329B080E34612A40098437C366ED0D4C9C0C78403AECEDABCCA484F275319540A8AABB93B577986CF2C8E0215A23E442A793C8A81D38CEA41A4040BF3C93909B5FD694C1225B46D7C50015D58FC6F7DE0BAF6E8B058F5B80950EA3BD93CC90F27DE3487EB2CD073D1BED149074F3DD341F7CE40359F12DCDE0A3A03B212E5CAEAC080650153135EE5FF91F0D34A5806E62724FE321BA38405D5FDB682A5C34C6083BF67C2EA88DC4B7A6ADD99BBF19410E483909666E0D3401C5BB071123A4DAFE60962847DC8F679B13AF7D790E78CDC08C2FBB212CFC74161EDEC0329DFA783A86BA3EC9780A00D1E4E0C912E25BDCEBBB809A3235ABF030C30E48842F8D080AF62C8C4D3280455508DBCD0DA8BF087AB8E7685D9A948995BCFC9A8EB87F3AD86CD5F418AC69E2A4C10BB31FA3829FF38A3C85403809FAC2053EE19C89FAC3056C088F5D51F47FBBC4F36C01BD3D4FC4198B39D9CACCE979880455AB6DB8DA16456539150518FB0B2C7301ED9452E57D0C013B09A04DF13D08816634361744F067F35BF205B6219858D9F4A137D96FE6EF56C4FBBF566202AC3030B602D6D216FC4EEA87439A685D88A39146282BBF3915150203010001A3819130818E300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E041604147DBB69EB8861E140CF4723640086A2666BDC8495304C0603551D200445304330410604551D20003039303706082B06010505070201162B687474703A2F2F7777772E636F7272656F2E636F6D2E75792F636F7272656F636572742F6370732E706466300D06092A864886F70D0101050500038202010056DF1389BE62B70E812173A4D437CAEDB72F9574D789F84B4781EE67EDB829DF21A0FC546767C8572C5BA10A75782121CAA0A8DF6B9CD936028DB801C16F8E7B6CC9A4B2C546A9CA4C0281FAA37B9D3D48E6CA4066D2449D76E055B9A69CA7D143D8F5A0B49DF8F7E5A6A642F302325946722B14EC5E65D5518178CEAA2F8D9689796AFB0FC85BCFB4AE90B65FE37C626CB7A6FF9081B59891731230AFC7E88102687329BB58753DB7D643D5AE4DF242B9F0DFDA310013DAE1B3B6068B5BFDC998B8A213D1BA8FC18A1A9E0FFF82BE0482E52B933E1EB5A20C1BC61AB073897683BC8E3BBB176D14C38BBE7D1526B5A99C177A507A2DEBE99994AE9810BDEE2A5D5DD68E345BAC1E87606B98C7878FD39CB268054907F9A931669CFEBFA759E82CF036D4F2A81982C09EA739F9B19834A31FFACDC9192D78DEB7FD62F093A3FE005BD60AE4F37E7C9728E105EC05344513FF2913618A274FDBB8D2922127B5887767A87ECF243C87080433738F0BB686F8CFEFB2A6241E0B91910050163212D80925DA634EDDDB2DD7E7046BE3631FA9FEA90163C4CA4C146883BC05AC5916FB6EA1076FBB4BBE6D984876257B4A11965408ACA9F337AB83C3D1CD8198C0E54035B89F91E76FE64B20168A537BAC3AD1983554D0D4BFAE7E9A4B1EE975A325B03BE765BF4F95F41DBDC4BAC94D8151C23F5AD912F4211BD695EA3D90FEA993E2
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F9DD19266B2043F1FE4B3DCB0190AFF11F31A69D
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F9CD0E2CDA7624C18FBDF0F0ABB645B8F7FED57A
Blob
0F00000001000000140000003C0BB60D9259E5F84E6DA4DD217992DB6F1D39EF030000000100000014000000F9CD0E2CDA7624C18FBDF0F0ABB645B8F7FED57A68000000010000000800000000C06BD91DE8D4017E000000010000000800000000C0A06C6128D4011D0000000100000010000000FE608AF523AF52C9D92EFD36B0B10C62140000000100000014000000C14BED70B6F73E7C003B008FC73E0E459F1E5DEC620000000100000020000000507941C74460A0B47086220D4E9932572AB5D1B5BBCB8980AB1CB17651A844D20B000000010000002600000043006F006D005300690067006E0020005300650063007500720065006400200043004100000009000000010000002A000000302806082B0601050507030106082B0601050507030206082B0601050507030406082B060105050703032000000001000000AF030000308203AB30820293A003020102021100C7284709B3B86C458C1DFA24F5364EE9300D06092A864886F70D0101050500303C311B301906035504031312436F6D5369676E20536563757265642043413110300E060355040A1307436F6D5369676E310B300906035504061302494C301E170D3034303332343131333732305A170D3239303331363135303435365A303C311B301906035504031312436F6D5369676E20536563757265642043413110300E060355040A1307436F6D5369676E310B300906035504061302494C30820122300D06092A864886F70D01010105000382010F003082010A0282010100C6B5685F1D9415C3A408552DE3A0577AEFE9742ABBB97C57491A115E4F29870C48D66AE78FD47E5724B90689E41C3CEAACE3DA218073210AEF79986C1F08FFA1507DF2981BC9546F3EA528EC21040F45BB073DA1C0FA2A981D4E0693FBF5883BAB5FCB16BFE6F39E4A87ED19EAC29F43E4F181A57F104F3ED14A62AD531BCB83FF0765A5922D66A95BB85AF41DB421914A177B9E32FE562439B2548443F584C2D8BC4190CC9DD668DAE98250A93B68CFB55D02946016B143D9435DDD5D876EEABBB3C96BF603940970DE16117A2BE8768F49109877B9635C8B339775F60B8CB2AB5BDE7420253FE3F311F98768863571C31D8C2DEBE51AAC0F73D582594080D30203010001A381A73081A4300C0603551D13040530030101FF30440603551D1F043D303B3039A037A0358633687474703A2F2F66656469722E636F6D7369676E2E636F2E696C2F63726C2F436F6D5369676E5365637572656443412E63726C300E0603551D0F0101FF040403020186301F0603551D23041830168014C14BED70B6F73E7C003B008FC73E0E459F1E5DEC301D0603551D0E04160414C14BED70B6F73E7C003B008FC73E0E459F1E5DEC300D06092A864886F70D0101050500038201010016CFEE921350AB7B149E33B642206AD415BD09ABFC72E8EF477A90AC51C1644EE988BD434581E366233F12864D19E405B0E637C28DDA0628C90F89A453A9753FB096FBAB4C3355F97826466F1B3698FB4276C182B98EDEFB45F9631B623B3906CA777AA83C09CF6C363D0F0A454B69161A457D330365F95271902695AC4C0CF58B933FCC75748598BAFF627A4D1F89FEAEBD940099BF11A5DCE079C5160B7D02611DEA85F902154FE75A894E146FE3374B85F5C13C61E0FD0541B2927FC31DA0D0AE5264606B18C6269CD8F564E4361A629F8A0F3EFF6D4E19564E20916C9F34333A3457503A6F815E06C6F53E7C4E8E2BCE65062E5DD22A53745ED36E279E8F
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F9CD0E2CDA7624C18FBDF0F0ABB645B8F7FED57A
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F9B5B632455F9CBEEC575F80DCE96E2CC7B278B7
Blob
0F00000001000000200000001E2A4EF9C6208AEA146FE6074589F80FB1C7A73D2D20511B6F47D0E61874EB6A030000000100000014000000F9B5B632455F9CBEEC575F80DCE96E2CC7B278B77E00000001000000080000000040D10FFC47D5017F000000010000000C000000300A06082B060105050703031D0000000100000010000000CF9381E42222DF55D1E3C07829CDFD1A1400000001000000140000009D93C6538B5ECAAF3F9F1E0FE59995BC24F6948F6200000001000000200000000376AB1D54C5F9803CE4B2E201A0EE7EEF7B57B636E8A93C9B8D4860C96F5FA753000000010000002400000030223020060A2B06010401828F09020130123010060A2B0601040182373C0101030200C00B000000010000002E000000410066006600690072006D0054007200750073007400200043006F006D006D00650072006300690061006C000000090000000100000054000000305206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B06010505070308060A2B0601040182370A030406082B0601050507030606082B060105050703072000000001000000500300003082034C30820234A00302010202087777062726A9B17C300D06092A864886F70D01010B05003044310B300906035504061302555331143012060355040A0C0B41666669726D5472757374311F301D06035504030C1641666669726D547275737420436F6D6D65726369616C301E170D3130303132393134303630365A170D3330313233313134303630365A3044310B300906035504061302555331143012060355040A0C0B41666669726D5472757374311F301D06035504030C1641666669726D547275737420436F6D6D65726369616C30820122300D06092A864886F70D01010105000382010F003082010A0282010100F61B4F67072BA115F50622CB1F01B2E373450644492CBB492514D6CEC3B7AB2C4FC641329457FA12A75B0EE28F1F1E8619A7AAB52DB95F0D8AC2AF853579322DBB1C6237F2B15B4A3DCACD715FE942BE94E8C8DEF9224864C6E5ABC62B6DAD05F0FAD50BCF9AE5F050A48B3B47A5235B7A7AF8333FB8EF9997E320C1D62889CF94FBB945EDE3401711D474F00B31E22B266A9B4C57AEAC203EBA457A05F3BD9B6915AE7D4E2063C435763A0702C937FDC747EEE8F1761D7315F297A4B5C87A79D942AA2B7F5CFECE264FA3668135AF44BA541E1C3032659DE63C935E504E7AE33AD46ECC1AFBF9D237AE242AAB570322280D49757FB728DA75BF8EE3DC0E79310203010001A3423040301D0603551D0E041604149D93C6538B5ECAAF3F9F1E0FE59995BC24F6948F300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106300D06092A864886F70D01010B0500038201010058ACF4040ECDC00DFF0AFDD4BA165F29BD7B68995849D2B41D374D7F277D46065D43C6862E3E73B2267D4F93A9B6C42A9AAB219714B1DE8CD3AB8915D86B24D4F116AED8A45CD47F518EED1801B19363BDBCF861809A9EB1CE4270E2A97D06257D27A1FE6FECB31E24DAE34B551A003B35B43BD9D75D30FD811389F2C2062BED67C48EC943B25C6B158902BC62FC4EF2B533AAB26FD30AA250E3F63BE82E44C2DB6638A9335648F16D1B338D0D8C3F60379DD3CA6D7E347E0D9F72768B1B9F72FD5235414502962F1CB29A734921B149474547B4EF6A3411C94D9ACC59B7D6029E5A4E65B594AE1BDF29B016F1BF009E073A1764B504B52321990A953B977CEF
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F9B5B632455F9CBEEC575F80DCE96E2CC7B278B7
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F90CC7521EAB33F228EAA835E4E50292E31D281E
Blob
0F000000010000002000000028BDB301E6E6B6FABDC450B244637C21441F4606B34174DC10602F4B677725D8030000000100000014000000F90CC7521EAB33F228EAA835E4E50292E31D281E1D00000001000000100000000AC70B99F3E34D7F3055A063B47B98F71400000001000000140000003CB69C385AECB5D4220B40BE630F088B28EE0C1962000000010000002000000092C4DB06C42A130D663574D7741B7F93C806FD6714DCE890E84B568FAE86E64C090000000100000022000000302006082B0601050507030206082B06010505070304060A2B0601040182370A030C0B000000010000005E0000005400720075007300740046006100630074006F0072007900200043006C00690065006E007400200052006F006F007400200043006500720074006900660069006300610074006500200041007500740068006F007200690074007900000020000000010000005C0600003082065830820440A0030201020211008E594058B7589FBD178492B3CC3AC793300D06092A864886F70D01010B05003081B4310B3009060355040613025A413110300E06035504080C0747617574656E673115301306035504070C0C4A6F68616E6E657362757267311D301B060355040A0C145472757374466163746F727928507479294C746431243022060355040B0C1B5472757374466163746F727920504B49204F7065726174696F6E733137303506035504030C2E5472757374466163746F727920436C69656E7420526F6F7420436572746966696361746520417574686F72697479301E170D3137313230353131343833365A170D3437313132383131343833365A3081B4310B3009060355040613025A413110300E06035504080C0747617574656E673115301306035504070C0C4A6F68616E6E657362757267311D301B060355040A0C145472757374466163746F727928507479294C746431243022060355040B0C1B5472757374466163746F727920504B49204F7065726174696F6E733137303506035504030C2E5472757374466163746F727920436C69656E7420526F6F7420436572746966696361746520417574686F7269747930820222300D06092A864886F70D01010105000382020F003082020A0282020100EAC06428738247B6C0CEAD88DCD2E1EE4852F310E74E0886E02FEF38264A17F07B431BAA514D22320753760AB760B1AA3F471A4BFE98CAF3D4A85B78DE939EFC34257490E816E69D63553E7F5573A6126FF7A873CD969231AEB4C401485D117FF67D82BE5D0DE9A32BEB312E39E65A4A9EDC066C2898F671FCF05A42F6BBC04126E6F9CF41A0F87E6CC193C5E363E7F6944224D86B67D1E7751B008E0A0427C7E01B37BB5EE02EC9A504730DFAF5D638A4A4D60696162B801077D0F769F16992A9AAFCC321B6FD13310938FFC3F56FE347B321E8F665D4B8D35B2E7CDD0A4FBA49DF6A8FB0426CB64769AEB3696B982862F3FC77F71F76344638B72317B9D42DDA57180309A5559DA1F20C00BC25396287D14007C00ECBCED40B7A5091EF90270ED857008892E217C969C1351EA46FC0A98634374452BC43B27D898FA5A359C0D0388CA7CB56FD195BC195B5E540BDF982C4C922D4329D85A3EF4A74A715063E7022482B0C23ACD0625CB97CF785D98DF8C5D3978F5EEAF00CD0B19A084F990681E41A297CA4FA16279B7351A9C524F62518A8B332D74AE7D35AD99BC2323B04868D587355902E684849543A3BEE25A099E25C036653CC6ED40D111D79AAD4F1650B8FCD4F5401100C3F5D8D0064341F0620ECA1D6920BC9BEB662875409FCFE1A73792111655C9ED5B390C5A496BE23AB7D8159F13A9B57AF5D816EFAD14BB10203010001A3633061301D0603551D0E041604143CB69C385AECB5D4220B40BE630F088B28EE0C19301F0603551D230418301680143CB69C385AECB5D4220B40BE630F088B28EE0C19300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106300D06092A864886F70D01010B050003820201000537162E8A1301C47C2669E8330552FD085A82128DCF0A13597837BAC544173AE2153FF38FCCDC572D13A33EE578BB2B919D3EE1426C55756E682C943F9B8237FC3C2F7E1C66F155C983D288C09BAC93FED9602F3A5324BFB52F555F61B3534F04DB6E36AB1D2F28C3D522BB18A4271E2BA7D17C517E822B77FF75759B8981E7D0C1DBF319BF4B6C0712040EE2060B2948663A3526D4BDE10574218AF5C6CF16502B14C564EA16FC4D21558C28EF1CCCEA109B4D18AA8E4DDC01C6454DF1C76EFB4780A730C727FCAD0A819BF75655DABB1F95F75F1078238BA3A065500463F33E41738714DC5A832738D0230FA5E82C8E162699EBE577957EE98F858F411490FF3C89C7E55C8AD7630C6973A5381D6DA9631C957FF7E29410D0ED56A047A140251FB9B2BCBA6ACD5E36800EB2558B3C4BE681C1CA2769DFB32E38FCBFB3AA1DB26D2052DC8C3F1B837AAC1B79D3A4E8293014EF788CE93E58E2D9CFF57BD361B91C0136B0EC30885B9FB3183A46FA16E5CB84B83904974E2400475D20F38CF1A46F3203E04A65E58CBA15D45458BCB1507A702EAC430A0DE6A6F0222E5F4A1A006C7193DB1A64EE19717D05B6988CDF80DD8AA83A28354314FEF3043A8F21380F4E13838EDFDBFBD9DAE0E5F7463CEFDAE86E4C9E01FA3265BB521320693B9B1B7F93CF30338EB38A23FC07D3696012F744BD032FA8F047157727D861B790B5
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F90CC7521EAB33F228EAA835E4E50292E31D281E
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F6108407D6F8BB67980CC2E244C2EBAE1CEF63BE
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F6108407D6F8BB67980CC2E244C2EBAE1CEF63BE
Blob
0F0000000100000030000000E0DA58676E3A50DE9D8CB3AA5FFEFFDAE691BA9705B3ABE41A09270D63A3284F58247CE20D354B579EB548755912E833030000000100000014000000F6108407D6F8BB67980CC2E244C2EBAE1CEF63BE1D00000001000000100000002A5E1BD40940BEAA4BF73F7BA7564E2E140000000100000014000000D3ECC73A656ECCE1DA769A56FB9CF3866D57E58153000000010000001F000000301D301B060567810C010130123010060A2B0601040182373C0101030200C0620000000100000020000000E35D28419ED02025CFA69038CD623962458DA5C695FBDEA3C22B0BFB258970920B000000010000002200000041006D0061007A006F006E00200052006F006F00740020004300410020003400000009000000010000004C000000304A06082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B06010505070308060A2B0601040182370A0304060A2B0601040182370A030C2000000001000000F6010000308201F230820178A0030201020213066C9FD7C1BB104C2943E5717B7B2CC81AC10E300A06082A8648CE3D0403033039310B3009060355040613025553310F300D060355040A1306416D617A6F6E3119301706035504031310416D617A6F6E20526F6F742043412034301E170D3135303532363030303030305A170D3430303532363030303030305A3039310B3009060355040613025553310F300D060355040A1306416D617A6F6E3119301706035504031310416D617A6F6E20526F6F7420434120343076301006072A8648CE3D020106052B8104002203620004D2AB8A374FA3530DFEC18A7B4BA87B464B63B062F62D1BDB087121D200E863BD9A27FBF0396E5DEA3DA5C981AAA35B2098455D16DBFDE8106DE39CE0E3BD5F8462F3706433A0CB242F70BA88A12AA075F881AE6206C481DB396E29B01EFA2E5CA3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020186301D0603551D0E04160414D3ECC73A656ECCE1DA769A56FB9CF3866D57E581300A06082A8648CE3D040303036800306502303A8B21F1BD7E11ADD0EF58962FD6EB9D7E908D2BCF6655C32CE328A9700A470EF0375912FF2D9994284E2A4F354D335A023100EA75004E3BC43A941291C958469D211372A7889C8AE44C4ADB96D4AC8B6B6B49125333ADD7E4BE24FCB50A76D4A5BC10
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F5C27CF5FFF3029ACF1A1A4BEC7EE1964C77D784
Blob
0F0000000100000014000000AADD4671641F37DC6A4F87469D90B4C1A35315F00B0000000100000014000000430065007200740052005300410030003100000009000000010000003E000000303C06082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B0601050507030806082B06010505070309030000000100000014000000F5C27CF5FFF3029ACF1A1A4BEC7EE1964C77D78420000000010000004E0400003082044A30820332A003020102020103300D06092A864886F70D01010505003041310B3009060355040613024B52310D300B060355040A13044B495341310F300D060355040B1306524F4F5443413112301006035504031309436572745253413031301E170D3030303330323135303030305A170D3130303330333134353935395A3041310B3009060355040613024B52310D300B060355040A13044B495341310F300D060355040B1306524F4F544341311230100603550403130943657274525341303130820122300D06092A864886F70D01010105000382010F003082010A0282010100CECFEDE1E8561DC94B32609B2AB7978761063468CB17AEC078C5C6115B4B7C97ABB96C4E2F00F6532CE9E19C5A906A3D7A3838355AAD1C0A5985BBF563670913E9264FD83C5DEF5342DE4562E43ECD72A4FAB3C0E01F8E94E2652D55C115922C6FF343D43505053437A02CB4735BF12726949AF5BA12CCFA7835A2AD54D5668F11EAA6194DD71335547B9197034763B0A90F68BED2F49EEA8DB57B44B5B92D38C900E3E5BFC675890399FF8C4B080FC20531A44D1711CEC3750F6BB05FD0AC86AD7DE9A088B9C612D6C03A2CD26F6C271DAAFF459BC603100269F906EF9F22A0383882C82411ACA19E8F4DBE785FDFBA3F83037D51A3F8C75DA891681F1E72DD0203010001A382014B30820147301D0603551D0E04160414FF8A46723358E8488822AA1768DA1648098B3591301F0603551D23041830168014FF8A46723358E8488822AA1768DA1648098B3591300E0603551D0F0101FF04040302010630150603551D20040E300C300A06082A831A8C9A44020130300603551D1104293027A42530233121301F06035504030C18ED959CEAB5ADECA095EBB3B4EBB3B4ED98B8EC84BCED84B030300603551D1204293027A42530233121301F06035504030C18ED959CEAB5ADECA095EBB3B4EBB3B4ED98B8EC84BCED84B030120603551D130101FF040830060101FF020101300C0603551D240405300380010030580603551D1F0451304F304DA04BA04986476C6461703A2F2F6469727379732E726F6F7463612E6F722E6B723A3338392F434E3D524F4F542D5253412D43524C2C204F553D524F4F5443412C204F3D4B4953412C20433D4B52300D06092A864886F70D010105050003820101002C3CA4236C42F8892847507CE3E6E7232D3636C6882A9198FB1E7C0FAB9D11AD75ACE45C6B31117433626FD4069111C67274982FB062FB3429AF14F2C664E0BFABCB57B9619CF3624D3379D7662A51CCDC00540501567E8CB68E13F42D9951E19A78BC55514A49DA5B0B82FB433DDACD9309CBB5A309C3B07D5948A29BD8FB37C36F0E37EA0597BFD26EA1C8E8C3FBF3AD32C855923442E0D412E5D4ED218AE79892FF5CD7A566AABFF13A7C2DC2E0553505DA916A0753D185B194C7260D1B682908C121930F6BA260B853AF44D9645DD36E9B8412783118DA73BFAC24F8AB2DBF0E7EBA7B09CA5A89A82C52CC4C74ADD95FB3B7D605F7415F71E56619062579
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F5C27CF5FFF3029ACF1A1A4BEC7EE1964C77D784
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F517A24F9A48C6C9F8A200269FDC0F482CAB3089
Blob
0F0000000100000030000000FA95CF8212A28D5983C7C9B5891589555DA7B46A4BA83D5ECCB3D6F4B9C4B2DB4FC23358C57C9CBE55EFD567D2521D03030000000100000014000000F517A24F9A48C6C9F8A200269FDC0F482CAB30891D00000001000000100000009E6391C4D5AE94C58832DB9F7431D29D140000000100000014000000CBD0BDA9E1980551A14D37A28379CE8D1D2AE4846200000001000000200000007E37CB8B4C47090CAB36551BA6F45DB840680FBA166A952DB100717F43053FC25300000001000000230000003021301F06096086480186FD6C020130123010060A2B0601040182373C0101030200C0090000000100000034000000303206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B060105050703080B00000001000000380000004400690067006900430065007200740020004100730073007500720065006400200049004400200052006F006F007400200047003300000020000000010000004A02000030820246308201CDA00302010202100BA15AFA1DDFA0B54944AFCD24A06CEC300A06082A8648CE3D0403033065310B300906035504061302555331153013060355040A130C446967694365727420496E6331193017060355040B13107777772E64696769636572742E636F6D312430220603550403131B4469676943657274204173737572656420494420526F6F74204733301E170D3133303830313132303030305A170D3338303131353132303030305A3065310B300906035504061302555331153013060355040A130C446967694365727420496E6331193017060355040B13107777772E64696769636572742E636F6D312430220603550403131B4469676943657274204173737572656420494420526F6F742047333076301006072A8648CE3D020106052B810400220362000419E7BCAC4465EDCDB83F58FB8DB157A9442D0515F2EF0BFF10749FB562525F667E1FE5DC1B45790BCCC6530A9D8D5D02D9A959DE025AF6952A0E8D384A8A49C6BCC60338075F55DA7E096EE27F5ED045200F597610D6A024F02DDE36F26C2939A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020186301D0603551D0E04160414CBD0BDA9E1980551A14D37A28379CE8D1D2AE484300A06082A8648CE3D0403030367003064023025A48145026B124B75744FC823E370F27572DE7C89F0CF9172619E5E10925956B983C710E738E95826367DD5E434863902307C3653F030E562633A99E2B6A33B9B34FA1EDA1092715E9113A7DDA46E92CC32D6F52166C72FEA96636A6545929501B4
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F517A24F9A48C6C9F8A200269FDC0F482CAB3089
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F48B11BFDEABBE94542071E641DE6BBE882B40B9
Blob
0F00000001000000140000006576BCF08464F0A055B87AFF04A585F4308A4707030000000100000014000000F48B11BFDEABBE94542071E641DE6BBE882B40B97E00000001000000080000000000042BEB77D5017F000000010000000C000000300A06082B060105050703031D00000001000000100000004C6FCD1D6CF75D100F89AA6EEC7BABEC140000000100000014000000CCCCEFCC2960A43BB192B63CFA32628FAC25153B6200000001000000200000007600295EEFE85B9E1FD624DB76062AAAAE59818A54D2774CD4C0B2C01131E1B3090000000100000034000000303206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B060105050703080B000000010000005600000054005700200047006F007600650072006E006D0065006E007400200052006F006F0074002000430065007200740069006600690063006100740069006F006E00200041007500740068006F0072006900740079000000200000000100000076050000308205723082035AA00302010202101F9D595AD72FC20644A5800869E35EF6300D06092A864886F70D0101050500303F310B30090603550406130254573130302E060355040A0C27476F7665726E6D656E7420526F6F742043657274696669636174696F6E20417574686F72697479301E170D3032313230353133323333335A170D3332313230353133323333335A303F310B30090603550406130254573130302E060355040A0C27476F7665726E6D656E7420526F6F742043657274696669636174696F6E20417574686F7269747930820222300D06092A864886F70D01010105000382020F003082020A02820201009A25B8ECCCA275A87BF7CE5B598AC9D186120854EC9CF2E746F688F37CE9A5DF4C4736A41B011C7F1E578A8DC3C5D121E3DA243F482BFB9F2EA194E72C1C93D1BF1B01875399CEA7F50A217677FFA9B7C673944F46F7104937FAA859495D6A810756F28AF906D0F770224DB4B741B932B8B1F0B1C39C3F70FD53DD81AAD86378F6D8536EA1AC6A8424725486C6D2B2CA1C0E7981D6B5706208012E4E4F0ED511AFA9AFE59ABFDCCC876D26E4C957A2FB96F9CCE13F538C6C4C7E9B53080B6C17FB67C8C2ADB1CD80B497DC76011615E96AD7A4E17847CE86D5FB31F3FA31BE34AA28FB704C1D49C7AF2C9D6D66A6B68D647EB5206A9D3B81B68F4000674B8986B8CC65FE1553E904C1D65F1D44D70A2F279A467DA10D75AD548615DC493BF196CE0F9BA0ECA37A5DBED52A7542E57BDEA5B6AAAF28ACAC90AC38B7D56835267ADCF73BF3FD459BD1BB43786E6FF142546A98F00DAD97E9525EE9D56A72DE6AF71B6014F4A5E4B67167AA1FEAE24DC14240FE674617382F473F719CAEE521CA612D6D07A8847C2DEE5125F163909EFDE157886BEF8A236DB1E6BD3FADD13D960B858DCD6B27BBB7059BECBB91A90A071202974E2090F0FF0D1EE2413BD3403AE78D5DDA66E402B00752985C0E8E339CC2A695FB55196E4C8EAE4B0FBDC1384D5E8F841D66CDC56096B4525A05898E957A98C1913C9523B20EF479B4C97CC14A210203010001A36A3068301D0603551D0E04160414CCCCEFCC2960A43BB192B63CFA32628FAC25153B300C0603551D13040530030101FF30390604672A07000431302F302D020100300906052B0E03021A050030070605672A0300000414039BF02213FF952836D3DC9EC032FB313A8A5165300D06092A864886F70D0101050500038202010040804AFA26C9CE5E30DD4F86747658F5AEB3833378A47A7417194EE952B5B9E00A7462AA68CA78A04C9A8E2C232ED56A1224BFD468D38AD0D89C9FB41F0CDE387E5738FC8DE24F5E0C9FAB3BD2FF7597CBA4E36708FFE5C016B548017DE9F90AFF1BE56A69BF7821A8C2A723A986AB7656E80E0CF613DD2A668A64493D1A188790049F4252B74FCBFE47417635EFFF00763645329BC646855DE224B01EE3489698574794557A0F41B14424F3C1FE1A6BBF88FDC1A6DA93605E814A99209C486619B50079540FB82C2F4BBCA95D5B607F8C87A5E052632ABED83B854015FE1EB6653FC54BDA7EB57A3529A32E7A986022A3F47D274E2DEAB4743CE90FA4330F1011BC1301D6E50ED3BFB512A2E14523C0CC086E61B789AB83E3241EE65D07E71F203ECF67C8E7AC306D274B686E4B2A5C020834DBF876E467A3269C3FA232C24AC58118311056AA84EF2D0AFFB81F77D2BFA558A062E4D74B91758D8980987E6DCB534E5EAFF6B2978597B9DA5506B924EED7C6381E631B123B95E158ACF2DF84D55F992F0D555BE638DB2E3F72E94885CBBB29138F1E3855B9F3B2C43099234E5DF248A1120CDC129009905491033C47E5D5C965E0B74B7DEC47D3B30B3EAD9ED074000EEBBD51ADC0DE2CC0C36AFEEFDC0BA7FA46DF60DB9CA659507523697393B2F9FC02D347E671CE1002EE278C84FFAC450D135C8332E025A5862C7CF412
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F48B11BFDEABBE94542071E641DE6BBE882B40B9
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F44095C238AC73FC4F77BF8F98DF70F8F091BC52
Blob
0F000000010000001400000001A8CC75ED5DE358B06BFB26E58B857C72AD9577030000000100000014000000F44095C238AC73FC4F77BF8F98DF70F8F091BC5268000000010000000800000000809EF40C18D5017E000000010000000800000000C0A06C6128D4011D00000001000000100000004748367A32E2D9519C507DE0DB925E35140000000100000014000000A2760E39786B8FBA2D714A08F7A27B6E00A2642553000000010000001F000000301D301B060567810C010130123010060A2B0601040182373C0101030200C0090000000100000020000000301E06082B0601050507030406082B0601050507030106082B06010505070308620000000100000020000000CE7DD096C8FDE2BF5C438EDB574BD6454385334EE8FF106C0F93D5051BE6BAC30B000000010000003C000000430065007200740050006C0075007300200043006C00610073007300200033005400530020005000720069006D006100720079002000430041000000200000000100000087030000308203833082026BA003020102021100AF3F646B56028666C6D843F94B7D96CF300D06092A864886F70D0101050500303F310B30090603550406130246523111300F060355040A130843657274706C7573311D301B06035504031314436C61737320335453205072696D617279204341301E170D3939303730373137313430305A170D3139303730363233353935395A303F310B30090603550406130246523111300F060355040A130843657274706C7573311D301B06035504031314436C61737320335453205072696D61727920434130820122300D06092A864886F70D01010105000382010F003082010A0282010100BD659A2343003CF9250143985B4634376737F45B578EA3DECD8C2F41B3153DE5988BF2CC5CA7C7AF35C7B3A74FC7102957E903898372067652C170023740EDF0CE8BB1B189AC02A85BDDDCD5434506DC28B6E9511B6AEEF37B48C59D11AE8DA67293C0254291A83E46E2684C8140B042D37ABE7B47D247500CA412A6CAE412D0C07C3A3C01A9CA0296DE825AC5FB19BA3C9CD80F741F9818AE945032075210114A4BEC58552CD49E4B947B05D272DF06F08DCB089EE4EEB444AD82F11B616AF1B3F81631364224BA90BFB57E616EC2590C5479B44C88281ECC1BDF848B23C8BEAF07F291B2DA8DCA8C5F7C283C7C896C0659BD3ECEC582D36AC9AC6855EEC5AF0203010001A37A3078300F0603551D13040830060101FF02010A300B0603551D0F040403020106301D0603551D0E04160414A2760E39786B8FBA2D714A08F7A27B6E00A2642530390603551D1F04323030302EA02CA02A8628687474703A2F2F7777772E63657274706C75732E636F6D2F43524C2F636C6173733354532E63726C300D06092A864886F70D01010505000382010100B59F689CC492F0777C13C215BC1CD40E6E7428A1FA86D2081B25FCE47BD97DD30258676F046E50EE7B4A010263BF4236D6BE0CFE220C993D8EF3AE1D94D6AAEAA63DE3439E47BB09C9CBEECEA12C0FAA7CDF7C7392E54BB904C43BDB20FE60F90C6E781A3D48D7274898B591ACA4DC22B3E79D5FECE54062268F7A17C6EAFB0AD6435B90DB3616ED982E9E5FAC1407822A50BFA6BF6FA6073472B66168EC5198195377E8C8BFF6217BBCB0DE7F743AF91534389AFB8933F0120D9FE8F1966DF61D487E3E12EFFA066759DEB3B2D6970B3B405742B2C17BC66DD826523425D285B6A10A0ADDAA94AA4E7B2093DDA4804356CFB6C4E058E96C958F626E5806AF78
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F44095C238AC73FC4F77BF8F98DF70F8F091BC52
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F435F85F0108DA684E7BFD517C90C627BB9A6CF5
Blob
0F000000010000004000000057E9594F2EBFD3FBCD4B7DB6434BA18E94CADFA10B89A846A4EFDBEC772D09772876BFB155E5D4E0073A2C3F5C80958C9268F503104EB2F06319C364033AAE0C030000000100000014000000F435F85F0108DA684E7BFD517C90C627BB9A6CF51D0000000100000010000000DD05B5B4B95053F12B5021FDF5F9D6D3140000000100000014000000D1A70816079EE9BD4ED3D7205396590627D7884D62000000010000002000000034FF2A4409DC1383E9F8966E8ADFE5719EBA373FD0AD5E2F49F90EE07CF5D4C109000000010000002C000000302A06082B0601050507030106082B0601050507030206082B06010505070304060A2B0601040182370A030C0B000000010000002C000000560052004B00200047006F0076002E00200052006F006F00740020004300410020002D0020004700320000002000000001000000120600003082060E308203F6A0030201020203030D40300D06092A864886F70D01010D0500308196310B30090603550406130246493121301F060355040A0C1856616573746F72656B6973746572696B65736B757320434131293027060355040B0C2043657274696669636174696F6E20417574686F7269747920536572766963657331193017060355040B0C105661726D656E6E6570616C76656C7574311E301C06035504030C1556524B20476F762E20526F6F74204341202D204732301E170D3137313231343038353033315A170D3338313231333038353033315A308196310B30090603550406130246493121301F060355040A0C1856616573746F72656B6973746572696B65736B757320434131293027060355040B0C2043657274696669636174696F6E20417574686F7269747920536572766963657331193017060355040B0C105661726D656E6E6570616C76656C7574311E301C06035504030C1556524B20476F762E20526F6F74204341202D20473230820222300D06092A864886F70D01010105000382020F003082020A0282020100BFD6004A890E2F233B727F732065A05F16C57B5E5C06F966732082F56296179451FE9B35E8F20E5F7F21951C62C0E4F982785CEF55C0C7FC0D79F3B64C82360AB04BFC2D61A60B88B84FB905AE06CC09D37B4A0D6889134500A39D5CE67EA51EE7062FF06B45A4A2D49B87CA986560EB5ACCA295EC935B4AA5767D5F75D22D95477A69B17388AC652479207F8886456412E814C73890971CF141F7B8E037FFB6B5CC315ACC28FF84A853565872DD63C03B471D8C5643DE54C708CC3F7AE8C203CA34BC8595E7C3D120D2F44A2BF1E9EF7D7A5BB504605204789DE8E729436E3B0100D82ACC0626026A843FF308AA3E14FDF7F78EB9803042A5057CCDF3A1842278114109D58C800B4E588D98D4733D15F76D993DE484F3473C2F6B991484213B9C566552F58FAB0DA96382CC3952B1EAA759E3A3C00F793EE8953E46ACB9DDB85785F697FF9EB308E63756DEFCA633388DBF0D6B96A68BE9704AB76744A8892E90E6978BEE6F9CAC7345FB6938FD56F805EBA311CCC8F2F2C4B0F8D719F806E696607DD4E4B6F3D49B195FDF3183CEB8E07596296D3C2FE859C04A9FBAECFA93F6916F2D2414922BBEAD9D085835E1612A13DFD8D07CF156F36B742DC4E3EE80612CAB0A5D55494B61AF954EB1B752D699D3EF24D01C06489A1BC2179CB2E68BFD2D72B1973C184951567C55E412BE50891D69281948C3DA2281A9E0E005AABD0203010001A3633061301F0603551D23041830168014D1A70816079EE9BD4ED3D7205396590627D7884D301D0603551D0E04160414D1A70816079EE9BD4ED3D7205396590627D7884D300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF300D06092A864886F70D01010D050003820201002D508FC166EF896513C378D4CCCC5A976FEC8F6054DE7364B70DE8E13BA5ACCF85B696394C44A43B59370C80401633727448E08425A31B2D0D00E13360C2C15F760FB3A24B70C52640CD10FA58F481538FAEDC27488595A6A2CE4A4219BF95352064DF426A66750D565B4B75963553831C50A0E5C7949DCBD6B23D934ACB949071C86F6F619B6EF1D088EBC46F3E833440549847FD4CCCCA1C8D83E0316D3035B3DF24C48D36DDC0D4FC5986ACA3F050BE184A407857A08DDC0D92B5C9966CA7395D3EBCAE2BDA71563DD12754AAB4067CD8C03C6DC59DF23C55BEF1610ED81CD1A87D6FD8B31742B7D5126526CEFB9485C66C6D5AE56E7C803D3B9BCE2FA3F8BDF292225C6E0D7A080A3E5CDDD3FFF617D62567C1FB867C54576A7352BD07A54905D9118B9546F2DC62068AAC810457C9B854461889C4681F151E950258AAC4619F2E0F44DB4C01826895FB31FFD0C2044E7D47B1F799CDE50EC28C17124496823D91981A97B6674170D28EBCD16220768012ED0EB9F99F26894CD74F6BA96EA5C1FABB04135D66478E89A82AB1F65F1716DCFD59126E276DDDBDE8FDC7117DF2F556CFAA7ED0FF13228562F947EA68ED0F93D85861CACF75E3146527E0127F231ED6ED0F3EBD015BE61426235DE004477425ACC19533A83360299D9D8663F5D0BD2F161126D399298F82967A5CAFFC52EEF38EF90ABC5541D299F41BA77D66
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F435F85F0108DA684E7BFD517C90C627BB9A6CF5
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F373B387065A28848AF2F34ACE192BDDC78E9CAC
Blob
0F0000000100000020000000927824E958A132AFBCADD9E12357A0F9788AB99C5669E1EC3825E1EB5F6F5454030000000100000014000000F373B387065A28848AF2F34ACE192BDDC78E9CAC1D000000010000001000000095B4475FEF63CAF7452D10FAA6F6362B14000000010000001400000052D8883AC89F7866ED89F37B387094C9020236D0530000000100000020000000301E301C06062B811F01110130123010060A2B0601040182373C0101030200C062000000010000002000000055926084EC963A64B96E2ABE01CE0BA86A64FBFEBCC7AAB5AFC155B37FD76066090000000100000034000000303206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030806082B060105050703030B000000010000003E00000041006300740061006C00690073002000410075007400680065006E007400690063006100740069006F006E00200052006F006F00740020004300410000002000000001000000BF050000308205BB308203A3A0030201020208570A119742C4E3CC300D06092A864886F70D01010B0500306B310B3009060355040613024954310E300C06035504070C054D696C616E31233021060355040A0C1A416374616C697320532E702E412E2F30333335383532303936373127302506035504030C1E416374616C69732041757468656E7469636174696F6E20526F6F74204341301E170D3131303932323131323230325A170D3330303932323131323230325A306B310B3009060355040613024954310E300C06035504070C054D696C616E31233021060355040A0C1A416374616C697320532E702E412E2F30333335383532303936373127302506035504030C1E416374616C69732041757468656E7469636174696F6E20526F6F7420434130820222300D06092A864886F70D01010105000382020F003082020A0282020100A7C6C4A529A42CEFE518C5B050A36F513B9F0A5AC9C248380AC21CA0187F91B587B9403FDD1D681F0883D52D1E88A0F88F568F6D9902929016D55F086C89D7E1ACBC20C2B1E083518A694D00965A6F2FC0447EA30EE491CD58EEDCFBC71E4547DD27B908019FA6211DF5412D2F4CFD28ADE08AAD22B456658E86548F934329DE394678A33023BACDF07D1357C05DD2836B484CC4AB9F805A5B3ABDC9A7223F8027335B0EB78A0C5D073708CB6CD27A47224435C5CCCC2E8EDD2AEDB77D660D5F615122551BE346E3E33DD035629ADBAF14C85BA1CC891BE13026FCA09B1F81A7471F04EBA33992069F99D3BFD3EA4F509C19FE96871E3C65F6A31824838610E7543EA83A76244F8121C5E30F02F893944720BBFED40ED368B9DDC47A8482E3535479DDDB9CD2F2079B2EB6BC3EED856DEF2511F2971A4261F74A97E88BB11007FA6581B2A239CFF73CFF18FBC6F15A8B59E202AC7B92D04E144F5945F60C5E285FB0E83F45CFCFAF9B6FFB84D3775A956FAC94849EEEBCC04A8F4A93F84421E2314561504E10D8E3357C4C19B4DE05BFA3069FC8B5CDE41FD717060D7A9574550D681AFC101B62649D6DE095A0C39407570D14E6BD05FBB89FE6DF8BE2C6E77E96F653C58034502858F01250711730BAE67863BCF4B2AD9B2BB2FEE1398C5EBA0B2094DE7B83B8FFE3568DB711E93B8CF2B1C15D9DA40B4C2BD9B218F5B59F4B0203010001A3633061301D0603551D0E0416041452D8883AC89F7866ED89F37B387094C9020236D0300F0603551D130101FF040530030101FF301F0603551D2304183016801452D8883AC89F7866ED89F37B387094C9020236D0300E0603551D0F0101FF040403020106300D06092A864886F70D01010B050003820201000B7B7287C060A6494C8858E61D88F7146448A6D8580A0E4F1335DF351DD4ED0631C8813E6AD5DD3B1A32EE903D11D22EF48EC3632E2366B067BE6FB6C0133960AAA23425937552DEA79DAD0E878952716A163C191D83F89A2965BEF43F9AD9F0F35A872171804DCBE0389B3FBBFAE0304DCF86D365101918D19702B12B724268ACA0BD4E5ADA18BF6B9881D0FD9ABE5E1548CD1115B9C0295CB4E888F73E36AEB762FD1E62DE7078101C485BDABCA438BA67ED553E5E57DFD403404C81A4D24F63A709420914FC00A9C280734F2EC040D9117B48EA7A02C0D3EB2801265874C1C073226D9395FD397DBB2AE3F682E32C975F4E1F9194FAFE2CA3D8761AB84DB2384F9BFA1D48607926E2F3FDA9D09AE8708F497AD6E5BD0A0EDB2DF38DBFEBE3A47DCBC79571E8DAA37CC5C2F87492041B86ACA4225340B6ACFE4C76CFFB9432C0359F763F6EE5906EA0A626A2B82CBED12B85FDA768C8BA012BB16C741DB87395E7EEB7C725F0004C00B27EB60B8B1CF3C0509E25B9E008DE3666FF37A5D1BB54642CC927B54B927E65FFD32DE1B94EBC7FA44121904177A6391FEA9EE39FD0666F05ECAA767EBF6B16A0EBB5C7FC92542F2B11272537784C516AB0F3CC585D14F16A4815FFC207B6B18D0F8E5C5046B33DBF01984FB25954473E347B786D56932E73EA662878CD1D14BFA08F2F2EB82E8EF2148ACCE9B57CFB6C9D0CA5E196
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F373B387065A28848AF2F34ACE192BDDC78E9CAC
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F18B538D1BE903B6A6F056435B171589CAF36BF2
Blob
0F00000001000000200000009F0A5682A992F8534CE24CE23B6C04A1A258B5E42B2B8196B24DA0690F2240F8030000000100000014000000F18B538D1BE903B6A6F056435B171589CAF36BF27E00000001000000080000000040D0D1B0FFD4017F000000010000000C000000300A06082B060105050703011D000000010000001000000036544967D6E5CCC2E6A9BEB2BF190A4F140000000100000014000000AD6CAA94609CEDE4FFFA3E0A742B6303F7B659BF6200000001000000200000004B03F45807AD70F21BFC2CAE71C9FDE4604C064CF5FFB686BAE5DBAAD7FDD34C53000000010000002500000030233021060B6086480186F8450107300130123010060A2B0601040182373C0101030200C0090000000100000034000000303206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B060105050703080B000000010000003800000074006800610077007400650020005000720069006D00610072007900200052006F006F00740020004300410020002D00200047003300000020000000010000002E0400003082042A30820312A0030201020210600197B746A7EAB4B49AD64B2FF790FB300D06092A864886F70D01010B05003081AE310B300906035504061302555331153013060355040A130C7468617774652C20496E632E31283026060355040B131F43657274696669636174696F6E205365727669636573204469766973696F6E31383036060355040B132F2863292032303038207468617774652C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79312430220603550403131B746861777465205072696D61727920526F6F74204341202D204733301E170D3038303430323030303030305A170D3337313230313233353935395A3081AE310B300906035504061302555331153013060355040A130C7468617774652C20496E632E31283026060355040B131F43657274696669636174696F6E205365727669636573204469766973696F6E31383036060355040B132F2863292032303038207468617774652C20496E632E202D20466F7220617574686F72697A656420757365206F6E6C79312430220603550403131B746861777465205072696D61727920526F6F74204341202D20473330820122300D06092A864886F70D01010105000382010F003082010A0282010100B2BF272CFBDBD85BDD787B1B9E776681CB3EBC7CAEF3A6279A34A3683171383362E4F3716679B1A965A3A58BD58F602D3F42CCAA6B32C023CB2C41DDE4DFFC619CE273B222951143185FC4B61F576C0A055822C8364C3A7CA5D1CF86AF88A74402137471730A425902F81B146B42DF6F5FBA6B82A29D5BE74ABD1E0172DB4B74E83B7F7F7D1F04B4269BE0B45AAC473D55B8D7B026522801314066D8D924BDF62AD8EC21495C9BF67AE97F55357E966B8D939327CB92BBEAAC40C09FC2F880CF5DF45ADCCE7486A63E6C0B53CABD92CE190672E60C5C3869C704D6BC6CCE5BF6F7689CDC25154888A1E9A9F8989CE0F3D5312861116C67968D3999CBC24524390203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E04160414AD6CAA94609CEDE4FFFA3E0A742B6303F7B659BF300D06092A864886F70D01010B050003820101001A40D89565AC099289C639F410E5A90E66535D78DEFA2491BBE74451DFC616340AEF6A4451EA2B078A037AC3EB3F0A2C5216A02B43B925903F70A933256D451A283B27CFAAC329421BDF3B4CC033345B4188BF6B2B65AF28EFB2F5C3AA66CE7B56EEB7C8CB67C1C99C1A18B8C4C34903F1600E50CD46C5F37779F7B615E038DBC72F28A00C3F772674D92512DA31DA1A1EDC294191223C69A7BB02F2B65C270389F406EA9BE47282E3A109C1E90019D33ED4706BBA71A6AA58AEF4BBE96CB6EF87CC9BBBFF39E65661D30AA7C45C4C607B0577267ABFD807522C62F77063D939BC6F1CC279DC7629AFCEC52C64045E88366E31D4401A6234363F3501AEAC63A0
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F18B538D1BE903B6A6F056435B171589CAF36BF2
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F17F6FB631DC99E3A3C87FFE1CF1811088D96033
Blob
0F0000000100000014000000399890E6C8E9DDBCE5A03CACDF9907EC990191D85300000001000000230000003021301F060960861803000301010530123010060A2B0601040182373C0101030200C00B00000001000000640000005400DC0052004B0054005200550053005400200045006C0065006B00740072006F006E0069006B00200053006500720074006900660069006B0061002000480069007A006D00650074002000530061001F016C0061007900310163003101730031010000090000000100000054000000305206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B06010505070308060A2B0601040182370A030406082B0601050507030606082B06010505070307030000000100000014000000F17F6FB631DC99E3A3C87FFE1CF1811088D960332000000001000000410400003082043D30820325A003020102020101300D06092A864886F70D01010505003081BF313F303D06035504030C3654C39C524B545255535420456C656B74726F6E696B20536572746966696B612048697A6D6574205361C49F6C6179C4B163C4B173C4B1310B3009060355040613025452310F300D06035504070C06416E6B617261315E305C060355040A0C5554C39C524B54525553542042696C676920C4B06C657469C59F696D2076652042696C69C59F696D2047C3BC76656E6C69C49F692048697A6D65746C65726920412EC59E2E20286329204172616CC4B16B2032303037301E170D3037313232353138333731395A170D3137313232323138333731395A3081BF313F303D06035504030C3654C39C524B545255535420456C656B74726F6E696B20536572746966696B612048697A6D6574205361C49F6C6179C4B163C4B173C4B1310B3009060355040613025452310F300D06035504070C06416E6B617261315E305C060355040A0C5554C39C524B54525553542042696C676920C4B06C657469C59F696D2076652042696C69C59F696D2047C3BC76656E6C69C49F692048697A6D65746C65726920412EC59E2E20286329204172616CC4B16B203230303730820122300D06092A864886F70D01010105000382010F003082010A0282010100ABB73E0A8CC8A55815E68AEF273D4AB4E825D3CD33C220DC19EE883F4D62F0DD13778F61A92AB5D4F2B93158293B2F3F6A9C6F737625EE342080EEEAB7F0C40ACD2B8694C9E360B14452B25A29B4919783D8B7A6142F2949A2F30506FBB44FDAA16C9A669FF04309CAEA728FEB00D73539D75617471730F4BEBF3FC268AF3640C1A9F4A9A7E8106B088AF7861EDC9A2A1506F6A3F0F4E0C714D4517FCFB4DB6DAF4796179B7771D8A7719D240CF6943F8531124FBAEE4E82B8B93E8F23375ECCA2AA75F7186F09D3AEA7542834FBE1E03B607DA0BE798986C89F2DF90A4BC450A2E7FD7916C77A0B18CFCE4CEF7DD6076F98F1AFB1C17AD78135B8AA17B4E0CB0203010001A3423040301D0603551D0E0416041429C590AB25AF11E461BFA3FF886191E60EFE9C81300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF300D06092A864886F70D01010505000382010100100DDAF83AEC28D1149582B1122C517A4125364C9FEC3F1F849D65545CA8160240FA6E1A3784EF729D860A559D5628AC662CD03A5693340725AD08B08FC80F0959CA9D981CE554F8B9457F6A976F88684D4A06263788020EB6C6D67299CE6B77DA6231A4561FAE5F8D77DA5DF688FC1AD99EB581F032B8E388D09CF36AA0B99B145935364FCFF38E5E5D17AD1595D8DDB2D5156E004EB34BCF6694E4E0CDB505DA63578BE5B3AADBC02E1C9044DB1A5D18A4EEBE045B99D5715F55656462D5A29B045986C86277E77C82456A3D17BFEC9D750CAEA36F5AD32F9836F4F0F519AB115DC8A6E32A586A4209C3BD922666320D5D085574FF8C98D00AA6846AD1397D
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F17F6FB631DC99E3A3C87FFE1CF1811088D96033
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F138A330A4EA986BEB520BB11035876EFB9D7F1C
Blob
0F0000000100000020000000C4317DB709496F89FF93419EBD8D954253F4BA9D5B33A50FEBDB9D76CE48BC54030000000100000014000000F138A330A4EA986BEB520BB11035876EFB9D7F1C7E00000001000000080000000040D10FFC47D5011D00000001000000100000001BE2D3EF417A9BB3D419D88BA8FDB0F61400000001000000140000002B232060BD2D8A8847ACAD2BBE0239BA98D4EC980B000000010000001E0000004400690067006900640065006E0074006900740079002000420056000000620000000100000020000000417DCF3180F4ED1A3747ACF1179316CD48CB05C5788435168AED98C98CDCB61509000000010000003E000000303C06082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030806082B0601050507030306082B060105050703092000000001000000A5050000308205A130820389A003020102020101300D06092A864886F70D01010B0500304E310B3009060355040613024E4C31193017060355040A13104469676964656E7469747920422E562E312430220603550403131B4469676964656E74697479204C3320526F6F74204341202D204732301E170D3131303432393130343431395A170D3331313131303130343431395A304E310B3009060355040613024E4C31193017060355040A13104469676964656E7469747920422E562E312430220603550403131B4469676964656E74697479204C3320526F6F74204341202D20473230820222300D06092A864886F70D01010105000382020F003082020A0282020100B811A345DE0147560D62B88EBA58665CFA32C66B806EB87FF853DF7EDF62A8C1574F9A4525C84A452D533824B320AC4FEAADFF9A10AF7FE20ECAB40E242591CE768E10A92F9953A7904B048B6D7AB9411BD301798C9F416BB990D781121A0796D009AFE9E46A215380B8869E626843ADB36A15FAF66D03326A35B1501348C77AB521139C049CDA93F96A2BC1A718FDF6C07E59F6FBE70E11B5DC23EA1CEF670557CE17E9F17BB1D132248CCF65E7D4BC3619707CA22721D680D22D154F4AB5E055909551932180F39C441FFF1D5555E4E21011941653D0FEAFF3EF97BA46E2775BCBD6A2591188A6E75541C392651D231462147F257220F6A487296F07FCFEE0D018D297F9148E36C6E80C1897F1761CF424DAE34AF9B74C121967F3F0E153FB5DE4C074635F25910AD93EF433ACE40B755FCEE698BC540D9DA231C515545D221C8B3A54A60DD1D7233AAC3EAA4A1764762D0DFB54E5EB823C3941439DE1AE7960CF66EEC771837B0C6B09DB9EA24D4E469368B7FA67E1DABFDF9180DAA3A289AD5E6CCC4B7775646F8D24E388880BE33FE9BFA7E556620D837FBD6A61C89089785B0CAF122AE293AD64E7D9452EF6B0C8AB45EE70386FBB353E16FEAB9EC3662FF3BE0960D56F80BD4DDBAF8DFE0C60336B0FE89D6BC430779F2C5038D09869EC37E89E0FE462EAFAFF114454D9EFCD9375914CE18965A694B953F9F94963C50203010001A38189308186300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E041604142B232060BD2D8A8847ACAD2BBE0239BA98D4EC9830440603551D20043D303B30390604551D20003031302F06082B060105050702011623687474703A2F2F706B692E6469676964656E746974792E65752F76616C696461746965300D06092A864886F70D01010B05000382020100A9FDEFBA8F1B7E3212671D410D2DA68BCFF2F4AD56787E0A98D89BA8D1B44B2C26ACE4D27F6737BD098DE5B973113A6E09C75764072134F80E5D2AD8917CF15451BC9CF00C6A42F43C014E9345413DACF3984B1E711E335932FF7C30F05CE4E1BE2D2EB5EADD62210E3DB40D95FCC9B8D9BAA0F762A7EDC303AE082C41D5EF437138B71472AE3FF4147447D8DE8C5179CEEFB154AC7047967E2D2EDD9BEEA1012E19EFBE5860712DAD975B5A6030CB3282624E56E5676AB4D23154723F02D0BC30398FB743092A1F263B0CC77C1D9B8060840EE92ED2F915BB5BE08AA400E9E329FB285BBD364560214331FF70A15F5C835B977C0DB75359EC98B54EE229B1D47C46E3E8E343EA3A96351F53F1041625E32CF368A1A691DF15FBBD9FE64E9EC2546B7E2257E3A49C5C22251F81AF99C8DF11154843F8B333A9237F0E338FBC461D43B43B60F5978519A216B055DC1A702965DAD97E091734EB89BAE96192D8DE34633C4A556ABFDA86EDCE33DEBB536FCF1CDA944F7654AC655510539AC8B86BDC06E6BAE551D5417F1FC4C041A1609134F31382D1A177D3F74CE419FFD7449AB0B5BCDCCA5E8FDCCEF1A06936E044922E99FABCAFB3C7783A5566C76BA5E46926E9341D1F2A970AE977A9775B73483281BFFFD1EC83C57083699E981BC357DF91951C80FC8DE8968305D39F7A887BFAE857F1C18428BDCDD61CCCA5E2490A73
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F138A330A4EA986BEB520BB11035876EFB9D7F1C
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F02B70BDE4EAE02B207377B9FD4785E4C9CC55DC
Blob
0F0000000100000020000000C965FC3CB55836E91A329927F355C8297F8B2F402C0BD593AAEBF9945439CE16030000000100000014000000F02B70BDE4EAE02B207377B9FD4785E4C9CC55DC09000000010000000E000000300C060A2B0601040182370A030C1D0000000100000010000000C697125E13FBE0B9B9FD7C22D65CAD09140000000100000014000000C0AC76A2D35DFFF6CD16005B38A77F557D85596C620000000100000020000000FFB85C26308A961351249EA641F659D49F639E91DAED9C92D046CCDCECC93D2F0B0000000100000022000000430046004300410020004900640065006E00740069007400790020004300410000002000000001000000A5050000308205A130820389A00302010202102C703E54E90FD99820CCC6D9F5463F35300D06092A864886F70D01010B0500305A310B300906035504061302434E3130302E060355040A0C274368696E612046696E616E6369616C2043657274696669636174696F6E20417574686F726974793119301706035504030C1043464341204964656E74697479204341301E170D3135303633303031323131325A170D3430303633303031323131325A305A310B300906035504061302434E3130302E060355040A0C274368696E612046696E616E6369616C2043657274696669636174696F6E20417574686F726974793119301706035504030C1043464341204964656E7469747920434130820222300D06092A864886F70D01010105000382020F003082020A0282020100E151252C78BBFAEE8B55C34E2564192D9442A4E6DE840F213528DC32893EFB34737B57E9AC12294A0C982CCEC9BFA44FA56D0ECEC2CE1809311070720D226B9EFDF3086E92D2C025CFB5B3EB617F1784FC756BB5AC571741190C34D52F516ED5F7516B716F32B1E2D3AEA0D63B1450481974FCEDAFB520A892E03FAE07D150BCD5DDAFD6D0F9CECE92B8C6818CC5F9398DBEF61B2E9A3864BFB7CD72E7FFED895AB8A4755AE1FEAF320C6D226E9335A862E2C0AE0A97D1B0AA3EF63A501E9B502A07DB979560033FA3A45D195521273A499ECBC8EC2CCC9B1748D30810B2A96F2101F45A61DDD3DE895DB50AF3E015D706770B5ED86858DFA077BE5F140A44BD2D1F1A3EF1AA2C5D0C850CE7A3DB8B3806A55B774CD4CADD5795E4A3E8B26477D934AF681D2A6D3F32472699339F0A606811565BD602F1872AD869D8512997A3DEF721268CDDF32C8C058F99364A90B1586939FD94D317D6A629C3500BD5BBA321404FB1071C006457E3515473E3EB19740288770FD17E558302CCD9CC74A5016CAF95B0B9D918A7759A1E4E8F6B5E43472A318403AC881130E8B3B178C743E1AD05879C684B239F7B343FCCFDEF9C42CBF136110B35DA9A7AA1AF854E2E5A6C27790B45812576646F64E768CA96E5043105589EA8B48FF87D56C4ED2831CD6D89E290787BF1901A944449D383EF1823C76A65BE9FEAB47BB56304E35CE177FB0203010001A3633061301F0603551D23041830168014C0AC76A2D35DFFF6CD16005B38A77F557D85596C300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E04160414C0AC76A2D35DFFF6CD16005B38A77F557D85596C300D06092A864886F70D01010B050003820201007CD3E66D744BB98F5DBB5B9522FC65AF4A6C5E8113ACBA14084DAFF079F1D22542C0F8D9642A0235C1E12A0F3A7D6A1A3A16611B4146A87543BFDF3CD5ED4C3B43BC2C9039FE4C8E79EB50BEC0CD5858A1301E3A6B9191E13471952114A02012CB832ACC81AE46E01E6DB20CCAD38288FA6E6B78B65CADBC412BDA7E430B8233FD32AC05FCA98A7C4E58AD371609F46074C553DC936D6580BD712085F11085386423D3218281EBB76D26654EABD0D6107586EAE81D359FE87756B193BAA9F97705D41E220D4BB887E5339F0AE101BC91242EACBFA1033012374E95DEBCE2633E9C33E6D858FE6DC18FB6730AC11A4AC1E08B2AC7374265F6C5C875DEF94C65A836FFDBE95D3DCCC663F0360B7B024FCF69BDC2EFA59E214E5EB5EA3044A3832D31860924A456C184F3EB7C3673326D17A1E7A53093D35ABA87668C0668C96E1348EF992951DDC5043763DE563B8CA5F75C85401CF0D42EE338DE88E7A6888A926A3B8127A18E5FFD2C825896AFDAB047703E0E24530CA651EA82A3CB6D73AEB170078D3380363FACB03E5F1E06BB6E55F6192BEC6AFD9B9A327A91A2BB606461F9EC1466C6C137BEBADCB0D4AF1A1A5D77AE8456A1B1CC63BC9337C34438B4843163B8A5F8C2B188A0D9E645D9471129BB9DAEE96C41B24E5D95C072E50276EFD0DB413EEFE02FFBA482FC7AD11BA7378A49A3C77F0C6F42361C7D80C97D247E
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F02B70BDE4EAE02B207377B9FD4785E4C9CC55DC
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F00FC37D6A1C9261FB6BC1C218498C5AA4DC51FB
Blob
0F0000000100000020000000A4431B6889FBE2AEF05D5E8797468083518DEEEEDAE06D078BC50E4D73ECD870030000000100000014000000F00FC37D6A1C9261FB6BC1C218498C5AA4DC51FB7E00000001000000080000000000042BEB77D5011D0000000100000010000000AFD647CDF9294CCA5405CB05AE04CEBE14000000010000001400000056A7ACAA021DB2AC3D900EA06F2E41C676E77BDA090000000100000020000000301E06082B0601050507030106082B0601050507030306082B06010505070308620000000100000020000000126BF01C1094D2F0CA2E352380B3C724294546CCC65597BEF7F12D8A171F19840B0000000100000032000000470050004B00490020004100700070006C00690063006100740069006F006E00430041003200200052006F006F00740000002000000001000000FB030000308203F7308202DFA003020102020B3132353337323832383238300D06092A864886F70D01010B05003058310B3009060355040613024A50311C301A060355040A13134A6170616E65736520476F7665726E6D656E74310D300B060355040B130447504B49311C301A060355040313134170706C69636174696F6E43413220526F6F74301E170D3133303331323135303030305A170D3333303331323135303030305A3058310B3009060355040613024A50311C301A060355040A13134A6170616E65736520476F7665726E6D656E74310D300B060355040B130447504B49311C301A060355040313134170706C69636174696F6E43413220526F6F7430820122300D06092A864886F70D01010105000382010F003082010A0282010100A6AAAD2565D60011D6E87A76AAF4E6B44BF3CCC352B48DACA64FB592716F46B5D5AD8B12221725CE45E8147A859AE42310A8FAB16750E56D47E06A8913E3AEAE35F1F442C505F74D977E3C28FCB026911E8C1E381A96DC58449762E332C8D115414D759878BEAB68A95EED47BEA4BA8EA10297DE9374996D67B40525EE94C8EDAAA4BA326C4211EBBECB170690E19385C86428CE1F47C7C05D60EE7636DC333B51EB7BCF72D80F78A8198208903E1A988D8EB4CF1536A66EDDB7E24D402053D9762AD078AC89F04F8B326D44EA2EBAB0A9EB89DDB76F790FAB816EB8E68B290B59AFB6490D512CA9FD9D286366B87095739AD8FA3B33BC42421B32ACB132FB3D0203010001A381C13081BE301D0603551D0E0416041456A7ACAA021DB2AC3D900EA06F2E41C676E77BDA300E0603551D0F0101FF040403020106307C0603551D1104753073A471306F310B3009060355040613024A5031183016060355040A0C0FE697A5E69CACE59BBDE694BFE5BA9C311B3019060355040B0C12E694BFE5BA9CE8AA8DE8A8BCE59FBAE79BA43129302706035504030C20E382A2E38397E383AAE382B1E383BCE382B7E383A7E383B343413220526F6F74300F0603551D130101FF040530030101FF300D06092A864886F70D01010B050003820101007F9A0975AC07D172742E775730C2049CD480A683E7A5A01B9FFEABF380BDD54AA3A18FB64C6011E7CAE16081D748C12059A561328B9D9E97D36683DA652E583EDBE52FA5CD8C73A651BE5828A0795C692F43DF63B28947CABBDEB9341163A00E2517E587F41DB0B0A5CF41A874C6E853D542F4822D5309116826719475134DAA76883C74B1D6E34C4F62C3494C4E6DF1707EC37FA605CC789BE981DBA8C8C75C9EFC92922DA697F238B56E73950CC03FCEA69430B5FA05B7DE9E20AAFC1364C98ABA64EFE263E4D898AE6BB53EA655B8333E2C72FB2C1100FB5B162F84D2139EFA05C5C1CB724E22DD84CA4BBCD22D861A0476591F4942623B131F16E8BAD7FD
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\F00FC37D6A1C9261FB6BC1C218498C5AA4DC51FB
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\EE869387FFFD8349AB5AD14322588789A457B012
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\EE869387FFFD8349AB5AD14322588789A457B012
Blob
0F0000000100000014000000A69C493C75FAC1DA819B515A29BB219B63E31BA2030000000100000014000000EE869387FFFD8349AB5AD14322588789A457B0121D0000000100000010000000F80F3F5AC1D39EC772F569FCAC0D49441400000001000000140000000B58E58BC64C1537A440A930A921BE47365A56FF0B000000010000001C0000005300650063007400690067006F0020002800430043004100290000006200000001000000200000001A0D20445DE5BA1862D19EF880858CBCE50102B36E8F0A040C3C69E74522FE6E53000000010000002600000030243022060C2B06010401B231010201050130123010060A2B0601040182373C0101030200C0090000000100000054000000305206082B0601050507030106082B0601050507030206082B0601050507030306082B0601050507030406082B06010505070308060A2B0601040182370A030406082B0601050507030606082B060105050703072000000001000000D4030000308203D0308202B8A003020102021020A4C47FDDDFE1C75363071388776012300D06092A864886F70D0101050500308181310B3009060355040613024742311B30190603550408131247726561746572204D616E636865737465723110300E0603550407130753616C666F7264311A3018060355040A1311434F4D4F444F204341204C696D69746564312730250603550403131E434F4D4F444F2043657274696669636174696F6E20417574686F72697479301E170D3131303130313030303030305A170D3330313233313233353935395A308181310B3009060355040613024742311B30190603550408131247726561746572204D616E636865737465723110300E0603550407130753616C666F7264311A3018060355040A1311434F4D4F444F204341204C696D69746564312730250603550403131E434F4D4F444F2043657274696669636174696F6E20417574686F7269747930820122300D06092A864886F70D01010105000382010F003082010A0282010100D0408B8B72E3911BF751C11B540498D3A9BFC1E68A5D3B87FBBB88CE0DE32F3F0696F0A2295099AEDB3BA157B0745171CDED42914D41FEA9C8D86A867744BB596697505EB4D42C7044CFDA379542693C30C471B352F0214DA1D8BA397C1C9EA3249DF2831698AA167C439B155BB7AE3491FED4622618469A3FEBC1F9F19057EBAC7A0D8BDB72306A66D5E046A370DC68D9FF04488977DEB5E9FB676D41E9BC39BD32D96202F1B1A83D6E379CE22FE2D3A2268BC6B8554388E1233EA5D224396A47AB00D4A1B3A925FE0D3FA71DBAD351C10BA4DAAC38EF55502405654693344F2D8DADC6D42119D28ECA056171077347E58A1912BD044DCE4E9CA548ACBB26F70203010001A3423040301D0603551D0E041604140B58E58BC64C1537A440A930A921BE47365A56FF300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF300D06092A864886F70D010105050003820101002FC9C41C073BCF610200B1D9215175720330B0C4161F6C008B10ACAFF147D4AE103C0C1AF8D4936CAC10377CB7A68364ADCDDF0E87339D37B0C67B3872B1F31A0EA3F9557A6D03660317954AF1B17ADF562106428FB1D3A885DEEE971D62EBA7E7311266C30FA64B2E4182F7FDC91BA81BAFEE3CCEE39CAE2807A12C9B24C20F232683328B860F1F2B124625168F7690036BDEBCAA22686B8CA1AC2B1139A6DB70C27D72E933E7FC26F1745A91E69D84ACF8A8061946E6A7E9AA3422A4A19F7AADB7B2A49A338871023C2ED67AB21FA2CAC0DD2F1094FDB38C84207946D505D410E4D2DB644FB85BEE1BC520475B94AB6ED495331DA61571F1F894CA54393EC1
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\EE68C3E94AB5D55EB9395116424E25B0CADD9009
Blob
0F000000010000003000000069ED5A79811138471B0367AA2EDBE202F8F2CAA02D3AF05BDCF3617F00AE980994682DD398DEF59DC334914B3854A1C4030000000100000014000000EE68C3E94AB5D55EB9395116424E25B0CADD900969000000010000000E000000300C060A2B0601040182373C03011D000000010000001000000084E23C465A003CA7569D66180C61F8D214000000010000001400000009CB597F86B2708F1AC339E3C0D9E9BFBB4DB223090000000100000016000000301406082B0601050507030106082B06010505070302620000000100000020000000ECDD47B5ACBFA328211E1BFF54ADEAC95E6991E3C1D50E27B527E903208040A10B000000010000005C0000004D006900630072006F0073006F00660074002000520053004100200052006F006F007400200043006500720074006900660069006300610074006500200041007500740068006F0072006900740079002000320030003100370000002000000001000000650600003082066130820449A003020102021029C87039F4DBFDB94DBCDA6CA792836B300D06092A864886F70D01010C050030818C310B3009060355040613025553311330110603550408130A57617368696E67746F6E3110300E060355040713075265646D6F6E64311E301C060355040A13154D6963726F736F667420436F72706F726174696F6E313630340603550403132D4D6963726F736F66742052534120526F6F7420436572746966696361746520417574686F726974792032303137301E170D3137303732363232303731375A170D3432303732363232313534375A30818C310B3009060355040613025553311330110603550408130A57617368696E67746F6E3110300E060355040713075265646D6F6E64311E301C060355040A13154D6963726F736F667420436F72706F726174696F6E313630340603550403132D4D6963726F736F66742052534120526F6F7420436572746966696361746520417574686F72697479203230313730820222300D06092A864886F70D01010105000382020F003082020A0282020100CA5BBE94338C299591160A95BD4762C189F39936DF4690C9A5ED786A6F479168F8276750331DA1A6FBE0E543A3840257015D9C4840825310BCBFC73B6890B6822DE5F465D0CC6D19CC95F97BAC4A94AD0EDE4B431D8707921390808364353904FCE5E96CB3B61F50943865505C1746B9B685B51CB517E8D6459DD8B226B0CAC4704AAE60A4DDB3D9ECFC3BD55772BC3FC8C9B2DE4B6BF8236C03C005BD95C7CD733B668064E31AAC2EF94705F206B69B73F578335BC7A1FB272AA1B49A918C91D33A823E7640B4CD52615170283FC5C55AF2C98C49BB145B4DC8FF674D4C1296ADF5FE78A89787D7FD5E2080DCA14B22FBD489ADBACE479747557B8F45C8672884951C6830EFEF49E0357B64E798B094DA4D853B3E55C428AF57F39E13DB46279F1EA25E4483A4A5CAD513B34B3FC4E3C2E68661A45230B97A204F6F0F3853CB330C132B8FD69ABD2AC82DB11C7D4B51CA47D14827725D87EBD545E648659DAF5290BA5BA2186557129F68B9D4156B94C4692298F433E0EDF9518E4150C9344F7690ACFC38C1D8E17BB9E3E394E14669CB0E0A506B13BAAC0F375AB712B590811E56AE572286D9C9D2D1D751E3AB3BC655FD1E0ED3740AD1DAAAEA69B897288F48C407F852433AF4CA55352CB0A66AC09CF9F281E1126AC045D967B3CEFF23A2890A54D414B92AA8D7ECF9ABCD255832798F905B9839C40806C1AC7F0E3D00A50203010001A381BC3081B9300E0603551D0F0101FF040403020186300F0603551D130101FF040530030101FF301D0603551D0E0416041409CB597F86B2708F1AC339E3C0D9E9BFBB4DB223301006092B0601040182371501040302010030650603551D20045E305C30060604551D20003052060C2B0601040182374C837D01013042304006082B060105050702011634687474703A2F2F7777772E6D6963726F736F66742E636F6D2F706B696F70732F446F63732F5265706F7369746F72792E68746D00300D06092A864886F70D01010C05000382020100101CC1497E5B250C6DA697BE4E5F70B1BACF06BA6CF53C3D9F15D6294F7BFE52B2CF65EE70EBCF1E718DEB24C7C321B7FFE324ED1401EBC9928ADAE174E332F07EE239142D90D420EF2F10316CFF5900AEB0B37D1A681AB38616A6EA55AA91641A63B30CD47F90D17813D373CE47F343DFDD86B5DBFCAD3BAB5F4F4055B6C6771F869031EF87517ACE05C7F1F3D6036908D279625F964C63590B0C9265AF9770FA4DB24EF7986A39904D5C0FC0B236EA400FB2654D1D752D4A41A8179021184F1D3EA4368E7E9D0D459B3A16B654222AC95395250F079468439D90B658EC382FD4B7EC5A79E27403845B63A81918E3270F380D572E3BC6D2C3EDF88245653BEB71F154A047575859B31F3290590153124AFB06022A41B01E84A35EB6C22E07569BEBE858E73BDE3E74BB7DC00F2C6F08B726960B4FBEA7B1F30C2611A4A13C194109161977318EBD258419BEF174733130C7474E366424CB4B8FE0DB627AC91F80832DA75D531A1B1893BC80FE5C61BA727CB552A669CA8B81D9082B4CBE729498F2CB57CD166D2BA45F6881CD37504A4E06F03EA398D00984F3B40A50ACB983AE58242BC7359F6DE37CC31D2F8BEF0A0C7635428C3515FC317138F03E713F1793036E31948979D9A17C0DAF9DA49EFEA8CEF334FBD561F4C28360D3A922E14193F00C686E2B24F5C4A474CF934C7F1E36E87BBF24635709EB326F9BF9C05217
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\EE68C3E94AB5D55EB9395116424E25B0CADD9009
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\EE29D6EA98E632C6E527E0906F0280688BDF44DC
Blob
0F00000001000000140000009B33EFB2735DAD085AC2C0D749F402EF12732DD4030000000100000014000000EE29D6EA98E632C6E527E0906F0280688BDF44DC090000000100000034000000303206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B060105050703080B000000010000003E0000004300680061006D006200650072007300690067006E0020005000750062006C006900630020004E006F007400610072007900200052006F006F00740000002000000001000000C2040000308204BE308203A6A003020102020100300D06092A864886F70D01010505003078310B300906035504061302455531273025060355040A131E41432043616D65726669726D61205341204349462041383237343332383731233021060355040B131A687474703A2F2F7777772E6368616D6265727369676E2E6F7267311B3019060355040313125075626C6963204E6F7461727920526F6F74301E170D3033303933303136313434395A170D3337303933303136313434395A3078310B300906035504061302455531273025060355040A131E41432043616D65726669726D61205341204349462041383237343332383731233021060355040B131A687474703A2F2F7777772E6368616D6265727369676E2E6F7267311B3019060355040313125075626C6963204E6F7461727920526F6F743082011F300D06092A864886F70D01010105000382010C003082010702820100587A02BC7EEC9366EDCB114EA7DD0ECB958DC71E376109E700C5D9E9057BEAFC9EB4D358B61946E468974F816DACAE019E9A40386C78447978398FE7E2C4F57A6CFF324C53CB478ED6903DAC457C27CA42CF7E74D3A9E9334ED0A59865AA500C54861D806A8E706A9D6C422BC73695C09C42112C6868FE6CFE6A66BD5BB2D7A5CE9B5039049DA1241FB6106F2E1776E43B507BC079020088DB3547E5B11FD927FF6D35D0B96C56F4B5F54F74572D987204C719077F7EBD2D55A2AC8E89B0482B4EDF7405DB54650635D5713CE13AD934D1AF5E07481C1D00742A21050EC11F774E0AE5E293800EDC56B4BB06E03F484253F909350965B842733F3C8D4BE401A5020103A38201543082015030120603551D130101FF040830060101FF02010C30400603551D1F043930373035A033A031862F687474703A2F2F63726C2E6368616D6265727369676E2E6F72672F7075626C69636E6F74617279726F6F742E63726C301D0603551D0E041604141A5887CCCF64C63BF0A2337449645D06C3ABE7F9300E0603551D0F0101FF040403020106301106096086480186F8420101040403020007302B0603551D110424302281207075626C69636E6F74617279726F6F74406368616D6265727369676E2E6F7267302B0603551D120424302281207075626C69636E6F74617279726F6F74406368616D6265727369676E2E6F7267305C0603551D20045530533051060B2B0601040181872E0A02013042304006082B060105050702011634687474703A2F2F6370732E6368616D6265727369676E2E6F72672F6370732F7075626C69636E6F74617279726F6F742E68746D6C300D06092A864886F70D01010505000382010100152829FEB822B255BF631F719901E4B3886DB775B72F5199914EEA69D75DB09E7F4A2393B847C67E8FFE7E039E8996523E2FA11BF63D70C33DA6DE41C344105EA727AFB50FE27A93C4BDCC8BFBBCB6734D1F3223A4A37BD0E1835DBFC39EC15448431F292EDEE5CF4A5CECB39859BB410F8539E606A41CBFA96D9AE429613C9DE81D5037B6AC9F30AF9EE730EC26FC2A24A1A153A83EFD1178D7006D38B2B8ACDFD21FBF865805EF1C25C54D391A2C445352C2D720012CC2594FBEE4DB16D5B35BFA0E0FF66699C2586B97E80C102D2DAFCBDD6F23B3979D48467A421302A18D365FF2EED6A198EA377CE9BCA1189602B6CA582A1A38D5B271BE78A64CF7EAC7
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\EE29D6EA98E632C6E527E0906F0280688BDF44DC
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\EDB3CB5FB419A185066267E5791554E1E28B6399
Blob
0F0000000100000014000000443C111B7824F3767EF7E4D4A35243F7E24252A5030000000100000014000000EDB3CB5FB419A185066267E5791554E1E28B639909000000010000002A000000302806082B0601050507030206082B0601050507030406082B0601050507030306082B060105050703080B000000010000003A00000053006F0075007400680020004100660072006900630061006E00200050006F007300740020004F0066006600690063006500200043004100000020000000010000003D0400003082043930820321A003020102020101300D06092A864886F70D01010505003081CE310B3009060355040613025A41311530130603550408130C5765737465726E2043617065311630140603550407130D536F6D65727365742057657374312A3028060355040A1321536F757468204166726963616E20506F7374204F6666696365204C696D69746564311A3018060355040B13115341504F2054727573742043656E747265311D301B060355040313145341504F20436C617373203220526F6F742043413129302706092A864886F70D010901161A706B6961646D696E40747275737463656E7472652E636F2E7A61301E170D3130303931353030303030305A170D3330303931343030303030305A3081CE310B3009060355040613025A41311530130603550408130C5765737465726E2043617065311630140603550407130D536F6D65727365742057657374312A3028060355040A1321536F757468204166726963616E20506F7374204F6666696365204C696D69746564311A3018060355040B13115341504F2054727573742043656E747265311D301B060355040313145341504F20436C617373203220526F6F742043413129302706092A864886F70D010901161A706B6961646D696E40747275737463656E7472652E636F2E7A6130820122300D06092A864886F70D01010105000382010F003082010A0282010100B77C697C60F56C26F4AA1C177F5DD4114BE7F3DAE773A7FAA44249683FDAA5405C06685F4ECCBDBE8138242DCC26A0446D03CB23E0BBDE85534B945F5F7BAAC81A97FED72393EDB06ABDD8FC003EB39204E04BBE4F3B98A79DEDCD63F081E76C98D46C605500E5B93CE634955DE0FD7187E9FF81EEE5776F18FFF3C97CA595DD82DC14D9A2E1BECD2773BB455B3F74B162786610222CF568F31788163B9A1B1DFB14AE0DBAF29055A2D530D62B9532C7396E7B65D27738CE6E56A5D923AB38B23B5185C01D1BB7112F056947D802CA92A8E133DE85089BED90D5D8219971BFB6F573EF67089864D2F22A7A4B2116E11F5861DE91471F219F1FFE8C23868318270203010001A320301E300E0603551D0F0101FF040403020106300C0603551D13040530030101FF300D06092A864886F70D0101050500038201010023C1C96C8379C8CF857F3C5EBB56ACFF604751A79C4AF187C44D87DFE64C0DE433E97E085310A2EB423EAF48F1C71D159774761CBD742243E859593E0DCA71C6E797A87EF75B9FDE74E81B51424963C0A3E8948FD69EB6CD05D6CEA0EAB187B0BB2E0ABAE85D3B3C00FF6F165D6564505035FF17B87618C7F16B5F0DD9E8EA1323617F61CE6B490781305221F2A1C198EFC642F32FE30E686945F391D16451A6DA4A799A245BC34CB18711C7E1F75CF8225E37D676477BBF699F55D530252C4AAB4C84E4255AA4D261C6A1E090732C7FA9BE369CFE6E2157459141AA026D53B830BBDCC2E720330E557BFB4293071A485E2DFE44B71F64BE1BC34D9DEAD63260
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\EDB3CB5FB419A185066267E5791554E1E28B6399
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\ED8DC8386C4886AEEE079158AAC3BFE658E394B4
Blob
0F00000001000000140000002EFA6F20BA6DF2B90368C7A5C67557E8AD7571C5030000000100000014000000ED8DC8386C4886AEEE079158AAC3BFE658E394B4090000000100000016000000301406082B0601050507030106082B060105050703020B000000010000002800000054007200750073007400690073002000450056005300200052006F006F007400200043004100000053000000010000002400000030223020060A2B06010401A87501010630123010060A2B0601040182373C0101030200C020000000010000007B030000308203773082025FA00302010202102406625F11B64CCCDA9E9C6CEA040268300D06092A864886F70D01010505003045310B300906035504061302474231183016060355040A130F54727573746973204C696D69746564311C301A060355040B1313547275737469732045565320526F6F74204341301E170D3037303130393132303030315A170D3237303130393131353630305A3045310B300906035504061302474231183016060355040A130F54727573746973204C696D69746564311C301A060355040B1313547275737469732045565320526F6F7420434130820122300D06092A864886F70D01010105000382010F003082010A0282010100D25C94C3CFDC490B7CDF045C0BEA79BBE0D0375B8C0ED7CD3918DE8C97B8B434106D67ADC4B30EED37D4A5BFFA43E5DA702786479FE2E9B281B9BE2D5BB9B128803041DFB894A920A67EAAACCA704CA3120CCF606281527A49830BC8222073A09D353C966FEDCE3D26C24F48CAA282A79506A9F62632FEF2C1FD23585F713BF8C7D7DD4C331FA0D6C1CF7337AB95FE9D9DECEC85C3E209BB8957F994562A546289CC04686E648A4FB1857B6CD4A4BD260AF527FC133E5D6A330A6739628CFE14FDAA24DA4FDEB2B5F27790A191EF29771D719559B6C0E381B8F4FF89EE7AA7FB59FEC9D48D6EDFD6A99FFC0B35B5DC6EA49979F388306BFA4AA96B38C8614B430203010001A3633061300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E04160414792D7396CEB27D5A730E87562931C528F2EDA55F301F0603551D23041830168014792D7396CEB27D5A730E87562931C528F2EDA55F300D06092A864886F70D0101050500038201010043C86FDF9BCC09AFDC38261D48FBD69673A066DF1AE2C0E69DD22F891CE834F2223491F4159F2EBDB472AAD7ED3C9FAD519F7F1E8566256A42698060375646BA3C56AB6A808098B5CA7A58DB0508C7F60781BFA03535C93792BF11F217414F3F41ED13D3AF193D718A7EB064C83BE7FA931364FE56C3DE2BD9EB57CD82D08C9D5252BC6113353F6F9F68F669F76E1ACF0B384A43B5400533D2A62B1A360FD38FB1F77B3E1DD2A06DD843AA2B3F690B007E1AE44E6FCA6D3191FF7481FCFBE24893765C8B8CC3DCA108200B5B6536FC76FB233FD1DA97C1D35A90A3BF459BD75B8108A452FC787E182E2D71FDDAEF0D814689F052F20C5069F7CED5017CB27F28
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\ED8DC8386C4886AEEE079158AAC3BFE658E394B4
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\EC93DE083C93D933A986B3D5CDE25ACB2FEECF8E
Blob
0F0000000100000020000000F908C630A787EA72D2E2A66B3569A32EEB9194D35C3D0F6E2C2F32FA16A6E6EE030000000100000014000000EC93DE083C93D933A986B3D5CDE25ACB2FEECF8E1D0000000100000010000000AC2FD752AF48BEA3C28A79EB692EB9F5140000000100000014000000E6A11383FE974BF2D8FF31A1A7743389CE5E7FA4620000000100000020000000EB7E05AA58E7BD328A282BF8867033F3C035342B516EE85C01673DFFFFBBFE58090000000100000054000000305206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B06010505070308060A2B0601040182370A030406082B0601050507030606082B060105050703070B000000010000005E0000004E00650074004C006F0063006B00200050006C006100740069006E0061002000280043006C00610073007300200050006C006100740069006E0075006D002900200046005101740061006E00FA007300ED0074007600E1006E00790000002000000001000000250600003082062130820409A003020102020649412DEC0010300D06092A864886F70D01010B05003081AD310B30090603550406130248553111300F06035504070C08427564617065737431153013060355040A0C0C4E65744C6F636B204B66742E31373035060355040B0C2E54616EC3BA73C3AD7476C3A16E796B696164C3B36B202843657274696669636174696F6E20536572766963657329313B303906035504030C324E65744C6F636B20506C6174696E612028436C61737320506C6174696E756D292046C59174616EC3BA73C3AD7476C3A16E79301E170D3038313231313135313234345A170D3238313230363135313234345A3081AD310B30090603550406130248553111300F06035504070C08427564617065737431153013060355040A0C0C4E65744C6F636B204B66742E31373035060355040B0C2E54616EC3BA73C3AD7476C3A16E796B696164C3B36B202843657274696669636174696F6E20536572766963657329313B303906035504030C324E65744C6F636B20506C6174696E612028436C61737320506C6174696E756D292046C59174616EC3BA73C3AD7476C3A16E7930820222300D06092A864886F70D01010105000382020F003082020A0282020100CDF2EEC41A7AEB74294CB6BDE4D60A176C65E2663DC4D1BC0CB65AD62B705F2DCC21D15910E4B113BDF6CC2295D66C464E9132B3EBF5ACCB04014F76DD533E789FF95EBCB5821346CA10E31D2D692B9432107321ABA938C5E36E1364D563A9ED0966EC8A6F898D1186D0F5BF32960B7570F52858425EAC69B4F5FC91392EA29140D13C5441872364504879684B68934B72EB8069B34A1C90BEB241A3A5CD17C0D11A697F02184AB5628726572D6CA82C2139F5975E9B9AA6F8E74C79C47B3B56DC7AF8B458CE760AAE2255EB8FC784647BBD6BCA954FD8BE3113BF8DA10A2BD579B7F576ADDA515C814762A8AAFFCF53E03471CF0D2553A99E6347AF8591F8CF1911E54EF9CFEDE33505012203CF9A7CEA1D515ACBFD733D390B31EBC43BCA852A111400A01B81A2098848F37CA264A1EC67B45887F014EAA9BEA522414DECBDA40EE83D87F72FAACE35864F3057928D36AE78D6FD18FCD7251ECF7AFC19FDA03F72173608413F9736950C89957145FA84D6D42060B3450AF2B7953D0BE5A4C3B812F2916CE96D6083F6451105BAE64783D991E26EE1BB466B481BBCC6FBCF7EDE2CBB9084EEB62739E78DA2310FDF81B72C6C00E2B1D82A175C1B1E47894B17511440404FC4391832C2806036E57A4767F6A80554C15D96A01FB688520C02BE8D557E144BC3A201EE9C8A415DF95F9691098EB4E4B5C504DFD636AD59B4B2D7020300F391A345304330120603551D130101FF040830060101FF020104300E0603551D0F0101FF040403020106301D0603551D0E04160414E6A11383FE974BF2D8FF31A1A7743389CE5E7FA4300D06092A864886F70D01010B05000382020100698442C0E35E1361972049F1F41685A59FA4110825C463868FF04BAFB329F507571A62C71B456EAF5D16B7C1D064833B97F543B64590F1662A83242AFF88E97A0BF9C25B7AAF63F70978864859345E9B6A104EF16E9589364A68D06F9BE07E4FB7350FE379B105AF277CAA890A43DEFA0CEFD9572F2871CD696B5242C98A304559A1CCFA594A8FF7D6DD44A5B32E5B1118E2B2B5E7115338FE824CD373BE65921A3AA8D2D2AABCD4BE6D3652FF6BD4D2B51B37F31742F12EA7D5906C749D74F5FA5F221BD3DC75A8B5FFF21AD1BC2B005C3CC5B886085449A29C23FBEFA68D70F442524D1B200081F8A0B8F474239CBEF4B90EEC1E6AD8654A1575F1775B6ED8B1E60FB496B81DFA86C8926E8BE97DDFA20ED5F1F17CAE4AE366BF5DFC5BEF48B29E69C77D90A055B6947081B90ABD897553EC84A903A5DF519908D0740C02D67372067B8BBB5DAA4EFC6767D88E1003192D373AD477A93A1C9DC0797B6C2977324D4A8B3088C2E736CE68A39A9886F989159EBFAA517DF15046540F022E5C9FE3DE573315FE189261A8D229055D65441E9BE3EFFBDC05DF15ABA6D80BA473B24C3AE09ED4B36AE53A0E0AF04ECF78811FBEA9986FB147517D423336B3A6A9025205747E2A6CD4AA9256B03E3B2358B18D35A7138F671E7115A6B3B50386B82066C0486FB9ACD44A0355B237DF04DD220C53862A4A2AA1C1383E3CE53CDF7597
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\EC93DE083C93D933A986B3D5CDE25ACB2FEECF8E
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\EC503507B215C4956219E2A89A5B42992C4C2C20
Blob
0F0000000100000020000000FCA6451D4B87C5B079334C184D9D28CE7E61D6F1DB1A209F6E4B468970FF4E23030000000100000014000000EC503507B215C4956219E2A89A5B42992C4C2C201D0000000100000010000000C6D136B9CB66C1E48021C62110A8EBED140000000100000014000000F77DC5FDC4E89A1B7764A7F51DA0CCBF87609A6D620000000100000020000000EBC5570C29018C4D67B1AA127BAF12F703B4611EBC17B7DAB5573894179B93FA0B00000001000000220000004100430020005200410049005A00200046004E004D0054002D00520043004D000000090000000100000036000000303406082B0601050507030106082B0601050507030206082B0601050507030406082B06010505070308060A2B0601040182370A030C200000000100000087050000308205833082036BA003020102020F5D938D306736C8061D1AC754846907300D06092A864886F70D01010B0500303B310B30090603550406130245533111300F060355040A0C08464E4D542D52434D31193017060355040B0C104143205241495A20464E4D542D52434D301E170D3038313032393135353935365A170D3330303130313030303030305A303B310B30090603550406130245533111300F060355040A0C08464E4D542D52434D31193017060355040B0C104143205241495A20464E4D542D52434D30820222300D06092A864886F70D01010105000382020F003082020A0282020100BA71807A4C866E7FC8136DC0C67D1C00978F2C0C23BB109A40A91AB78788F89B566AFBE67B8E8B928EA7255D5911DB362EB751171FA9081F04172458AA374A18DFE539D457FDD7C12C910191E222D403C058FC7747EC8F3E7443BAAC348D4D3876678EB0C86F303358715CB4F56B6ED40150B8137E6C4AA349D12019EEBCC0291865A7DEFEEFDD0A9021E71A67924210985F4F30BC3E1C45B410D7684014C040FAE777177AE60B8F655B3CD99A52DBB5BD9E46CF3DEB910502C096B2764C4D10963B92FA9C7F0F99DFBE2335451E025CFEB5A89B9925DA5EF322C339F5E42A2ED3C61FC46CAAC51C6A01054A2FD2C5C1A834265D66A5D20221F918B706F54E996FA8AB4C51E8CF5018C577C839092C49923299A8BB171779B05AC5E6A3C459654735835EA9E8350B99BBE4CD20C69B4A0639B568FC22BAEE558C2B4EEAF3B1E3FCB6999AD542FA714D08CF871E6A717DF9D3B4E9A571817BC24E4796A5F67685A3288FE9806E8153A56D5FB848F9C2F936A62E49FFB896C28C07B39B8858FCEB1B1CDE2D70E2979230A189E3BC55A827D64BED90AD8BFA6325592DA835DDCA9733BCE5CDC79DD1ECEF5E0E4A90062663ADB9D9352D07BA76652CAC578F7DF40794D78102965DA30749D57AD057F91BE7534675AAB07942CB687108E960BD3969CEF4AFC35640C7AD52A209E46F86478A1FEB28275D8320AF04C96C569A8B46F50203010001A38183308180300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E04160414F77DC5FDC4E89A1B7764A7F51DA0CCBF87609A6D303E0603551D200437303530330604551D2000302B302906082B06010505070201161D687474703A2F2F7777772E636572742E666E6D742E65732F647063732F300D06092A864886F70D01010B0500038202010007904ADFF3234EF0C39C51659B9C22A28A0C85F373296B4DFE01E2A90C6301BF0467A59D985FFD0113FAEC9A62E986FEB662D26E4C94FBC075457C650CF8B237CFAC0FCF8D6FF919F78FEC1EF2709EF0CAB8EFB7FF7637765BF66E88F3AF623222930D3A6A8E14660C2D537457651ED5B2DD23813BA566232767098FE177AA43CD655108ED5158FEE639F9CB4784A415F176BBA4EEA43BC45FEFB233961118B7C965BE18E1A3A4DCFA18F9D3BC139B397A34BAD341FBFA328A2AB72B860B698338BECD8A2E0B70AD8D2692EE1EF5012B0AD9D6979B6EE0A8191C3A218B0C1E40AD03E7DD667EF5B9200D03E896F98245D439E0A0005DD798E67D9E6773C39A2AF7AB8BA13A14EF34BC520E89989A0440841D7E45699357CEEBCEF8507C4F1C6E04439BF9D63B2318E9EA8ED14D468DF13BE46ACABAFB23B79BFA9901295A585A2DE3F9D46D0E26ADC16E34BC32F80C05FA65A3DB3B378322E9D6DC7233FD5DF220BD763C23DA28F7F91BEB5964D5DC5F727E20FCCD89B590674D627A3F4EAD1DC339FE7AF42816DF41F6488005D70F5179AC10ABD4EC0366E66AB0BA319242406ABE3AD372E16A3755BCAC1D95B76961F2439174E6A0D30A2446A108AFD6DA451996D4531D5B8479F0C0F747EF8B8FC506AE9D4C629DFF4604F8D3C9B610254075FE16AAC94A60862FBAEF3077E454E2B884995880AA138B513A4F48F68BB6B3
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\EC503507B215C4956219E2A89A5B42992C4C2C20
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\EC0C3716EA9EDFADD35DFBD55608E60A05D3CBF3
Blob
0F00000001000000140000008C88FE8A33FD9C47F91820978B2DBBC97FEDA69F030000000100000014000000EC0C3716EA9EDFADD35DFBD55608E60A05D3CBF3090000000100000016000000301406082B0601050507030406082B060105050703010B00000001000000460000004400530054002000280055006E0069007400650064002000500061007200630065006C00200053006500720076006900630065002900200052006F006F0074004300410000002000000001000000FC030000308203F8308202E0021100D01E408B0000027C0000000700000001300D06092A864886F70D01010505003081B9310B3009060355040613027573310D300B0603550408130455746168311730150603550407130E53616C74204C616B65204369747931243022060355040A131B4469676974616C205369676E617475726520547275737420436F2E311E301C060355040B1315556E697465642050617263656C2053657276696365311930170603550403131044535420285550532920526F6F7443413121301F06092A864886F70D010901161263614064696773696774727573742E636F6D301E170D3938313231303030323534365A170D3038313230373030323534365A3081B9310B3009060355040613027573310D300B0603550408130455746168311730150603550407130E53616C74204C616B65204369747931243022060355040A131B4469676974616C205369676E617475726520547275737420436F2E311E301C060355040B1315556E697465642050617263656C2053657276696365311930170603550403131044535420285550532920526F6F7443413121301F06092A864886F70D010901161263614064696773696774727573742E636F6D30820122300D06092A864886F70D01010105000382010F003082010A0282010100EF17ECAF29E6D92B27C0DB7B249F66F404A3C2AD0ACAB0CD842BAA37F380A160EF428FE55D775F574254DD2BDB61B2715E937B6F5FEB242BE7A4F2EBF173B30B8DF559D732DFAC908E4E31BA254DB60CA6F1E5AF0CE1E56F520315C1DFBE7E4AA6A61846703FEFA74DA8DCF574D9617A403CA19428EAC29488CB371505193C9562BA1C2DFB288CD1C89E923C5B11543B78D9473B9B2D4AE63E7B6BDFF4F605CF28F6BA9836009E3C37850A9CDEB7A485C563FDB762146D171ECC8A8085423211B021E29D77C98016419EEBE514897FB7C3BC4FC19F879B96EC63F6F990560E95A3230A8C64DA9BBB1C77B04C5DE6C8E8F57D792D57243FCCE33D2C98CF129F170203010001300D06092A864886F70D01010505000382010100BB388E042226580E214456CCBD597C2968CB5C0FC886543F8178A7AD8FCC46F71C54B8792D5B72056AE821D0EC1D1DFEA43451BEEEEDCECC9C1668E25D7573084331916A102B10C24B69F8C9AD98A8FDB8EFF6ABF05F21EFCB856B09ED2F4866B56072C0E8A0C798DB0EF71B738D34080A7BC57762AA30239BB01E8B809854DC0587B3A96259FC8BB7159AAC44ECCF351AF70F2E5D924B01C87BEEA037EDE41D820D99414317ADD4D5CAE3F97D17A201D0300F40B9DCB904826983B6F90FFA0692F7A8F4D6171CF05E7FC429C8E6E1E2FF36682151AEFFA9BA8492AD8A7B33D890D2C1796D33333974AC1B38719F2C0790EA1DE0D3895FCBEF148D2754A5BD46
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\EC0C3716EA9EDFADD35DFBD55608E60A05D3CBF3
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\EABDA240440ABBD694930A01D09764C6C2D77966
Blob
0F0000000100000014000000B09805544D023A57EA249858C090F5EC398A4118030000000100000014000000EABDA240440ABBD694930A01D09764C6C2D779667E00000001000000080000000000042BEB77D5017F000000010000000C000000300A06082B060105050703091D0000000100000010000000AB56310DA267B26F5047C7EEDB98A63C1400000001000000140000008C7650CE25D3792B3CF46D9D9AE19E054FE83D256200000001000000200000000771920C8CB874D5C5A4DC0D6A51A2D495D38C4DE2CD5B83D2A06FAA051935F60B00000001000000260000004300680069006E0061002000460069006E0061006E006300690061006C00200043004100000009000000010000005E000000305C06082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030806082B0601050507030606082B06010505070307060A2B0601040182370A030406082B0601050507030906082B060105050703032000000001000000230300003082031F30820207A003020102020419993C3F300D06092A864886F70D01010505003022310B300906035504061302434E31133011060355040A130A43464341204754204341301E170D3131303631333038313530395A170D3236303630393038313530395A3022310B300906035504061302434E31133011060355040A130A4346434120475420434130820122300D06092A864886F70D01010105000382010F003082010A0282010100BF73C65A2B8C78F658B7FCD21790A52B74EC812C93CD52CC6EE42ACB24A131E4AD306EE3982231D7219B9FD50F372F5ABB38A2B7792667D60DC5172A9CB95404E10D75866ED8CCC580671BC88C2D0026863C7A793EB6A9C24E20B03797C6857612820AE754BB8BFE3DAEE3EC6B5843F6A537EB58A2BD90C4E5FBCA6BCA306CB77B89F631D28CFF4FC2962543A97135250B18E1ACC8A324B671938CF15DFC9C10057BFFC05BE0B197AD1FD8FE45F5C01F9D5B47391C06FADB6685DB2423EA7BD23920F8EB2AB21A51F3945A28024EA75C476ECFFCD9E8E6615A1627C7150D98D9E8D303359029DFB22F8D107723C8B87AD311616AF3FF8192A5EC424B684E80D70203010001A35D305B301F0603551D230418301680148C7650CE25D3792B3CF46D9D9AE19E054FE83D25300C0603551D13040530030101FF300B0603551D0F0404030201C6301D0603551D0E041604148C7650CE25D3792B3CF46D9D9AE19E054FE83D25300D06092A864886F70D01010505000382010100BEBB9658D4DD89890F2CCDFA6345760D39809A8DFAA845613D2155E8CE68C719E9C2B107C28B3B2FCF618590A75217323AAF0A0515C8C6CEDD8E942606F8D060EEB36ED40DBA5ADDABA07C5072A6D5909356D75939DBE87FB39578538152525FF4928102C1FB22B9D10357A77ECBFBC046BC13744C282B7692691FC1509111C54CDE0B948C17838CAF3787B4EA6B6FA25A354161852F9C17C0FBB90EA261064776BC900998740DD2082FBDE40D72F1A65FC37CC07DEABCD3AB2091CB5C058C9DA835FA3656BB09F3845DD6F1E22C9ED97EF182A0E1B72F7EEDF97BA000B8B2DE1D79E181F352599A145DE7C211F39AC33A7823BE4E66DEA43969F2983A2C0A00
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\EABDA240440ABBD694930A01D09764C6C2D77966
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E7F3A3C8CF6FC3042E6D0E6732C59E68950D5ED2
Blob
0F0000000100000030000000224B13F7DB2BA006B545E060DC3F6D3BA7D8BC1AD643B31C8513F7F3C1280B27D561DCEC7A7AF11CE026A9B51BB660B2030000000100000014000000E7F3A3C8CF6FC3042E6D0E6732C59E68950D5ED21D00000001000000100000006C35EF9A4DAA140CBD8466E117E175E314000000010000001400000055A98489D2C132BD18CB6CA6074EC8E79DBE829053000000010000001F000000301D301B060567810C010130123010060A2B0601040182373C0101030200C062000000010000002000000055903859C8C0C3EBB8759ECE4E2557225FF5758BBD38EBD48276601E1BD58097090000000100000034000000303206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B060105050703080B0000000100000064000000540072007500730074007700610076006500200047006C006F00620061006C002000450043004300200050003300380034002000430065007200740069006600690063006100740069006F006E00200041007500740068006F00720069007400790000002000000001000000A10200003082029D30820224A003020102020C08BD85976C9927A48068473B300A06082A8648CE3D040303308191310B30090603550406130255533111300F06035504081308496C6C696E6F69733110300E060355040713074368696361676F3121301F060355040A131854727573747761766520486F6C64696E67732C20496E632E313A30380603550403133154727573747761766520476C6F62616C2045434320503338342043657274696669636174696F6E20417574686F72697479301E170D3137303832333139333634335A170D3432303832333139333634335A308191310B30090603550406130255533111300F06035504081308496C6C696E6F69733110300E060355040713074368696361676F3121301F060355040A131854727573747761766520486F6C64696E67732C20496E632E313A30380603550403133154727573747761766520476C6F62616C2045434320503338342043657274696669636174696F6E20417574686F726974793076301006072A8648CE3D020106052B81040022036200046BDA0D753508314705AE459955F111132E4AF8103123A37E83D37F28083A261A3ACF97821F80B727098FD18E30C40A9B0EAC5804ABF7367D9423A49B0A8A8BABEBFD392566F15EFE8CAE8D41799D0960CE28A9D38A6DF3D645D4F298843865A0A3433041300F0603551D130101FF040530030101FF300F0603551D0F0101FF04050303070600301D0603551D0E0416041455A98489D2C132BD18CB6CA6074EC8E79DBE8290300A06082A8648CE3D040303036700306402303701929745127EA0F33EAD193A72DDF450930312BE44D24F41A48C9C9D1FA3F6C292E74814FE4E9BA59157AEC63772BB023067250AB10C5EEEA963926FE5900BFE6622CA47FD8A31F783FE7ABF10BE182B1E8FF6291E9459EF8E2137CB5198A56E4B
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E7F3A3C8CF6FC3042E6D0E6732C59E68950D5ED2
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E7B4F69D61EC9069DB7E90A7401A3CF47D4FE8EE
Blob
0F0000000100000014000000354E7163959676669D078F6FA769B1C210269A0A030000000100000014000000E7B4F69D61EC9069DB7E90A7401A3CF47D4FE8EE090000000100000048000000304606082B0601050507030106082B0601050507030206082B0601050507030306082B0601050507030406082B0601050507030606082B0601050507030706082B060105050703090B0000000100000052000000570065006C006C00730053006500630075007200650020005000750062006C0069006300200043006500720074006900660069006300610074006500200041007500740068006F007200690074007900000053000000010000002400000030223020060A6086480186FB7B83740930123010060A2B0601040182373C0101030200C02000000001000000C1040000308204BD308203A5A003020102020101300D06092A864886F70D0101050500308185310B30090603550406130255533120301E060355040A0C1757656C6C7320466172676F2057656C6C73536563757265311C301A060355040B0C1357656C6C7320466172676F2042616E6B204E413136303406035504030C2D57656C6C73536563757265205075626C696320526F6F7420436572746966696361746520417574686F72697479301E170D3037313231333137303735345A170D3232313231343030303735345A308185310B30090603550406130255533120301E060355040A0C1757656C6C7320466172676F2057656C6C73536563757265311C301A060355040B0C1357656C6C7320466172676F2042616E6B204E413136303406035504030C2D57656C6C73536563757265205075626C696320526F6F7420436572746966696361746520417574686F7269747930820122300D06092A864886F70D01010105000382010F003082010A0282010100EE6FB4BD79E28F08219E38044125EFAB5B1C5392AC6D9EDDC2C42E4594033588677457E3DF8CB8A7768F3BF7A8C4DB29630E9168368A978E8A71680907E4E8D40E4FF8D62B4CA416F9EF43988FB39E52DF6D91398F38BD778B4363EBB793FC304C1C0193B613FBF7A11FBF25E174372C1EA45E3C68F84BBF0DB91E2E36E8A9E4A7F80FCB82757C352D22D6C2BF0BF3B4FC6C95611E57D7048132835279E68363CFB7CB638B11E2BD5EEBF68DED957228B4AC1262E94A33E68332AE057595BD8495DB2A5C9B8E2E0CB8812B41E638569F499B6C76FA8A5DF70179817CC1834005FE71FD0C3FCC4E60090E6547102F01C0053F8FF8B341EF5A427E59EFD2970C650203010001A382013430820130300F0603551D130101FF040530030101FF30390603551D1F04323030302EA02CA02A8628687474703A2F2F63726C2E706B692E77656C6C73666172676F2E636F6D2F7773707263612E63726C300E0603551D0F0101FF0404030201C6301D0603551D0E0416041426951910D9E8A19791FFDC19D9B5043ED2730A6A3081B20603551D230481AA3081A7801426951910D9E8A19791FFDC19D9B5043ED2730A6AA1818BA48188308185310B30090603550406130255533120301E060355040A0C1757656C6C7320466172676F2057656C6C73536563757265311C301A060355040B0C1357656C6C7320466172676F2042616E6B204E413136303406035504030C2D57656C6C73536563757265205075626C696320526F6F7420436572746966696361746520417574686F72697479820101300D06092A864886F70D01010505000382010100B915B14491CC23C82B4D77E3F89A7B270DCD72BB9900CA7C661950C6D598EDABBF035AE54DE51EC84F719786D5E31DFD90C93C7577577A7DF8DEF4D4D5F795E6746E1D3CAE7C9DDB0203052C714B253E07E35E9AF5661729881A389FCFAA410384976B93387ACA30441B244433D0E4D1DC2838F4134335352963A87CA2B5AD38A4EDADFDC69A1FFF9773FEFBB335A79386C6769100E6AC5116C427325CDB73DAA593578E3E6D35260859D5E744D7762063E7AC1367C36DB170467CD596113D896F5DA8A1EB8D0ADAC31D336CA3EA67199A997F4B3D83512A1DCA2F860CA27E102D2BD416950B07AA2E149249B7296FD86D317DF5FCA1100787CE2F59DC3E58DB
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E7B4F69D61EC9069DB7E90A7401A3CF47D4FE8EE
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E7A19029D3D552DC0D0FC692D3EA880D152E1A6B
Blob
0F00000001000000200000008B1FD6F6775FF5B9550DF544854C8FCEE94764C386EA9C1991E73C7FB94103DA030000000100000014000000E7A19029D3D552DC0D0FC692D3EA880D152E1A6B7E000000010000000800000000C00C0F7F39D3011D00000001000000100000005523B69A1933F6D177AC4F09CD2DFF1014000000010000001400000045D9A5816E3D884D8D71D246C16E451EF3C4809D620000000100000020000000D95FEA3CA4EEDCE74CD76E75FC6D1FF62C441F0FA8BC77F034B19E5DB258015D530000000100000021000000301F301D06076085740153150030123010060A2B0601040182373C0101030200C009000000010000002A000000302806082B0601050507030106082B0601050507030206082B0601050507030306082B060105050703080B000000010000002C0000005300770069007300730063006F006D00200052006F006F0074002000450056002000430041002000320000002000000001000000E4050000308205E0308203C8A003020102021100F2FA64E27463D38DFD101D041F76CA58300D06092A864886F70D01010B05003067310B30090603550406130263683111300F060355040A13085377697373636F6D31253023060355040B131C4469676974616C204365727469666963617465205365727669636573311E301C060355040313155377697373636F6D20526F6F742045562043412032301E170D3131303632343039343530385A170D3331303632353038343530385A3067310B30090603550406130263683111300F060355040A13085377697373636F6D31253023060355040B131C4469676974616C204365727469666963617465205365727669636573311E301C060355040313155377697373636F6D20526F6F74204556204341203230820222300D06092A864886F70D01010105000382020F003082020A0282020100C4F71D2F57EA576CF7705D63B071520960442833A37A4E0AFAD8EA6C8B51161A55AE5426C4CC4507414F10797F71D27A4E3F384EB300C695CA5BCDC12A83D7271F310E2316B725CB1CB4B980325E1A9D93F1E83C602CA75E571958515EBC2C560BB8D8EF8B82B43CB8C224A813C7A021361B7A572928A72EBF712590F344836950A4E4E11B62199409A3F3C3BCEFF4BDECDB139DCF9D48095267C03729111EFBD211A785187479E44F8514EB5237E2B145D8CC0D437FAE13D26B2B3FA7C2E2A86D765B439FBEB49DB326863B1F7FE5F2E866281625D04B9738A7E4CF09D136C30BBEDA3B44588DBEF19E096B3EF332C72B87C6EC5E9CF68765AD3329C42F89D9B9CBC9039DFB6C945197101B860B1A1B3FF6027E7BD4C55164289DF5D3AC838188D374B4599DC1EB61335A45D1CB39D0066A53601DAFF6FB69BC6ADC01CFBDF98FD9BD5BC13A5F8EDA0F4BA99B9D2A286B1A0A7C3CAB220BE5772D71F6823581AEF87B81E6EAFEACF41A9B745CE88F24F65D9D46C42CD21E2B216A832767554AA4E3C83297669072DAE3D4642E5FE3A16AF660D4E735CDCAC4688DD771C8D3243373B16CF96AE128DB5FC63DE8BE55E6371BED24D90F198F5F631858508151656FF29F7E6A04E7342471BA764B581E19BD156045AA0C1240019D10E2C73807720A65C0B6BB2529DA169E8B358B61EDE5715783B53C719FE34FBF7E1E819F41970203010001A38186308183300E0603551D0F0101FF040403020186301D0603551D2104163014301206076085740153020206076085740153020230120603551D130101FF040830060101FF020103301D0603551D0E0416041445D9A5816E3D884D8D71D246C16E451EF3C4809D301F0603551D2304183016801445D9A5816E3D884D8D71D246C16E451EF3C4809D300D06092A864886F70D01010B05000382020100943A73069F524B305CD4FEB15C25F9D78E6FF587649FED148EB8048E284B8FAA7B8E39B4D958F67BA1350AA19D8AF763E5EBBD3982D4E37A2D6FDF133CBAFE7E56980BF3549FCD444E6E3CE13E15BF06269DE4F090B6D4C29E302E1FEFC77AC450C7EA7BDA50CB7A26CB00B45AABB5931F80898404958D8D7F0993BFD4A8A8E4636DD964E4B8295A08BF50E1840F557B5F08221BF5BD991E14F6CEF4581082B30A3D19C1BF5BABAA99D8F231BDE53866DC5805C7ED631A2E0A977C87932BB28AE3F1EC18E575B62987E7DC8B1A7EB4D8C9D38A176C7D2944BE8AAAF57E3A2E683193B96ADA9AE0DBE92EA584CD1C0AB84A08F99CF161269893B77B66EC915EDD513FDB730FAD045809DD0402950A3ED376DFA6101E803DE8CDA464D133C792C7E24E44E309C94EC25D870E129EBF0FC90510DE7AA3B13CF23FA5AA2779AD317D1FFDFC1969C5DDB93F7CCDC6B4C2301E7E6E92D77F61765A8FEB954DBC116E217C593799D006BCF9066D3216A5D969A8E1DC3C801E6051DCD754211ECA62774FFAD88FB32B3A0D7872C968415A474AC2A3EB1AD70AAB3C3255C80A119CDF74D6F040151DC8B98FB536C5AFF822B8CA1DF3D6B6190F9F61656AEA74C87C8FC34F5D65821FD90D89DA7572FBEFF1476713B3C8D1198827269A99797F1EE42C3F7BEEF1DE4D8B9697C3D53F7C1B23EDA4B31D1672434B20E1597EC2E8AD26BFA2F7
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E7A19029D3D552DC0D0FC692D3EA880D152E1A6B
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E72EF1DFFCB20928CF5DD4D56737B151CB864F01
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E72EF1DFFCB20928CF5DD4D56737B151CB864F01
Blob
0F0000000100000020000000281D590E2000FAF72E950EAC38010962188DB670446B1623ABBF2855D16BD6D3030000000100000014000000E72EF1DFFCB20928CF5DD4D56737B151CB864F011D0000000100000010000000013AFFDB74784B5AE81A4948FD83C2B4140000000100000014000000FEA1E0701E2A0339525A42BE5C91857A18AA4DB553000000010000001F000000301D301B060567810C010130123010060A2B0601040182373C0101030200C0620000000100000020000000125609AA301DA0A249B97A8239CB6A34216F44DCAC9F3954B14292F2E8C8608F0B000000010000002800000065006D005300690067006E00200052006F006F00740020004300410020002D00200043003100000009000000010000002C000000302A060A2B0601040182370A030C06082B0601050507030106082B0601050507030206082B06010505070304200000000100000077030000308203733082025BA003020102020B00AECF00BAC4CF32F843B2300D06092A864886F70D01010B05003056310B300906035504061302555331133011060355040B130A656D5369676E20504B4931143012060355040A130B654D756468726120496E63311C301A06035504031313656D5369676E20526F6F74204341202D204331301E170D3138303231383138333030305A170D3433303231383138333030305A3056310B300906035504061302555331133011060355040B130A656D5369676E20504B4931143012060355040A130B654D756468726120496E63311C301A06035504031313656D5369676E20526F6F74204341202D20433130820122300D06092A864886F70D01010105000382010F003082010A0282010100CFEBA9B9F19905CCD828214AF3733451845610F5A04F2C12E3FA139A27D0CFF9791A745F1D7939FC5BF8708EE09252F7E425F95483D91DD3C85A853F5EC7B607EE3EC0CE9AAFAC56422A392570D6BFB57B36ADACF673DCCDD71D8A83A5FB2B9015376B1C2647DC3B2956936AB3C16A3A9D3DF5C1973858058B1C11E3E4B4B85D851D83FE785F0B45681848A54673343BFE0FC876BBC718F305D186F385EDE7B9D932AD5588CEA6B691B04FAC7E152396F63FF0203416DE0AC6C40445797FA7FDBED2A9A5AF9CC5232AF73C216CBDAF8F4EC53AB2F33412FCDF801A49A4D4A995F79E895EA289AC94CBA8689BAF8A6527CD89EEDD8CB56B297043A0690BE4B90F0203010001A3423040301D0603551D0E04160414FEA1E0701E2A0339525A42BE5C91857A18AA4DB5300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF300D06092A864886F70D01010B05000382010100C24A56FA15217B28A2E9E51DFBF82DC43996414C3B272CC46C181580C6ACAF47592F260BE336B0EF3BFE439749329912155BDF1129FFAB53F8BBC1780FAC9C53AF57BD688C3D6933F0A3A023633B64672244ADD571CB562A7892A34F12313636E2DEFE00C4A3600F27ADA0B08AB5367A52A1BD27F4202762E84D942413E40A04E93CAB2EC843094AC66104E549347ED3C4C8F50FC0AAE9BA545EF3632B4F4F50D4FEB97B998C3DC02EBC022BD3C440E48A07311E9BCE269913FB11EA9A220C1119C75E1B815030C896126EE7CB417F913BA247B754801BDC00CC9A90EAC3C35006620C30C01548A7A8597CE1AE22A2E20A7A0FFA62AB524CE1F1DFCABE830D42
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E70715F6F728365B5190E271DEE4C65EBEEACAF3
Blob
0F0000000100000014000000FCB18262C85ED970365EC364248440F79E528BBE030000000100000014000000E70715F6F728365B5190E271DEE4C65EBEEACAF309000000010000002A000000302806082B0601050507030106082B0601050507030206082B0601050507030406082B060105050703090B000000010000004600000041007500730074007200690061002000540065006C0065006B006F006D002D0043006F006E00740072006F006C0020004B006F006D006D0069007300730069006F006E00000020000000010000001C0400003082041830820300A003020102020100300D06092A864886F70D0101050500305D310B300906035504061302415431233021060355040A131A54656C656B6F6D2D436F6E74726F6C2D4B6F6D6D697373696F6E312930270603550403132054656C656B6F6D2D436F6E74726F6C2D4B6F6D6D697373696F6E20546F702031301E170D3032303932343132343030305A170D3035303932343132343030305A305D310B300906035504061302415431233021060355040A131A54656C656B6F6D2D436F6E74726F6C2D4B6F6D6D697373696F6E312930270603550403132054656C656B6F6D2D436F6E74726F6C2D4B6F6D6D697373696F6E20546F70203130820122300D06092A864886F70D01010105000382010F003082010A028201010095B13A9AEE1A9B2544635081E648DA4808E3D57565CA4AD6DF683325582ECE9E956D41AB3CB2AEF4BB62AD9A7AF5DADC7821FC0347FCF2482AFAD52F412B9835B3B2361DBAA933EB41DE32936BFF11E83B4014E8CC71A5841422BE68BC92A3F440A2E5DA6C7C537E99D279D40CDD7707F06F954ED7BC53FBE4F3D9DAD41DE6F802F65FB09C2E5BDE2E0A2E0561DABC0541DF7CB44D985A40666B8278D81DDA95C1BEB7107ABD2562165C92189E1B9F83FDB2ACF8E38352762A749B56EABC10288FDFD9EFCC960BE781CC788D02EC74B0BFBE2D17AD8EF21F0FAE725D105937DA4F62CBBC6FFA114529DDE3699D4860F97563E12FBA597C25DF5C2A43E68EC8110203010001A381E23081DF301D0603551D0E0416041465CD574EBB9DD3FFA6BCBB79209DE9E04653ED0B30370603551D1F0430302E302CA02AA0288626687474703A2F2F7777772E7369676E617475722E7274722E61742F63757272656E742E63726C300C0603551D240405300380010030560603551D20044F304D304B06092A2800150001000100303E303C06082B060105050702011630687474703A2F2F7777772E7369676E617475722E7274722E61742F64652F6469726563746F72792F6370732E68746D6C300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020204300D06092A864886F70D0101050500038201010050477CA049B1C8FE1D672DA4F64D2037AE90EE9BA141E1ABF6ED68D1324B0C1C63DF882B8B66F0340C7F882DE1C0461BF8FA32BA9BBBA8622878120534DA8DF696E1FED7BE372C0452B5E9B84145792B914A72A0A40EDE39D973F9A9DA43CFACC25EA20F913194D44D2191B72DF116950FF98F4D59CD3575526F0157FA441FEC91D70728DE28DF89F9ED32AD8543FA56F3FC2BB564C17030C800D67C743290E683006B7123CA56A23922AC79141B031793E3A8989B6AC756AF00F1D7DD0FC2C0A7E2665E3DE479FE6CA8CF6AE7A9FF0CBBA7101CCE7F31B3DB919364BE316CB3F8785FE7EBB5C42A61851DC4B583CC994C3A0470EFE456DA0701CA15CF8E6772
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E70715F6F728365B5190E271DEE4C65EBEEACAF3
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E621F3354379059A4B68309D8A2F74221587EC79
Blob
0F00000001000000140000003C574C8C3C5896F06FE67795885AFB18FEC4FF8D030000000100000014000000E621F3354379059A4B68309D8A2F74221587EC797E00000001000000080000000080D3875058D4017F000000010000000C000000300A06082B060105050703011D00000001000000100000002DED75E7852E72900D8A5D3DF0597AC2140000000100000014000000DABB2EAAB00CB8882651745C6D03D3C0D88F7AD6620000000100000020000000A0459B9F63B22559F5FA5D4C6DB3F9F72FF19342033578F073BF1D1B46CBB9120B000000010000002C000000470065006F0054007200750073007400200055006E006900760065007200730061006C002000430041000000090000000100000034000000303206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B0601050507030820000000010000006C0500003082056830820350A003020102020101300D06092A864886F70D01010505003045310B300906035504061302555331163014060355040A130D47656F547275737420496E632E311E301C0603550403131547656F547275737420556E6976657273616C204341301E170D3034303330343035303030305A170D3239303330343035303030305A3045310B300906035504061302555331163014060355040A130D47656F547275737420496E632E311E301C0603550403131547656F547275737420556E6976657273616C20434130820222300D06092A864886F70D01010105000382020F003082020A0282020100A61555A0A3C6E01F8C9D2150D7C1BE2B5BB5A49EA1D97258BD001B4CBF61C9141D4582ABC61D80D63DEB109C3AAF6D24F8BC71019E06F57C5F1EC10E55CA839A5930AE19CB304895ED22378DF44A9A72663EAD95C0E01600E0101F2B310ED79454D34233A0341D1E4576DD4FCA1837EC85157A1908FCD5C79CF0F2A92E10A992E63D583DA916683C2F7521187F2877A5E16117B7A6E9F81E99DB736EF40AA2216CEEDAAA859266AFF67A6B82DABA2208350FCF42F135FA6AEE7E2B25CC3A11E46DAF73B2761DADD0B278671AA4391C510B675683FD385D0DCEDDF0BB2B961FDE7B3252FD1DBBB506A1B2215EA5D695687FF0999EDC45083EE7D2090D3594DD804E5397D7B509442064161703024C530D68DED5AA724D936D820EDB9CBDCFB4F35C5D547A690996D6DB11C18D75A8B4CF39C8CE3CBC247CE662CAE1BD7DA7BD57650BE4FE25EDB66910DC281A46BD011DD097B5E1983BC03764D63D94EE0BE1F528AE0B56BF718B2329418E86C54B527BD871AB1F8A15A63B835AD7580151C64C41D97FD8416772A228DF6083A99EC87BFC53737259F5937A17760ECEF7E55CD90B5534A2AA5BB56A54E713CA57EC976DF45E062F458B58D4231692E4166E28635930DF50019C63891A9FDB1794827037C3249E9A47D65ACA4EA86989721F916CDB7E9E1BADC71F73DD2C4F1965FD7F9340102ED2F0ED3C9E2E283E692633C57B0203010001A3633061300F0603551D130101FF040530030101FF301D0603551D0E04160414DABB2EAAB00CB8882651745C6D03D3C0D88F7AD6301F0603551D23041830168014DABB2EAAB00CB8882651745C6D03D3C0D88F7AD6300E0603551D0F0101FF040403020186300D06092A864886F70D010105050003820201003178E6C7B5DFB89440C971C4A835EC461DC285F3285886B00BFC8EB2398F4455AB64845C69A9D09A383CFAE51F35E544E380799468A4BBC49F3DE134CD30468B542B95A5EFF73F9984FD35E6CF31C6DC6ABFA7D72308E1985EC35A0876A9A6AF772FB760BD44466AEF97FF7395C18EE893FBFD31B7EC571111459B30F11A8839C14F3CA700D5C7FCAB6D802270A50CE05D042902FBCBA091D17CD6C37E50D59D58BE4138EBB9753C15D99BC94A8359C0DA53FD33BB36189B850F15DDEE2DAC7693B9D9018D4810A8FBF53886F1DB0AC6BD84A32341DED6776F85D4851C50E0AE518ABA8D3E76E2B9CA27F25F9FEF6E590D06D82B17A4D27C6BBB5F141A488F1A4CE7B3471C8E4C452B20EE48DFE7DD098E18A8DA408D9226115361735DEBBDE7C44D293761EBAC392D672E16D6F5008385A1CC7F76C47DE4B74B66EF03456069B60C529692845EA6A3B5A43E2BD9CCD81B47AAF244DA4FF903E8F014CB3FF383DED0C154E3B7E80A374D8B2059033019A12CC8BD111FDFAEC94AC5F327666686AC6891FFD9E6531C0F8B5C69650A26C81E34C35D517BD7A99C06A136DDD58994BCD9E42D0C5E096C08977CA33D7C93FF3FA114A7CFB55DEBDBDB1CC476DF88B9BD4505951BAEFC466A4CAF48E3CEAE0FD27EEBE66C9C4F816A7A64ACBB3ED5E7CB762EC5A748C15C900FCBC83FFAE632E18D1B6FA4E68ED8F929488ACE73FE2C
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E621F3354379059A4B68309D8A2F74221587EC79
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E619D25B380B7B13FDA33E8A58CD82D8A88E0515
Blob
0F0000000100000014000000903DBA1B35A9B3A2CD68FB80239FCDA38DB90CFF0B000000010000002000000041002D00540072007500730074002D005100750061006C002D00300031000000090000000100000068000000306606082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B06010505070308060A2B0601040182370A030406082B0601050507030606082B0601050507030706082B0601050508020206082B06010505070309030000000100000014000000E619D25B380B7B13FDA33E8A58CD82D8A88E0515200000000100000057040000308204533082033BA003020102020300E243300D06092A864886F70D01010505003081CF310B300906035504061302415431818B308188060355040A1E81800041002D005400720075007300740020004700650073002E0020006600FC007200200053006900630068006500720068006500690074007300730079007300740065006D006500200069006D00200065006C0065006B00740072002E00200044006100740065006E007600650072006B00650068007200200047006D0062004831183016060355040B130F412D54727573742D5175616C2D3031311830160603550403130F412D54727573742D5175616C2D3031301E170D3034313133303233303030305A170D3134313133303233303030305A3081CF310B300906035504061302415431818B308188060355040A1E81800041002D005400720075007300740020004700650073002E0020006600FC007200200053006900630068006500720068006500690074007300730079007300740065006D006500200069006D00200065006C0065006B00740072002E00200044006100740065006E007600650072006B00650068007200200047006D0062004831183016060355040B130F412D54727573742D5175616C2D3031311830160603550403130F412D54727573742D5175616C2D303130820122300D06092A864886F70D01010105000382010F003082010A0282010100A686077121BC531843877D71A27B023734595D01628559F2E87CEFB923551BBC0E5ABEDEC882C197CFFB48FDFE471946DAB1C2348BBC46D2DA95940E5CB5080B46AC60C47B604E431CAAC00461DB33DCB66C09D5CED50AEF10118B4D200177188BFE049627ACFBEC24B0C7B5E0D361F0C4F57CD9C8C691217710D1899EDB880009D10D69FF3911E315AB4D4729A831B1DA38465748685FED8E45AEB1C4A86CA2F44EACBFBF380DEFD3D5A4EFB249FC716794983CEFFFFA26886FDAFD5F4A41EC7FEB55CDF0EB615105675FEBBF9622F634AC7BE08D82FC68075F90745A43CDAAC48E82696F27F70AB93D0FBDE5205450C0034A18060704D4A0CC9416CDD2498F0203010001A3363034300F0603551D130101FF040530030101FF30110603551D0E040A04084B3C8C1D85E96FAD300E0603551D0F0101FF040403020106300D06092A864886F70D01010505000382010100214BAC989CCC251890F13007AC900E7A57EE5A84C672A748BFB4F2B3F7CD976C85D9F8EF1D3F09D3568A89A9455696D5790D9729BD4ED9B1CE41800A82C759DA367FB1D2F65151514C79A274BBBA3DD8160814612584042D0A2984EF5056F7E1000D13C1B11262A4F3FA7948E46AFB0997BC7FA1C49A12660AD510B1D402B9F1A09518784FEB481A2346727C9510767DDE64957A916BD55036F424D13ED7AE1A303CD63780CFDA5E622144D425EFC4AF5C262BF405C00B14B5A60030A844BCC8459840FAC0306149B0335AEA5423C0DE4050BC80BDE6DC90BCDCB6746D15B3E3BA3F02DA357FECB92944950D3A5F697557031A61BE2F64A16A3746CE8415C456
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E619D25B380B7B13FDA33E8A58CD82D8A88E0515
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E5DF743CB601C49B9843DCAB8CE86A81109FE48E
Blob
0F00000001000000140000003DA87EEF8882806783F2A90A618ABD357FB8DC630B00000001000000360000005300450043004F004D002000540072007500730074002000530079007300740065006D007300200043004F0020004C00540044000000090000000100000016000000301406082B0601050507030406082B06010505070301030000000100000014000000E5DF743CB601C49B9843DCAB8CE86A81109FE48E2000000001000000EB020000308202E730820250020101300D06092A864886F70D01010505003081BB312430220603550407131B56616C69436572742056616C69646174696F6E204E6574776F726B31173015060355040A130E56616C69436572742C20496E632E31353033060355040B132C56616C694365727420436C617373203120506F6C6963792056616C69646174696F6E20417574686F726974793121301F06035504031318687474703A2F2F7777772E76616C69636572742E636F6D2F3120301E06092A864886F70D0109011611696E666F4076616C69636572742E636F6D301E170D3939303632353232323334385A170D3139303632353232323334385A3081BB312430220603550407131B56616C69436572742056616C69646174696F6E204E6574776F726B31173015060355040A130E56616C69436572742C20496E632E31353033060355040B132C56616C694365727420436C617373203120506F6C6963792056616C69646174696F6E20417574686F726974793121301F06035504031318687474703A2F2F7777772E76616C69636572742E636F6D2F3120301E06092A864886F70D0109011611696E666F4076616C69636572742E636F6D30819F300D06092A864886F70D010101050003818D0030818902818100D859827A89B896BAA62F686F582EA7541C066EF4EA8D48BC319417F0F34EBCB2B8359276B0D0A5A501D7000312221908F8FF11239BCE07F5BF691A26FE4EE9D17F9D2C401D59686EA6F858B09D1A8FD33FF1DC190681A80EE03ADDC853450906E60F70C3FA40A60EE256050F184DFC2082D17355748D7672A01D9D1DC0DD3F710203010001300D06092A864886F70D01010505000381810050683D49F42C1C0694DF95607F967B17FE4F71AD64C8DD77D2EF5955E83FE88E052A21F207D2B5A752FE9CB1B6E25B771740EA72D623CB288132C3007918EC591789C9C66A1E71C9FDB774A5254569C548AB19E1458A256B19EEE5BB12F57FF7A68D51C3F09D74B7A93EA0A5FFB6490313DA22CCED71822B99CF3AB7F52D72C8
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E5DF743CB601C49B9843DCAB8CE86A81109FE48E
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E45501608AA1EF89E27B8CD3C3B34C03B038E6D7
Blob
0F0000000100000014000000D074382C394C27DE0249FCB555A8EF835B889769030000000100000014000000E45501608AA1EF89E27B8CD3C3B34C03B038E6D71D00000001000000100000008AA2C13CD3D4D9D48C8D1863D137CC59140000000100000014000000AB9D2393FD1F334A322DAA245AF22D64A9019A41620000000100000020000000FD7CCA48B745213470F503EC6E969C447FC12D4DD5AA2A7CC6C3D5ABBD962B3309000000010000002A000000302806082B0601050507030206082B0601050507030406082B0601050507030306082B060105050703080B000000010000002A0000005300410050004F00200043006C0061007300730020003200200052006F006F007400200043004100000020000000010000005C0400003082045830820340A003020102020101300D06092A864886F70D01010505003081CE310B3009060355040613025A41311530130603550408130C5765737465726E2043617065311630140603550407130D536F6D65727365742057657374312A3028060355040A1321536F757468204166726963616E20506F7374204F6666696365204C696D69746564311A3018060355040B13115341504F2054727573742043656E747265311D301B060355040313145341504F20436C617373203220526F6F742043413129302706092A864886F70D010901161A706B6961646D696E40747275737463656E7472652E636F2E7A61301E170D3130303931353030303030305A170D3330303931343030303030305A3081CE310B3009060355040613025A41311530130603550408130C5765737465726E2043617065311630140603550407130D536F6D65727365742057657374312A3028060355040A1321536F757468204166726963616E20506F7374204F6666696365204C696D69746564311A3018060355040B13115341504F2054727573742043656E747265311D301B060355040313145341504F20436C617373203220526F6F742043413129302706092A864886F70D010901161A706B6961646D696E40747275737463656E7472652E636F2E7A6130820122300D06092A864886F70D01010105000382010F003082010A0282010100B77C697C60F56C26F4AA1C177F5DD4114BE7F3DAE773A7FAA44249683FDAA5405C06685F4ECCBDBE8138242DCC26A0446D03CB23E0BBDE85534B945F5F7BAAC81A97FED72393EDB06ABDD8FC003EB39204E04BBE4F3B98A79DEDCD63F081E76C98D46C605500E5B93CE634955DE0FD7187E9FF81EEE5776F18FFF3C97CA595DD82DC14D9A2E1BECD2773BB455B3F74B162786610222CF568F31788163B9A1B1DFB14AE0DBAF29055A2D530D62B9532C7396E7B65D27738CE6E56A5D923AB38B23B5185C01D1BB7112F056947D802CA92A8E133DE85089BED90D5D8219971BFB6F573EF67089864D2F22A7A4B2116E11F5861DE91471F219F1FFE8C23868318270203010001A33F303D300E0603551D0F0101FF040403020106300C0603551D13040530030101FF301D0603551D0E04160414AB9D2393FD1F334A322DAA245AF22D64A9019A41300D06092A864886F70D01010505000382010100565251B90F02E1F62E9CB1315AA6F8CEBCEE02841509F128525FE7E12CBDDB790A7ABFEB629ED5864729EE7430EC4C75B51EE3AA33EFADE16A4CBF3701BE55834CA952D83798506F68DD4741B72C30C86E4C072CC6D349B9B55CD2CBCCD436C6070D184F3F6300C4ECB688FB016463ADD1F7777C64542B123D341585F0A0BA79295F989B42EAAEC1A89F13898A6DE9B838C961ED60ECF72A58059BA160788317E17E5FE8FD78E06B562A8676AE5BC25EEB45E430B831ED64B15D2EC03D800DC72713D376E286FBDCDB800A81E1FD08F90BC431B4635BE78C33E506B6526AB3D7E96BE332783266944EDD8D776DD324285B546177026775944B574BE66CC5396F
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E45501608AA1EF89E27B8CD3C3B34C03B038E6D7
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E3D73606996CDFEF61FA04C335E98EA96104264A
Blob
0F00000001000000140000002642E69FCFC9DBDA517BEF110D1B9800F63286B10B000000010000001A00000044002D0054005200550053005400200047006D00620048000000090000000100000034000000303206082B0601050507030106082B0601050507030206082B0601050507030306082B0601050507030406082B06010505070308030000000100000014000000E3D73606996CDFEF61FA04C335E98EA96104264A2000000001000000EB040000308204E7308203CFA00302010202030326DA300D06092A864886F70D01010505003052310B300906035504061302444531153013060355040A0C0C442D547275737420476D6248312C302A06035504030C23442D5452555354205175616C696669656420526F6F74204341203120323030373A504E301E170D3037303630383131343734365A170D3132303630383131343734365A3052310B300906035504061302444531153013060355040A0C0C442D547275737420476D6248312C302A06035504030C23442D5452555354205175616C696669656420526F6F74204341203120323030373A504E30820124300D06092A864886F70D010101050003820111003082010C028201010089D9FFD3FF37FC57881560C1BD2F681080B72D59A5A24AC70AD62F8E40377B2A32AAC6B6130D20E74FFE3F0E6EADF954CF6B050BFE69F2FABC813FDEEDB333BB392C74C434F6B4FAC3D3D258CA79708F63E39534F839579F01748B979CADEA1CBB65FD4AE62438493E9EB2C650E35CD63BE9873977D9A41E0728A05D92872B4C8B75C54003BD3F400D943C3B14A7E0AE72BD2BEBD2F1B0DE08E2D1A411D638C24EF212771FCF48460BF817339B831F08B805E746534B887B87FCD2A33D4572E90E19B4058A6A1F370C0F0CCCC8A8B95B02BAF3B8A30D0FC314EB6B7B3781EA9E58D1B0B7474B053104E94C0AA1C09214BD2337D221F6E4C0EC4E997F8D8DE851020500E9CC4529A38201C2308201BE300F0603551D130101FF040530030101FF301D0603551D0E041604142C4CF69A2A9F288201C1990611AFB34B7CB79AFE303806082B06010505070101042C302A302806082B06010505073001861C687474703A2F2F7175616C2E6F6373702E642D74727573742E6E657430170603551D200410300E300C060A2B06010401A534021F0130330603551D11042C302A8110696E666F40642D74727573742E6E65748616687474703A2F2F7777772E642D74727573742E6E6574301806082B06010505070103040C300A3008060604008E460101300E0603551D0F0101FF0404030201063081D90603551D1F0481D13081CE3081CBA081C8A081C5867F6C6461703A2F2F6469726563746F72792E642D74727573742E6E65742F434E3D442D54525553542532305175616C6966696564253230526F6F7425323043412532303125323032303037253341504E2C4F3D442D5472757374253230476D62482C433D44453F63657274696669636174657265766F636174696F6E6C6973748642687474703A2F2F7777772E642D74727573742E6E65742F63726C2F642D74727573745F7175616C69666965645F726F6F745F63615F315F323030375F706E2E63726C300D06092A864886F70D0101050500038201010069A9F184C8B6069D1A170765F3AA479CF772AA3DAF2666E514210ECE1B893E8A54C8FF36C91D2C8A11E5CDC772A4845B1E5BC33535B1B16D4BAA08D4D9D4E2FD074BE4565BF6CA70C875BA9C7E440E058AFDD61B74D3BBD2E55AE4DAF60FB21F8D54CC1565FE761A2C10B9C6D424263B0CAD68496F63ACAC585ED617B906680CB430CCE1B7E63FC0EED20F4DA0D8A25F7C80C8E0178A54F7450872774A4BB329A093A0E1CA43C1732DBBDAB492F15CE61026D588F186E73E1B622726CCBBCECC30DECFD8BAFF8C82371E6C4584D923B58696970EC7AA228D4FA2FB2903B01ADC105463BD9CD69E9CE41F329790D0D79ABB79A3238FB475AE64C87797FA2C238D
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E3D73606996CDFEF61FA04C335E98EA96104264A
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E392512F0ACFF505DFF6DE067F7537E165EA574B
Blob
0F00000001000000100000001400FA980DEFC139D23D53877F2CC0C80B00000001000000580000004E00650074004C006F0063006B00200045007800700072006500730073007A002000280043006C006100730073002000430029002000540061006E007500730069007400760061006E0079006B006900610064006F00000009000000010000004A000000304806082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030706082B06010505070306060A2B0601040182370A030406082B06010505070308030000000100000014000000E392512F0ACFF505DFF6DE067F7537E165EA574B2000000001000000530500003082054F308204B8A003020102020168300D06092A864886F70D010104050030819B310B30090603550406130248553111300F06035504071308427564617065737431273025060355040A131E4E65744C6F636B2048616C6F7A617462697A746F6E73616769204B66742E311A3018060355040B131154616E7573697476616E796B6961646F6B313430320603550403132B4E65744C6F636B20457870726573737A2028436C6173732043292054616E7573697476616E796B6961646F301E170D3939303232353134303831315A170D3139303232303134303831315A30819B310B30090603550406130248553111300F06035504071308427564617065737431273025060355040A131E4E65744C6F636B2048616C6F7A617462697A746F6E73616769204B66742E311A3018060355040B131154616E7573697476616E796B6961646F6B313430320603550403132B4E65744C6F636B20457870726573737A2028436C6173732043292054616E7573697476616E796B6961646F30819F300D06092A864886F70D010101050003818D0030818902818100EBECB06C618A2325AF6020E3D99FFC930BDB5D8DB0A1B3403A82CEFD75E0783203865A869591ED53FA9D40FCE6E8DDD95B7A03BD5DF33B0CC351799BAD55A0E9D00310AF0ABA1442D952261122C7D220CC82A49AA9FEB881769D6AB7D236753EB18609F66E6D7E4EB77AECAE7184F60433082532EB74AC1644C6E440931D7FAD0203010001A382029F3082029B30120603551D130101FF040830060101FF020104300E0603551D0F0101FF040403020006301106096086480186F84201010404030200073082026006096086480186F842010D048202511682024D46494759454C454D2120457A656E2074616E7573697476616E792061204E65744C6F636B204B66742E20416C74616C616E6F7320537A6F6C67616C7461746173692046656C746574656C656962656E206C6569727420656C6A617261736F6B20616C61706A616E206B65737A756C742E204120686974656C65736974657320666F6C79616D617461742061204E65744C6F636B204B66742E207465726D656B66656C656C6F737365672D62697A746F73697461736120766564692E2041206469676974616C697320616C616972617320656C666F6761646173616E616B2066656C746574656C6520617A20656C6F69727420656C6C656E6F727A65736920656C6A61726173206D6567746574656C652E20417A20656C6A61726173206C656972617361206D656774616C616C6861746F2061204E65744C6F636B204B66742E20496E7465726E657420686F6E6C61706A616E20612068747470733A2F2F7777772E6E65746C6F636B2E6E65742F646F63732063696D656E2076616779206B65726865746F20617A20656C6C656E6F727A6573406E65746C6F636B2E6E657420652D6D61696C2063696D656E2E20494D504F5254414E5421205468652069737375616E636520616E642074686520757365206F662074686973206365727469666963617465206973207375626A65637420746F20746865204E65744C6F636B2043505320617661696C61626C652061742068747470733A2F2F7777772E6E65746C6F636B2E6E65742F646F6373206F7220627920652D6D61696C20617420637073406E65746C6F636B2E6E65742E300D06092A864886F70D01010405000381810010AD7FD70C32800AD886F17998B5ADD4CDB336C49648C15CCD9AD9052E9FBE50EBF42614102DD46617F89EC127FDF1EDE47B4BA06CB5AB9A5770A6EDA0A4ED2EF5FDFCBDFE4D37080CBCE3968322F5491B7F4B2BB454C1807C994E1DD08CEED0ACE592FA7556FE64A0138FB8B8169D61056780C8D0D8A507023498048D3304D4
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E392512F0ACFF505DFF6DE067F7537E165EA574B
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E2B8294B5584AB6B58C290466CAC3FB8398F8483
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E2B8294B5584AB6B58C290466CAC3FB8398F8483
Blob
0F000000010000002000000047452C0A07D5C464094763E532740F28E2B3034FF0FCBFABE2D0F22650F57D2A030000000100000014000000E2B8294B5584AB6B58C290466CAC3FB8398F84837E00000001000000080000000000042BEB77D5017F000000010000000C000000300A06082B060105050703091D00000001000000100000001CE58292567CD481FC323DF3726106F7140000000100000014000000E3FE2DFD28D00BB5BAB6A2C4BF06AA058C93FB2F0B000000010000001A0000004300460043004100200045005600200052004F004F00540000006200000001000000200000005CC3D78E4E1D5E45547A04E6873E64F90CF9536D1CCC2EF800F355C4C5FD70FD53000000010000003E000000303C301D060760811C86EF2A0330123010060A2B0601040182373C0101030200C0301B060567810C010130123010060A2B0601040182373C0101030200C009000000010000005E000000305C06082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B06010505070308060A2B0601040182370A030406082B0601050507030606082B0601050507030706082B060105050703092000000001000000910500003082058D30820375A0030201020204184ACCD6300D06092A864886F70D01010B05003056310B300906035504061302434E3130302E060355040A0C274368696E612046696E616E6369616C2043657274696669636174696F6E20417574686F726974793115301306035504030C0C4346434120455620524F4F54301E170D3132303830383033303730315A170D3239313233313033303730315A3056310B300906035504061302434E3130302E060355040A0C274368696E612046696E616E6369616C2043657274696669636174696F6E20417574686F726974793115301306035504030C0C4346434120455620524F4F5430820222300D06092A864886F70D01010105000382020F003082020A0282020100D75D6BCD103F1F0559D5054D37B10EEC982B8E151DFA934B178221711052D751647016C255694D8E156D9FBF0C1BC2E0A367D60CACCF22AEAF77542A4B4C8A53527AC3EE2EDEB37125C1E95D3DEEA12FA3F72A3CC9231D6AAB1DA1A7F1F3ECA0D544CF15CF722F1D6397E899F9FD93A454804C52D452AB2E49DF90CDB85FBE3FDEA1CA4D20D425E8842953B7B1881FFFFADA909F0AA92D413FB1F11829EE16592C34491AA806D7A888D203727A32E2EA684D6E2C96657BCA59FAF2E2DDEE302CFBCC46ACC463EB6F7F362B347312947FDFCC269EF1725D5065598F69B3875E326FC3188AB5958FB07A37DE5A453BC736E1EF67D139D3975B736219482D871C06FB7498204973F005D21BB1A0A3B71B70D38869B95AD638F462DC258B78BFF8E87EB85CC9954F5FA72DB9206BCF6BDDF50DF482B7F4B2662E1028F6975A7B96168F01192D6C6E7F3958066483018383C34D92DD32C687A437E916CEAA2D68AF0A81653A70C19BAD4D6D54CA2A2D4B851BB380E670450D6B5E35F07F3BB89CE4047089122593DA0A9922606A63604E7606984EBD83AD1D588A2585D2C7651E2D8EC6DFB6C6E17F8A0421152974F03E9C909D0C2EF18A3E5AAA0C091EC7D53CA3ED97C31E34FA38F9080EE3C05D2B83D1566AC9B6A854532E7832673D827F74D0FBE1B60560B970DB8E0BF913586F7160105210B9C14109EF721F673178FF96058D0203010001A3633061301F0603551D23041830168014E3FE2DFD28D00BB5BAB6A2C4BF06AA058C93FB2F300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E04160414E3FE2DFD28D00BB5BAB6A2C4BF06AA058C93FB2F300D06092A864886F70D01010B0500038202010025C6BA6BEB87CBDE8239963DF044A76B847303DE9D2B4FBA207FBC78B2CF97B01B9CF3D7792EF548B6D2FB1788E6D37A3FED5313D0E22F6A79CB002328E61E3757358984C2764F3436AD67C3CE410688C5F7EED81AB8D60B7F50FF93AA174B8CECED5260B2A406EA4EEBF46B19FDEBF51AE0252A9ADCC74136F7C8740584399539D60B3BA427FA08D85C1EF804605211282803FFEF536600A54A3416667CFD09A4AE9E671A6F410B6B06139B8F867105B42F8D8966332976549A11F827FAB23F91E0CE0D1BF3301AADBF225D1BD3BF25054DE1921A7F999F3C4493CAD440496C8087D7043AC33252350E56F8A5DD7DC48B0D111F53CB1EB217B668775AE0D4CBC807AEF53A2E8E37B7D0014B4329778C39978F825AF851E589A018E7687F5D0A2EFBA3470E3DA6237AC601C78FC85EBF6D8056BE8A24BA33EA9FE132119EF1D24F80F61B40AF389E115079731212CDE66C9D2C88723C3081069122EA59ADDA192E22C28DB98C87E066BC73235F2164638048F5A03C183D94C848411D40BA5EFEFE5639A1C8CF5E9E19644610DA1791B70580AC8B99927DE7A2D8070B3627E74879608AC3D7135CF87240DF4ACBCF99000A000B1195DA564503880A9F67D0D579B1A88D406D0DC27A40FAF35F644792CB53B9BB59CE4FFDD0155301D8DFEBD9E676EFD023BB3BA979B3D50229CD89A3960F4A35E74E42C075CD07CFE62CEB7B2E
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E252FA953FEDDB2460BD6E28F39CCCCF5EB33FDE
Blob
0F00000001000000200000008F65AB514D193E1BC2C69D82520F73C4E3255744356064E9859107F26C0EFD5C030000000100000014000000E252FA953FEDDB2460BD6E28F39CCCCF5EB33FDE1D00000001000000100000002B291EA88AAC2DDCA8623806EFF79F711400000001000000140000002E16A94A18B5CBCCF56F50F3235FF85DE7ACF0C8090000000100000020000000301E06082B0601050507030106082B0601050507030206082B060105050703040B000000010000002000000053005A004100460049005200200052004F004F00540020004300410032000000620000000100000020000000A1339D33281A0B56E557D3D32B1CE7F9367EB094BD5FA72A7E5004C8DED7CAFE200000000100000076030000308203723082025AA00302010202143E8A5D07EC55D232D5B7E3B65F01EB2DDCE4D6E4300D06092A864886F70D01010B05003051310B300906035504061302504C31283026060355040A0C1F4B72616A6F776120497A626120526F7A6C69637A656E696F776120532E412E3118301606035504030C0F535A4146495220524F4F5420434132301E170D3135313031393037343333305A170D3335313031393037343333305A3051310B300906035504061302504C31283026060355040A0C1F4B72616A6F776120497A626120526F7A6C69637A656E696F776120532E412E3118301606035504030C0F535A4146495220524F4F542043413230820122300D06092A864886F70D01010105000382010F003082010A0282010100B7BC3E50A84BCD40B5CE61E796CAB4A1DA0C22B0FAB57B7600778C0BCF7DA886CC2651E4203D850CD658E3E7F42A189DDAD1AE26EEEB53DCF490D6134A0C903CC3F4DAD28E0D923ADCB1B1FF38DEC3BA2D5F80B902BD4A9D1B0FB4C3C2C16703DDDC1B9C3DB3B0DE001EA83447BB9AEBFE0B14BD3684DA0D20BFFA5BCBA91620AD3960EE2F75B6E7979CF93EFD7E4D6F4D2FEF880D6AFADDF13D6E20A5A012B44D70B9CED7723B8993A780841C27497249B5FF3B959EC1CCC801ECE80E8A0A96E7B3A687E5D6F9052B0D9740703CBAAC755A9CD54D9D020AD24B9B664B46071765AD9F6C8800DC2289E0E164D467BC3179613CBBCA41CD5C6A00C83C388E58AF0203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020106301D0603551D0E041604142E16A94A18B5CBCCF56F50F3235FF85DE7ACF0C8300D06092A864886F70D01010B05000382010100B573F803DC595B1D76E9A32A7B9028B24DC0334FAA9AB1D4B8E427FFA99699CE46E06D7C4CA238A40670F0F44111EC3F478D3F7287F93BFDA46F2B5300E0FF39B96A070EEB1D1CF6A27290CB823D11828BD2BB9F2AAF21E663869D7919EFF7BB0C3590C38AED4F0FF5CC12D9A43EBBA0FC20955F4F262F1123834E75070FBF9BD1B41DE91004FECA608FA24CB8ADCFE1900FCDAE0AC75D7BB750D2D461FAD515DBD79F875154EBA5E3EBC985A0252037FB8ECE0C3484E13C81B2774E43A5885F8667A13DE6B45C61B63EDBFEB728C5A207AEB5CACA8D2A12EF97EDC230A4C92A7AFBF34D231B993334A02EF5A90B3FD45DE1CF849FE219C25F8AD6201EE373B7
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E252FA953FEDDB2460BD6E28F39CCCCF5EB33FDE
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E1C950E6EF22F84C5645728B922060D7D5A7A3E8
Blob
0F0000000100000030000000E4C58A0A499480862DB093ADA2B299298D57D1C586BEE12C4B74D5E13DD4BCBDA6D57BE981EEE012E984E6B83D0B4C7B030000000100000014000000E1C950E6EF22F84C5645728B922060D7D5A7A3E81D0000000100000010000000AFEC13F04D331040C81E81D2B3EC2E24140000000100000014000000E4AF2B26711A2B4827852F52662CEFF08913713E0B0000000100000018000000470054005300200052006F006F00740020005200310000006200000001000000200000002A575471E31340BC21581CBD2CF13E158463203ECE94BCF9D3CC196BF09A547209000000010000002A000000302806082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030820000000010000005E0500003082055A30820342A00302010202106E47A9C54B470C0DEC33D089B91CF4E1300D06092A864886F70D01010C05003047310B300906035504061302555331223020060355040A1319476F6F676C65205472757374205365727669636573204C4C43311430120603550403130B47545320526F6F74205231301E170D3136303632323030303030305A170D3336303632323030303030305A3047310B300906035504061302555331223020060355040A1319476F6F676C65205472757374205365727669636573204C4C43311430120603550403130B47545320526F6F7420523130820222300D06092A864886F70D01010105000382020F003082020A0282020100B611028B1EE3A1779B3BDCBF943EB795A7403CA1FD82F97D32068271F6F68C7FFBE8DBBC6A2E9797A38C4BF92BF6B1F9CE841DB1F9C597DEEFB9F2A3E9BC12895EA7AA52ABF82327CBA4B19C63DBD7997EF00A5EEB68A6F4C65A470D4D1033E34EB113A3C8186C4BECFC0990DF9D6429252307A1B4D23D2E60E0CFD20987BBCD48F04DC2C27A888ABBBACF5919D6AF8FB007B09E31F182C1C0DF2EA66D6C190EB5D87E261A45033DB079A49428AD0F7F26E5A808FE96E83C689453EE833A882B159609B2E07A8C2E75D69CEBA756648F964F68AE3D97C2848FC0BC40C00B5CBDF687B3356CAC18507F84E04CCD92D320E933BC5299AF32B529B3252AB448F972E1CA64F7E682108DE89DC28A88FA38668AFC63F901F978FD7B5C77FA7687FAECDFB10E799557B4BD26EFD601D1EB160ABB8E0BB5C5C58A55ABD3ACEA914B29CC19A432254E2AF16544D002CEAACE49B4EA9F7C83B0407BE743ABA76CA38F7D8981FA4CA5FFD58EC3CE4BE0B5D8B38E45CF76C0ED402BFD530FB0A7D53B0DB18AA203DE31ADCC77EA6F7B3ED6DF912212E6BEFAD832FC1063145172DE5DD61693BD296833EF3A66EC078A26DF13D757657827DE5E491400A2007F9AA821B6A9B195B0A5B90D1611DAC76C483C40E07E0D5ACD563CD19705B9CB4BED394B9CC43FD255136E24B0D671FAF4C1BACCED1BF5FE8141D800983D3AC8AE7A98371805950203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E04160414E4AF2B26711A2B4827852F52662CEFF08913713E300D06092A864886F70D01010C0500038202010038960AEE3DB4961E5FEF9D9C0B339F2BE0CAFDD28E0A1F4174A57CAA84D4E5F21EE63752329C0BD1611DBF28C1B6442935757798B27CD9BD74AC8A68E3A9310929016073E3477C53A8904A27EF4BD79F93E78236CE9A680C82E7CFD410166F5F0E995CF61F717DEFEF7B2F7EEA36D697700B15EED75C566A33A5E349380CB87DFB8D85A4B1595EF46AE1DDA1F66444AEE651832166C6113EF3CE47EE9C281F25DAFFAC6695DD350F5CEF202C62FD91BAA9CCFC5A9C93818329974A7C5A72B439D0B777CB79FD693A9237ED6E3865467EE960BD7988975F3812F4EEAF5B82C886D5E1996D8C04F276BA49F66EE96D1E5FA0EF27827640F8A6D3585C0F2C42DA42C67B8834C7C1D8459BC13EC5611DD9635049F634856AE018C56E47AB4142299BF6600DD231D3639823935A008148B4EFCD8ACDC9CF99EED99EAA36E1684B71491436283A3D1DCE9A8F25E68071612BB57BCCF9251681E1315FA1A37E16A49C166A9718BD7672A50B9E1D36E62FA12FBE70910FA8E6DAF8C492406C257E7BB309DCB217AD8044F068A58F9475FF745AE8A8027C0C09E2A94B0BA0850B62B9EFA13192FBEFF65104896CE8A974A1BB17B3B5FD490F7C3CEC831820434ED593BAB434B11F16361F0CE66439164CDCE0FE1DC8A9623D40EACAC53402B4AE89883335DC2C1373D827F1D072EE753B22DE9868665BF1C66347551CBAA5085175A64825
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E1C950E6EF22F84C5645728B922060D7D5A7A3E8
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E1A45B141A21DA1A79F41A42A961D669CD0634C1
Blob
0F00000001000000140000000437EFCE6C464D17FBE4DA5DB1552A44D69DBF1F030000000100000014000000E1A45B141A21DA1A79F41A42A961D669CD0634C168000000010000000800000000C06BD91DE8D4017E000000010000000800000000C0A06C6128D4011D0000000100000010000000238458FF4265151B5F4A1A91A645B4851400000001000000140000004B019B3E561A653676CB7B97AA9205EE32E728310B000000010000001600000043006F006D005300690067006E002000430041000000620000000100000020000000AE4457B40D9EDA96677B0D3C92D57B5177ABD7AC1037958356D1E094518BE5F209000000010000002A000000302806082B0601050507030106082B0601050507030206082B0601050507030406082B06010505070303200000000100000097030000308203933082027BA00302010202101413968314558CEA7B63E5FC34877744300D06092A864886F70D01010505003034311330110603550403130A436F6D5369676E2043413110300E060355040A1307436F6D5369676E310B300906035504061302494C301E170D3034303332343131333231385A170D3239303331393135303231385A3034311330110603550403130A436F6D5369676E2043413110300E060355040A1307436F6D5369676E310B300906035504061302494C30820122300D06092A864886F70D01010105000382010F003082010A0282010100F0E454692BD3C78F6A44E47E5827F80BD0E494128AF11B38382F1F319C06D42CA7DE0B2AAE1AA0E39E6ABF9F3CC76EA2F98B646C3AAD85555154A53855B8AB8304F23F6436F7C08D43436A66D1F7172AD5EF36FA301042D753CDF9FA33734CB3E984208AD6412735E438FA949BB87AE4791F33FB1BD82109287C4D18695E648A7A1993CA7EECF372E73707585928AC42F9C5FFCD3FE7A5FA38B1D00CC7D9521A53D681CC427A355BED4B3A7AF6B58ECCFF0F7CE46036872FADF0A1257DFFD24B11887054A641A8675352425EE4349EE4BEA3ECAA625DDDC34CA68241E4330BACC9330F6482572AFD0CAD36E10CAE4BC5EF3B99D923B35B5DB457EC74700C2A4F0203010001A381A030819D300C0603551D13040530030101FF303D0603551D1F043630343032A030A02E862C687474703A2F2F66656469722E636F6D7369676E2E636F2E696C2F63726C2F436F6D5369676E43412E63726C300E0603551D0F0101FF040403020186301F0603551D230418301680144B019B3E561A653676CB7B97AA9205EE32E72831301D0603551D0E041604144B019B3E561A653676CB7B97AA9205EE32E72831300D06092A864886F70D01010505000382010100D0D9A57EFE2960459D7E83CF6EBC476EF51A9E54764271B43C583F2D402542F6819CF18910C80EAA784F380957B03CC008FC358EF148518D0C7174BA84C4D7729B847C384E6406272AE1A7B5EC0899B40A0DD48573C812E135EDF105311D73990CEB96CADDD3E685AAF08AFB75C1F2093C656564F34CD8ADCB8869F3E483B70CBD175A9617CA5BFFADBB1CE92D8480D821BE8552D9D474B96985BA4DED2832EBF9614AE4C4361E19DC6F84111F95F5832818A833924327DD5D1304454F87D546CD3DA8BAF0F3B8562445EB37C7E1764F723918DF7E7472C7732D39EA60E6AD11A256877BC3689AFEF88C70A8DF6532F4A4408CA1C244030E940067A071008248
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E1A45B141A21DA1A79F41A42A961D669CD0634C1
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46
Blob
0F0000000100000014000000F45A0858C9CD920E647BAD539AB9F1CFC77F24CB030000000100000014000000E12DFB4B41D7D9C32B30514BAC1D81D8385E2D461D0000000100000010000000F919B9CCCE1E59C2E785F7DC2CCF6708140000000100000014000000DAED6474149C143CABDD99A9BD5B284D8B3CC9D86200000001000000200000006FFF78E400A70C11011CD85977C459FB5AF96A3DF0540820D0F4B8607875E58F090000000100000022000000302006082B0601050507030306082B06010505070308060A2B0601040182370A03040B000000010000002A0000005300650063007400690067006F0020002800550054004E0020004F0062006A006500630074002900000020000000010000006A040000308204663082034EA003020102021044BE0C8B500024B411D3362DE0B35F1B300D06092A864886F70D0101050500308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A656374301E170D3939303730393138333132305A170D3139303730393138343033365A308195310B3009060355040613025553310B3009060355040813025554311730150603550407130E53616C74204C616B652043697479311E301C060355040A131554686520555345525452555354204E6574776F726B3121301F060355040B1318687474703A2F2F7777772E7573657274727573742E636F6D311D301B0603550403131455544E2D5553455246697273742D4F626A65637430820122300D06092A864886F70D01010105000382010F003082010A0282010100CEAA813FA3A36178AA31005595119E270F1F1CDF3A9B826830C04A611DF12F0EFABE79F7A523EF55519684CDDBE3B96E3E31D80A2067C7F4D9BF94EB47043E02CE2AA25D870409F6309D188A97B2AA1CFC41D2A136CBFB3D91BAE7D97035FAE4E790C39BA39BD33CF5129977B1B709E068E61CB8F39463886A6AFE0B76C9BEF422E467B9AB1A5E77C18507DD0D6CBFEE06C7776A419EA70FD7FBEE9417B7FC85BEA4ABC41C31DDD7B6D1E4F0EFDF168FB25293D7A1D489A1072EBFE10112421E1AE1D89534DB647928FFBA2E11C2E5E85B9248FB470BC26CDAAD328341F3A5E54170FD65906DFAFA51C4F9BD962B19042CD36DA7DCF07F6F8365E26AAB8786750203010001A381AF3081AC300B0603551D0F0404030201C6300F0603551D130101FF040530030101FF301D0603551D0E04160414DAED6474149C143CABDD99A9BD5B284D8B3CC9D830420603551D1F043B30393037A035A0338631687474703A2F2F63726C2E7573657274727573742E636F6D2F55544E2D5553455246697273742D4F626A6563742E63726C30290603551D250422302006082B0601050507030306082B06010505070308060A2B0601040182370A0304300D06092A864886F70D01010505000382010100081F52B1374478DBFDCEB9DA959698AA556480B55A40DD21A5C5C1F35F2C4CC8475A69EAE8F03535F4D025F3C8A6A4874ABD1BB17308BDD4C3CAB635BB59867731CDA78014AE13EFFCB148F96B25252D51B62C6D45C198C88A565D3EEE434E3E6B278ED03A4B850B5FD3ED6AA775CBD15A872F3975135A72B002819FBEF00F845420626C69D4E14DC60D9943010D12968C789DBF50A2B144AA6ACF177ACF6F0FD4F824555FF0341649663E5046C96371383162B862B9F353AD6CB52BA212AA194F09DA5EE793C68E1408FEF0308018A086854DC87DD78B03FE6ED5F79D16AC922CA023E59C91521F94DF179473C3B3C1C17105200078BD13521DA83ECD001FC8
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E12DFB4B41D7D9C32B30514BAC1D81D8385E2D46
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E0B4322EB2F6A568B654538448184A5036874384
Blob
0F0000000100000014000000DB7C911BF8FE225C8AB812CD16072D8EDA9395BF030000000100000014000000E0B4322EB2F6A568B654538448184A50368743840B000000010000000E00000045004400490043004F004D0000001D0000000100000010000000179616EAC79381FE42C8386D9E564849140000000100000014000000A6B3E12B2B49B6D773A1AA94F501E773654CAC5062000000010000002000000003950FB49A531F3E1991942398DFA9E0EA32D7BA1CDD9BC85DB57ED9400B434A090000000100000054000000305206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B06010505070308060A2B0601040182370A030406082B0601050507030606082B060105050703072000000001000000B9050000308205B53082039DA0030201020208618DC7863B018205300D06092A864886F70D010105050030443116301406035504030C0D4143454449434F4D20526F6F74310C300A060355040B0C03504B49310F300D060355040A0C06454449434F4D310B3009060355040613024553301E170D3038303431383136323432325A170D3238303431333136323432325A30443116301406035504030C0D4143454449434F4D20526F6F74310C300A060355040B0C03504B49310F300D060355040A0C06454449434F4D310B300906035504061302455330820222300D06092A864886F70D01010105000382020F003082020A0282020100FF9295E1680676B42CC85848CAFD805429556324FF90659B10757BC36ADB620201F21886B57C5A38B1E458B9FBD3D82D9FBD3237BF2C156DBEB5F421D21391D907AD0105D6F3BD77CE5F42810AF96AE38300A82B2E55136381CA471C7B5C16577A1B8360043A3E65C3CD01DEDEA4D60CBA8EDED904EE1756229B8F63FD4D160BB77B778CF925B5D16D99122E4F1AB8E6EA0492AE3D11B951423D87B03185AF795A9CFEE74E5E924F43FCAB3AADA5122666B9E20CD798CED458A595400AB7449D13742BC2A5EB22159810D88BC5049F1D8F60E5061B9BCFB979A03DA2233F423F6BFA1C037B308DCE6CC0BFE61B5FBF67B88419D515EF7BCB90363162C9BC02AB465F9BFE1A6894343D908EADF6E41D097F4A88383FBE67FD3496F51DBC3074CB38EED56CABD4FCF400B7005B8532167633E9D8A3999D0500AA16E6F3817D6F7DAA866DAD1574D3C4A271AAF4147DE732B81FBCD5F14EBD6F170239D70E95423AC7003EE9266311EA0BD14AFF189DB2D77B2F3AD996FBE81E92AE1355C8D927F6DC481BB024C185E3779D9AA4F30C111D0DC8B414EEB5825709BF20587F2F2223D870CB796CC94BF2A92AC8FC872BD71A50F827E82F43E33ABDD85771FDCEA6525BF9DD4DEDE5F66F89EDBB939C762175F0924C29F72F9C012EFE50469E640C14B3075BC5C2736CF1075C45241435AE83F16A4D897AFAB3D82D66F03687F52B530203010001A381AA3081A7300F0603551D130101FF040530030101FF301F0603551D23041830168014A6B3E12B2B49B6D773A1AA94F501E773654CAC50300E0603551D0F0101FF040403020186301D0603551D0E04160414A6B3E12B2B49B6D773A1AA94F501E773654CAC5030440603551D20043D303B30390604551D20003031302F06082B060105050702011623687474703A2F2F6163656469636F6D2E656469636F6D67726F75702E636F6D2F646F63300D06092A864886F70D01010505000382020100CE2C0B525162267D0C27838FC5F6DAA0687B4F925EEAA47332115344B244CB9DEC0F7942B310A6C70D9DCBB6FA3F3A7CEABF88531B3CF782FA053533E135A857C0E7FD8D4F3F93324F786603770758E995C87E3ED079008CF21B51339BBC94E93A7B6E522D329E23A445FBB62E13B08B18B1DDCED51DA7427F55BEFB5BBB47D4FC24CD04AE960515D6ACCE30F3CA0BC5BAE222E0A6AD22E402EE74117F4CFF781D35DAE60234EB1812617706091663EA18ADA2871FF2C7800909754E10A88F3D86B87511C024628A967B4A45E9EC59C5BE6B83E6E1E8ACB5301EFE050780F9E1230D508F0598FF2C5FE83BB6ADCF81B52187CA082A232730202BCFED945BACB27AD2C728A18A0B9B4D4A2C6D853F09723C67E2D9DC07BAEB657B5A0163D6905B4F17663D7F0B19A3936310522A9F141658E2DCA5F4A1168B0E918B81CA9B59FAD86B910765555F521FAF3AFB90DD69A55B9C6D0E2CB6FACEACA57C324A6740DC303423DDD7042366F0FC5580A7FB66198235676270395E6FC7EA904044081EB8B2D6DBEE59A70D187934BC54185E53CA3451ED450AE68EC782363EA73863A9302C171060929F5587125910C20F676911CC4E1E7E4A9AADAF40A875AC569074B8A09CA5796FDCE91AC86905E9BAFA03B37CE4E04EC2CE9DE8B6460D6E7E573A6794C2CB1F9C774A674E6986439338FBB6DB4F8391D4607E4B3E2B380755985EA4
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E0B4322EB2F6A568B654538448184A5036874384
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E0AB059420725493056062023670F7CD2EFC6666
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E0AB059420725493056062023670F7CD2EFC6666
Blob
0F0000000100000014000000A0A4DC95E6DCE4171F4F508D8E02D74C6BF78DF2030000000100000014000000E0AB059420725493056062023670F7CD2EFC6666090000000100000020000000301E06082B0601050507030106082B0601050507030306082B060105050703080B000000010000004000000054006800610077007400650020005000720065006D00690075006D0020005300650072007600650072002000430041002000280053004800410031002900000020000000010000003A030000308203363082029FA003020102021036122296C5E338A520A1D25F4CD70954300D06092A864886F70D01010505003081CE310B3009060355040613025A41311530130603550408130C5765737465726E204361706531123010060355040713094361706520546F776E311D301B060355040A131454686177746520436F6E73756C74696E6720636331283026060355040B131F43657274696669636174696F6E205365727669636573204469766973696F6E3121301F06035504031318546861777465205072656D69756D205365727665722043413128302606092A864886F70D01090116197072656D69756D2D736572766572407468617774652E636F6D301E170D3936303830313030303030305A170D3231303130313233353935395A3081CE310B3009060355040613025A41311530130603550408130C5765737465726E204361706531123010060355040713094361706520546F776E311D301B060355040A131454686177746520436F6E73756C74696E6720636331283026060355040B131F43657274696669636174696F6E205365727669636573204469766973696F6E3121301F06035504031318546861777465205072656D69756D205365727665722043413128302606092A864886F70D01090116197072656D69756D2D736572766572407468617774652E636F6D30819F300D06092A864886F70D010101050003818D0030818902818100D236366A8BD7C25B9EDA8141628F38EE490455D6D0EF1C1B951647EF1848353A52F42B6A068F3B2FEA56E3AF868D9E17F79EB46575024DEFCB09A22151D89BD067D0BA0D92061473D493CB972A009C5C4E0CBCFA1552FCF2446EDA114A6E089F2F2DE3F9AA3A8673B6465358C88905BD8311B8733FAA078DF4424DE7409D1C370203010001A3133011300F0603551D130101FF040530030101FF300D06092A864886F70D0101050500038181006590AC880F56D9E63034D426C7D050F192DE6BD439880922C6A6638303F79977D8B2E518B85D63F3D473FB6C9C9978F14B787D1924C32B0284F8BC22D98A22D7A0FC71EC918720F1B8ECB1E55580AC3D52C8390EC2F0C0054FD682758CBD5FD2DC769A0512C9AF72C3DC257EA44D8E17A5E0877FE19A5AE160DC64233C422E4D
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E0925E18C7765E22DABD9427529DA6AF4E066428
Blob
0F0000000100000014000000E1E83E67D95E41D7EB0C5AE1AE0355AFF672E58A0B000000010000002C00000048006F006E0067006B006F006E006700200050006F0073007400200052006F006F0074002000430041000000090000000100000034000000303206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030806082B06010505070309030000000100000014000000E0925E18C7765E22DABD9427529DA6AF4E06642820000000010000002F0300003082032B30820213A003020102020101300D06092A864886F70D01010505003045310B300906035504061302484B31163014060355040A130D486F6E676B6F6E6720506F7374311E301C06035504031315486F6E676B6F6E6720506F737420526F6F74204341301E170D3030303131363037343230305A170D3130303131363233353930305A3045310B300906035504061302484B31163014060355040A130D486F6E676B6F6E6720506F7374311E301C06035504031315486F6E676B6F6E6720506F737420526F6F7420434130820122300D06092A864886F70D01010105000382010F003082010A0282010100A5A291BE3CE5363C4AEF348F88FDBA6D71A66272EDC206BC7625BB8A5F15252738DDE99191018A6F8ED55BA6BF3E23B363C354E1F1C30C964CFB7A0E271EF0231080D22868BD06958B7DE929F9D427F6F2775F22AB25A8459797455661589C8724329D381D3DEDB81C74053565A0A5910FAF683D7A0F5C21FBE72C1BFE56865271736481D4E08480D09556BD49D03D24335D8E7A823854B66AF4BA74692EBBD141701174E6376863AF4CEADCA220CDF68F4CE6D080082450991874E5CED607D07816065F3DDC85CB743F787F19C80D8E4854696A0580A96CB241FEB404068BBAB5A27E29A6AAAF41E91C4911B70D4808727F4B8398F3131A794BD14E14CE12330203010001A326302430120603551D130101FF040830060101FF020103300E0603551D0F0101FF040403020106300D06092A864886F70D010105050003820101009505191630569CB9984B40348D115B4F24F12C68C2B5ACB5E0B484A04C6DEC8A7661C1F3D574F1619F7CBE20922752FA3124B8D19EE0F36D50BAADE22DAF28756BE12AEFF821CD3BCBC8321ED3BA59CF38E8F29078DD9E0844955F864F6A9BDCA28BE59CA6568B8665351C6C0CCA1EA49E4E5C1293D278C8D869EA698626D4A4D38FAD574A58F4ECC67F6CBBB4F2C792F2CE3CF442C32167866DA54DA03FC2F718AB57D6E8C792FA86A736050E1972BF06F0ACA4444CAC3EE8EF7D0B48C5C11B33E9C901D0CCEFFE61ED8CE8329ACCF5C9D9C93D78A600051D29EB26018E4BFE39ACC592FFBE709A57C2F2CF21B8662EDEE0D4FEBBDBB44789927F18BC2C86B5
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E0925E18C7765E22DABD9427529DA6AF4E066428
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E011845E34DEBE8881B99CF61626D1961FC3B931
Blob
0F0000000100000030000000836D9489191F18A2959E1C1FD1C0EF276C268788B1F10506F1893C6A299199131076EB746B7009D92FD65008E113D1CE030000000100000014000000E011845E34DEBE8881B99CF61626D1961FC3B9317E00000001000000080000000000042BEB77D5017F000000010000000C000000300A06082B060105050703031D0000000100000010000000739C893CF462CB0C22A038C0EA9497A5140000000100000014000000488714ACE3C39E90603AD7CA89EED3AD8CB450666200000001000000200000008560F91C3624DABA9570B5FEA0DBE36FF11A8323BE9486854FB3F34A5571198D0B00000001000000400000004F004900530054004500200057004900530065004B0065007900200047006C006F00620061006C00200052006F006F007400200047004300200043004100000009000000010000004C000000304A06082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B06010505070308060A2B0601040182370A0304060A2B0601040182370A030C20000000010000006D02000030820269308201EFA0030201020210212A560CAEDA0CAB4045BF2BA22D3AEA300A06082A8648CE3D040303306D310B30090603550406130243483110300E060355040A1307574953654B657931223020060355040B13194F4953544520466F756E646174696F6E20456E646F72736564312830260603550403131F4F4953544520574953654B657920476C6F62616C20526F6F74204743204341301E170D3137303530393039343833345A170D3432303530393039353833335A306D310B30090603550406130243483110300E060355040A1307574953654B657931223020060355040B13194F4953544520466F756E646174696F6E20456E646F72736564312830260603550403131F4F4953544520574953654B657920476C6F62616C20526F6F742047432043413076301006072A8648CE3D020106052B81040022036200044CE950C0C60F7218BCD8F1BAB389E2794AA316A76B5424DB51FFEAF40924C30B229FCB6A2782810DD2C0AF31E474826ECA25D98C759DF1DBD09AA24B217E16A76390D239D4B187785F18960F501B35370F6AC6DCD9134DA48E9037E6BD5B3191A3543052300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E04160414488714ACE3C39E90603AD7CA89EED3AD8CB45066301006092B06010401823715010403020100300A06082A8648CE3D0403030368003065023026C7695BDCD5E7B2E7C80C8C8CC3DD798C1B63D5C952944E4D824A731EB28084A925C04C5A6D4929607813E27E48EB64023100DB34203208FF9A4902B688DE14AF5D6C99718D1A3F8BD7E0A236861C07823A7653FDC2A2EDEF7BB0804F580F4B5339BD
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\E011845E34DEBE8881B99CF61626D1961FC3B931
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF717EAA4AD94EC9558499602D48DE5FBCF03A25
Blob
0F00000001000000200000007A9BC7FFECF427111C5A2E5BF589FFFF1EE95FEF12B3CC42764D7C907A3F6959030000000100000014000000DF717EAA4AD94EC9558499602D48DE5FBCF03A251D000000010000001000000066908ED134572466070299553E6E2B99140000000100000014000000ED4419C0D3F0068BEEA47BBE42E72654C88E36766200000001000000200000005D56499BE4D2E08BCFCAD08A3E38723D50503BDE706948E42F55603019E528AE0B000000010000003E0000004900640065006E0054007200750073007400200043006F006D006D00650072006300690061006C00200052006F006F007400200043004100200031000000090000000100000042000000304006082B0601050507030106082B0601050507030406082B0601050507030206082B06010505070308060A2B0601040182370A0304060A2B0601040182370A030C530000000100000081000000307F3020060A6086480186F92F00060930123010060A2B0601040182373C0101030200C0301B060567810C010130123010060A2B0601040182373C0101030200C03021060B6086480186F92F00060E0130123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C02000000001000000640500003082056030820348A00302010202100A0142800000014523C844B500000002300D06092A864886F70D01010B0500304A310B300906035504061302555331123010060355040A13094964656E5472757374312730250603550403131E4964656E547275737420436F6D6D65726369616C20526F6F742043412031301E170D3134303131363138313232335A170D3334303131363138313232335A304A310B300906035504061302555331123010060355040A13094964656E5472757374312730250603550403131E4964656E547275737420436F6D6D65726369616C20526F6F74204341203130820222300D06092A864886F70D01010105000382020F003082020A0282020100A75019DE3F993DD43346F16F516182B2A94F8F67895D84D953DD0C28D9D7F0FFAE95437299F9B55D7C8AC142E1315074D1810D7CCD9B21AB43E2ACAD5E866EF3098A1F5A32BDA2EB94F9E85C0AECFF98D2AF71B3B4539F4E87EF92BCBDEC4F3230884B175E57C453C2F602978DD9622BBF241F628DDFC3B8294B49783C93608822FC99DA36C8C2A2D42C540067356E73BF0258F0A4DDE5B0A2267ACAE036A51916F5FDB7EFAE3F40F56D5A04FDCE34CA24DC74231B5D3313125DC40125F630DD025D9FE0D547BDB4EB1BA1BB4949D89F5B02F38AE42490E4624F4FC1AF8B0E7417A8D172886A7A0149CCB44679C617B1DA981E0759FA75218565DD9056CEFBABA5609DC49DF952B08BBD87F98F2B230A23763BF733E1C900F369F94BA2E04EBC7E93398407F744707EFE075AE5B1ACD118CCF235E5494908CA56C93DFB0F187D8B3BC113C24D8FC94F0E37E91FA10E6ADF622ECB350651792CC82538F4FA4BA7895C9CD2E30D39864A747CD55987C23F4E0C5C52F43DF75282F1EAA3ACFD49341A28F341883A13EEE8DEFF991D5FBACBE81EF2B95060C031D373E5EFBEA0ED330B74BE2020C4676CF008037A55807F464E96A7F41E3EE1F6D809E133642B63D7325E9FF9C07B0F786F97BC939AF99C1290787A808715D772749C557478B1BAE16E7004BA4FA0BA68C37BFF31F0733D3D942AB10B410EA0FE4D88656B7933B4D70203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E04160414ED4419C0D3F0068BEEA47BBE42E72654C88E3676300D06092A864886F70D01010B050003820201000DAE9032F6A64B7C447619611E2728CD5E54EF25BCE30890F929D7AE6808E1940058EF2E2E7E53528CB65C07EA88BA998B5094D78280DF61090093AD0D14E6CEC1F2379478B05F9CB3A273B88F059338CD8D3EB0B8FBC0CFB1F2EC2D2D1BCCECAA9AB3AA60821B2D3BC3843D578A961E9C75B8D330CD60088390D38E54F14D66C05D740340A3EE857EC21F779C06E8C1A7185D5295EDC9DD259E6DFAA9EDA33A34D0597BDAED50F335BFEDEB144D31C760F4DAF1879CE248E2C6C537FB0610FA755966314729DA769A1CE982AEEF9AB951F788239A6995623CE5558036D75402FFF1B95DCED4236FD845844A5B65EF890CDD14A720CB18A525B40DF901F0A2D2F400C8748EA12A488E65DB13C4E225177DEBBE875B17205451934A53030BEC5DCA33ED62FD45C72F5BDC58A08039E6FAD7FE1314A6ED3D944A4274D4C3775973CD8F46BE5538EFFAE89132EA97580422DE38C3CCBC6DC9333A6A0A693FA0C8EA728F8C638623BD6D3C969E95E0494CAAA2B92A1B9C368178EDC3E846E2265944751ED9758951CD10849D6160CB5DF997224D8E98E6E37FF65BBBAECDCA4A816B5E0BF351E1742BE97E27A7D999494EF8A580DB250F1C63628AC933676B3C1083C6ADDEA8CD168E8DF00737719FF2ABFC41F5C18BEC00375D09E54E80EFFAB15C3806A51B4AE1DC382D3CDCAB1F901AD54A9CEED1706CCCEEF457F818BA846E87
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF717EAA4AD94EC9558499602D48DE5FBCF03A25
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF646DCB7B0FD3A96AEE88C64E2D676711FF9D5F
Blob
0F0000000100000020000000CA6FAF52BF1A102FB5C0C4474C1A60A7F959FE5670ADD4AA4DA718A41B3A221B030000000100000014000000DF646DCB7B0FD3A96AEE88C64E2D676711FF9D5F680000000100000008000000008024EED112D2011D00000001000000100000009018DBB7B972B1C88E9B9E875708115E140000000100000014000000C8445AFE7FFDA99B8635BEE2A5F619FB5EBF6F59620000000100000020000000632D80BB096D209677D1734E5B35EA9D3019B9C44F8FCB2640C879039AC94EE80B00000001000000480000005400570043004100200052006F006F0074002000430065007200740069006600690063006100740069006F006E00200041007500740068006F007200690074007900200032000000090000000100000054000000305206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B06010505070308060A2B0601040182370A030406082B0601050507030606082B0601050507030720000000010000007F0500003082057B30820363A003020102020101300D06092A864886F70D01010B0500305F310B300906035504061302545731123010060355040A0C0954414957414E2D43413110300E060355040B0C07526F6F74204341312A302806035504030C215457434120526F6F742043657274696669636174696F6E20417574686F72697479301E170D3038303832383037343731335A170D3330313233313135353935395A305F310B300906035504061302545731123010060355040A0C0954414957414E2D43413110300E060355040B0C07526F6F74204341312A302806035504030C215457434120526F6F742043657274696669636174696F6E20417574686F7269747930820222300D06092A864886F70D01010105000382020F003082020A0282020100CB010C6481BB504899F31CD920B08BA48712F7AE4FCE5E73CBA88615E21CF9996306DA1CD60ABCFE94BADE6081689CB2F24B7701DAB71BC6F9F560902078FC314A3E3577C01A1E8C59557855704192099B024AC36FAC0B98E9B2527D9A7FBF5D1F038742FDC31CEA633065D1B58E9C695A6BEE338DAFBAFA632450892DC9051E6CEB8E5E8E0148A180C338452B4E1FF422C2F82E4A767EEACE9CD1188757F6B6FAEDCC90558E80CA35B9DA646516CCE96451593EFB8ACE80B0A5924563FD9B9600BC5C5E868EC549DF14A8C9919B78F71C8C2686689AF981C3817B3D33DB105E3D0469D666E0AE39DC89E2E626FB517F7BA8096B872638CDD98D2D9E3DCAB1F32B9BFD46ED81DBCF8521BEC045C9E589DD7697BFB48144293BB7981734F2B8AA9AB07B415526C13CB4249796AD1B8F3671B72BF3B6830230FAB20A13BC4BB60FF9A39D636E2250D328DC5F36073C29AC4568EA22405D3F09C70A328FCAB4E5E8D7D7CA8B64FF6F6525EC0D74A8B51C1A26E628B272CECDFAC4244A3712E2D8B709CEAC2E273DC214EBEA308C37CA73198589B3BBFB38431D79A5A58B1924A0A612521AFED157C19D127B9D95D66C7B4A1DC1AE15024D2C63A075273FFEF20020324AE5B1AC2E13E048A6F44E91540CD974583E1175EDFA9CC2AABB487FCBF65F5C26B009877AC4FD9C7EAF336742571653FEF13D4340528AB635714FFC013CE50203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E04160414C8445AFE7FFDA99B8635BEE2A5F619FB5EBF6F59300D06092A864886F70D01010B05000382020100128BDDD5089D286F08F189566D4007ABFBE108A804A4BED77D85AE5A58B6674C0169CDAC8B368E5CFD3B3601F9D5A17B287A4C8493CDC40B19F01204894D8FEDA0992585BB2C95996C30ED6D046FE62BFB8910BB4C930CBE93D5D60984930070CFCEC5781AED5554DF2F0E5958F83585AE4FF821D292DE21BA99D197F1609EAC4443A760AF89E251D23989109415CF04D22182EFCAED69154F19ABBC936A9901E002D11C3A9D31CAF5FBC4F64D9ABB208C3F6F71327F274B447F8151E9931B620EA4875F3DDD5440B924976257958EC71091A798C5584250A9961CE54AB6B6B2DC4E91F280D291E85008D31640890F6813AEC35C57171317ED331DB2EA91F6AA2E71444089B2E066BDB1BD173D4D3D0F57392565046A2A83DB38B5CEBFE400D74D283790A8A9A6E4B155F0CACFE30C6A2F4796B7D4E4EFC837033C7FEB81928A2A69981D013B488A2D6BAFE5CFB2B4DDD6677A80010B045725B665420F49E123CA40AAC22CFC85AF6518AA0731DB2DAEEBC371E668DF3797F99A3FF1255EF0DF57E9FC12E039068774DD63936B81C4F3E0DB0914D8BFBF406F71812668F7A58517405203BE5C9314E541521577BC35A147732A0C975C8CDE313C638CF09B5F544FD2E25B6C3C1CC3E7346673A641A32032447BCDEABC6997FD437031BC3282A26598A3402F6A46F400502E55E0DB7A4EE06DC868E154E8958318BEFACD8F1D66
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF646DCB7B0FD3A96AEE88C64E2D676711FF9D5F
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DF3C24F9BFD666761B268073FE06D1CC8D4F82A4
Blob
0F00000001000000200000004B4EB4B074298B828B5C003095A10B4523FB951C0C88348B09C53E5BABA408A3030000000100000014000000DF3C24F9BFD666761B268073FE06D1CC8D4F82A41D00000001000000100000007DC30BC974695560A2F0090A6545556C1400000001000000140000004E2254201895E6E36EE60FFAFAB912ED06178F39620000000100000020000000CB3CCBB76031E5E0138F8DD39A23F9DE47FFC35E43C1144CEA27D46A5AB1CB5F5300000001000000230000003021301F06096086480186FD6C020130123010060A2B0601040182373C0101030200C00B000000010000003000000044006900670069004300650072007400200047006C006F00620061006C00200052006F006F0074002000470032000000090000000100000034000000303206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B060105050703082000000001000000920300003082038E30820276A0030201020210033AF1E6A711A9A0BB2864B11D09FAE5300D06092A864886F70D01010B05003061310B300906035504061302555331153013060355040A130C446967694365727420496E6331193017060355040B13107777772E64696769636572742E636F6D3120301E06035504031317446967694365727420476C6F62616C20526F6F74204732301E170D3133303830313132303030305A170D3338303131353132303030305A3061310B300906035504061302555331153013060355040A130C446967694365727420496E6331193017060355040B13107777772E64696769636572742E636F6D3120301E06035504031317446967694365727420476C6F62616C20526F6F7420473230820122300D06092A864886F70D01010105000382010F003082010A0282010100BB37CD34DC7B6BC9B26890AD4A75FF46BA210A088DF51954C9FB88DBF3AEF23A89913C7AE6AB061A6BCFAC2DE85E092444BA629A7ED6A3A87EE054752005AC50B79C631A6C30DCDA1F19B1D71EDEFDD7E0CB948337AEEC1F434EDD7B2CD2BD2EA52FE4A9B8AD3AD499A4B625E99B6B00609260FF4F214918F76790AB61069C8FF2BAE9B4E992326BB5F357E85D1BCD8C1DAB95049549F3352D96E3496DDD77E3FB494BB4AC5507A98F95B3B423BB4C6D45F0F6A9B29530B4FD4C558C274A57147C829DCD7392D3164A060C8C50D18F1E09BE17A1E621CAFD83E510BC83A50AC46728F67314143D4676C387148921344DAF0F450CA649A1BABB9CC5B1338329850203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020186301D0603551D0E041604144E2254201895E6E36EE60FFAFAB912ED06178F39300D06092A864886F70D01010B05000382010100606728946F0E4863EB31DDEA6718D5897D3CC58B4A7FE9BEDB2B17DFB05F73772A3213398167428423F2456735EC88BFF88FB0610C34A4AE204C84C6DBF835E176D9DFA642BBC74408867F3674245ADA6C0D145935BDF249DDB61FC9B30D472A3D992FBB5CBBB5D420E1995F534615DB689BF0F330D53E31E28D849EE38ADADA963E3513A55FF0F970507047411157194EC08FAE06C49513172F1B259F75F2B18E99A16F13B14171FE882AC84F102055D7F31445E5E044F4EA879532930EFE5346FA2C9DFF8B22B94BD90945A4DEA4B89A58DD1B7D529F8E59438881A49E26D56FADDD0DC6377DED03921BE5775F76EE3C8DC45D565BA2D9666EB33537E532B6
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE990CED99E0431F60EDC3937E7CD5BF0ED9E5FA
Blob
0F0000000100000014000000210B7771CF36A78E846392B77D2F078AF48B13F7030000000100000014000000DE990CED99E0431F60EDC3937E7CD5BF0ED9E5FA7E000000010000000800000000809EF40C18D5017A000000010000000C000000300A06082B060105050703011D00000001000000100000004226C1DC9DBDEB7DC4AB4AFA9500101914000000010000001400000027F3C8151E6E9A020916AD2BA089605FDA7B2FAA7F0000000100000016000000301406082B0601050507030106082B060105050703030B000000010000001C00000043006900730063006F002000530079007300740065006D00730000006200000001000000200000008327BC8C9D69947B3DE3C27511537267F59C21B9FA7B613FAFBCCD53B7024000090000000100000068000000306606082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B06010505070308060A2B0601040182370A030406082B0601050508020206082B0601050507030606082B0601050507030706082B06010505070305200000000100000047030000308203433082022BA00302010202105FF87B282B54DC8D42A315B568C9ADFF300D06092A864886F70D0101050500303531163014060355040A130D436973636F2053797374656D73311B301906035504031312436973636F20526F6F742043412032303438301E170D3034303531343230313731325A170D3239303531343230323534325A303531163014060355040A130D436973636F2053797374656D73311B301906035504031312436973636F20526F6F74204341203230343830820120300D06092A864886F70D01010105000382010D00308201080282010100B09AB9ABA7AF0A77A7E271B6B4666294788847C66255844032BFC0AB2EA51C71D6BC6E7BA8AABA6ED2158848459DA2FC83D0CCB98CE02668704A78DF21179EF46105C915C8CF16DA3561899443A884A83198789BB94E6F2C53126CCD1DAD2B24BB31C42BFF83446FB63D247709EABF2AA81F6A56F6200F1154978175A725CE596A8265EFB7EAE7E28D758B6EF2DD4FA65E629CCF100A64D04E6DCE2BCC5BF560A527478D69F47FCE1B70DE701B20D66ECDA601A83C12D2A93FA06B5EBB8E208B7A91E3B568EEA0E7C40174A8530B2B4A9A0F65120E824D8E63FDEFEB9B1ADB53A61360AFC27DD7C76C1725D473FB4764508180944CE1BFAE4B1CDF92ED2E05DF020103A351304F300B0603551D0F040403020186300F0603551D130101FF040530030101FF301D0603551D0E0416041427F3C8151E6E9A020916AD2BA089605FDA7B2FAA301006092B06010401823715010403020100300D06092A864886F70D010105050003820101009D9D8484A341A97C770CB753CA4E445062EF547CD375171CE8E0C6484BB6FE4C3A198156B056EE199662AA5AA364C1F64E5433C677FEC51CBAE55D25CAF5F0939A83112EE6CBF87445FEE705B8ABE7DFCB4BE13784DAB98B97701EF0E28BD7B0D80E9DB169D62A917BA9494F7EE68E95D883273CD568490ED49DF62EEBA7BEEB30A4AC1F44FC95AB3306FB7D600ADEB48A63B09CA9F2A4B9530187D068A4277FABFFE9FAC940388867B439C6846F57C953DBBA8EEEC043B2F809836EFF66CF3EEF17B358182509345EE3CBD614B6ECF2926F74E42F812AD59291E0E0973C326805854BD1F757E2521D931A549F0570C04A71601E430B601EFEA3CE8119E10B35
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE990CED99E0431F60EDC3937E7CD5BF0ED9E5FA
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE3F40BD5093D39B6C60F6DABC076201008976C9
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE3F40BD5093D39B6C60F6DABC076201008976C9
Blob
0F00000001000000140000008A2375A87E6675F9FB223BE8FECE422D4573BC91030000000100000014000000DE3F40BD5093D39B6C60F6DABC076201008976C91D000000010000001000000036D5F95CC9FA9EFF45D97FC248E9AF801400000001000000140000008B4B6DEDD329B90619EC3939A9F097846ACBEFDF620000000100000020000000A45EDE3BBBF09C8AE15C72EFC07268D693A21C996FD51E67CA079460FD6D887353000000010000002400000030223020060A2B0601040182375E010130123010060A2B0601040182373C0101030200C0090000000100000034000000303206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B060105050703080B000000010000004C000000510075006F0056006100640069007300200052006F006F0074002000430065007200740069006600690063006100740069006F006E00200041007500740068006F00720069007400790000002000000001000000D4050000308205D0308204B8A00302010202043AB6508B300D06092A864886F70D0101050500307F310B300906035504061302424D31193017060355040A131051756F5661646973204C696D6974656431253023060355040B131C526F6F742043657274696669636174696F6E20417574686F72697479312E302C0603550403132551756F566164697320526F6F742043657274696669636174696F6E20417574686F72697479301E170D3031303331393138333333335A170D3231303331373138333333335A307F310B300906035504061302424D31193017060355040A131051756F5661646973204C696D6974656431253023060355040B131C526F6F742043657274696669636174696F6E20417574686F72697479312E302C0603550403132551756F566164697320526F6F742043657274696669636174696F6E20417574686F7269747930820122300D06092A864886F70D01010105000382010F003082010A0282010100BF61B59553BA57FCFAF2670B3A1ADF11806495B4D1BCCD7ACFF629962E2454402438F71A85DC584CCBA4274297D09F838AC3E406035B00A5511E700474E2C1D43AABD7AD3B0718058EFD83ACEA66D9181B688AF5571A98BAF5ED763D7CD9DE946A3B4B17C1D58FBD65383A95D03D55364EDF7957312A1ED85965495820987EAB5F7E9FE9D64DEC8374A9C76CD8EE294A852A0614F954E6D3DA65078B633712D7D0ECC37B204144A3EDCBA017E17165CE1D6631F7760119C87D0358B695491DA61226E8C60C76E0E366CBEA5DA626EEE5CC5FBD67A701270EA2CA54C5B17A951D711E4A298A03DC6A45C1A4195E6F36CDC3A2B0B7FE5C38E252BCF84443E690BB0203010001A38202523082024E303D06082B060105050701010431302F302D06082B06010505073001862168747470733A2F2F6F6373702E71756F76616469736F666673686F72652E636F6D300F0603551D130101FF040530030101FF3082011A0603551D20048201113082010D3082010906092B06010401BE5800013081FB3081D406082B060105050702023081C71A81C452656C69616E6365206F6E207468652051756F566164697320526F6F7420436572746966696361746520627920616E7920706172747920617373756D657320616363657074616E6365206F6620746865207468656E206170706C696361626C65207374616E64617264207465726D7320616E6420636F6E646974696F6E73206F66207573652C2063657274696669636174696F6E207072616374696365732C20616E64207468652051756F566164697320436572746966696361746520506F6C6963792E302206082B060105050702011616687474703A2F2F7777772E71756F76616469732E626D301D0603551D0E041604148B4B6DEDD329B90619EC3939A9F097846ACBEFDF3081AE0603551D230481A63081A380148B4B6DEDD329B90619EC3939A9F097846ACBEFDFA18184A48181307F310B300906035504061302424D31193017060355040A131051756F5661646973204C696D6974656431253023060355040B131C526F6F742043657274696669636174696F6E20417574686F72697479312E302C0603550403132551756F566164697320526F6F742043657274696669636174696F6E20417574686F7269747982043AB6508B300E0603551D0F0101FF040403020106300D06092A864886F70D010105050003820101008AD414B5FEF49A92A719D4A47E72188FD9687C5224DD676F397AC4AA5E3DE258B04D70988461E81BE369180ECEFB4750A04EFFF0241FBDB2CEF527FCEC2F53AA737B033D746EE6169EEBA52EC4BF5627502B62BABE4B1C3C555C411D24BE8220475DD5447E7A1668DF7D4D517078571D331EFD02999C0CCD0A054FC7BB8EA475FA4A6DB1808E0956B99C1A60FE5DC1D77ADC1178D0D65DC1B7D5AD3299033A8ACC54253931817B132251BA466CA1BB9EFA046C4926748FD273EBCC30A2E6EA592287F897F50EFDEACC92A416C45218EA21CEB1F1E68481E5BAA98628F2435A5D129DAC1ED9A8E50A6AA77FA08729CFF2894DD4ECC5E2E67AD036238A4A7436F9
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE28F4A4FFE5B92FA3C503D1A349A7F9962A8212
Blob
0F0000000100000014000000F6D2EF0341D7F1BAA1DE015024AF0D8221EF716E030000000100000014000000DE28F4A4FFE5B92FA3C503D1A349A7F9962A82121D00000001000000100000000DBE99793CDF5DCF29109233CC451BA5140000000100000014000000C07A98688D89FBAB05640C117DAA7D65B8CACC4E620000000100000020000000FF856A2D251DCD88D36656F450126798CFABAADE40799C722DE4D2B5DB36A73A0B0000000100000026000000470065006F0054007200750073007400200047006C006F00620061006C002000430041000000090000000100000034000000303206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B06010505070308200000000100000058030000308203543082023CA0030201020203023456300D06092A864886F70D01010505003042310B300906035504061302555331163014060355040A130D47656F547275737420496E632E311B30190603550403131247656F547275737420476C6F62616C204341301E170D3032303532313034303030305A170D3232303532313034303030305A3042310B300906035504061302555331163014060355040A130D47656F547275737420496E632E311B30190603550403131247656F547275737420476C6F62616C20434130820122300D06092A864886F70D01010105000382010F003082010A0282010100DACC186330FDF417231A567E5BDF3C6C38E471B77891D4BCA1D84CF8A843B603E94D21070888DA582F663929BD05788B9D38E805B76A7E71A4E6C460A6B0EF80E489280F9E25D6ED83F3ADA691C798C9421835149DAD9846922E4FCAF18743C11695572D50EF892D807A57ADF2EE5F6BD2008DB914F8141535D9C046A37B72C891BFC9552BCDD0973E9C2664CCDFCE831971CA4EE6D4D57BA919CD55DEC8ECD25E3853E55C4F8C2DFE502336FC66E6CB8EA4391900B7950239910B0EFE382ED11D059AF64D3E6F0F071DAF2C1E8F6039E2FA36531339D45E262BDB3DA814BD32EB180328520471E5AB333DE138BB073684629C79EA1630F45FC02BE8716BE4F90203010001A3533051300F0603551D130101FF040530030101FF301D0603551D0E04160414C07A98688D89FBAB05640C117DAA7D65B8CACC4E301F0603551D23041830168014C07A98688D89FBAB05640C117DAA7D65B8CACC4E300D06092A864886F70D0101050500038201010035E3296AE52F5D548E2950949F991A14E48F782A6294A227679ED0CF1A5E47E9C1B2A4CFDD411A054E9B4BEE4A6F5552B324A1370AEB64762A2E2CF3FD3B7590BFFA71D8C73D37D2B5059562B9A6DE893D367B38774897ACA6208F2EA6C90CC2B2994500C7CE11512222E0A5EAB615480964EA5E4F74F7053EC78A520CDB15B4BD6D9BE5C6B15468A9E36990B69AA50FB8B93F207DAE4AB5B89CE41DB6ABE694A5C1C783ADDBF527870E046CD5FFDDA05DED8752B72B1502AE39A66A74E9DAC4E7BC4D341EA95C4D335F92092F88665D7797C71D7613A9D5E5F116091135D5ACDB2471702C98560BD917B4D1E3512B5E75E8D5D0DC4F34EDC2056680A1CBE633
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE010808E41EC41930D44095F8FE596B582C8CA2
Blob
0F000000010000002000000024ED0E35CBBC5D8A92186E5EC3EFD91C13BA632777BF013E20751B70F97886DF030000000100000014000000DE010808E41EC41930D44095F8FE596B582C8CA21D0000000100000010000000287316119E6B0619207E6964ECF4BBB514000000010000001400000061B5E042DEB6AFA720EAF624C8A79D85A05853D86200000001000000200000003945E08A8D4A0554B7605A7B355B10188E3EF842C76A805C54E3657C4D041AAA0900000001000000220000003020060A2B0601040182370A030C06082B0601050507030206082B060105050703040B000000010000003000000048006F006E0067006B006F006E006700200050006F0073007400200052006F006F0074002000430041002000320000002000000001000000D3050000308205CF308203B7A003020102021468A5FDA6D01C5E3FCFE4F999DF7A6C6F39A97FFC300D06092A864886F70D01010B0500306F310B300906035504061302484B3112301006035504081309486F6E67204B6F6E673112301006035504071309486F6E67204B6F6E6731163014060355040A130D486F6E676B6F6E6720506F73743120301E06035504031317486F6E676B6F6E6720506F737420526F6F742043412032301E170D3135303930353032333433365A170D3430303930353032333433365A306F310B300906035504061302484B3112301006035504081309486F6E67204B6F6E673112301006035504071309486F6E67204B6F6E6731163014060355040A130D486F6E676B6F6E6720506F73743120301E06035504031317486F6E676B6F6E6720506F737420526F6F74204341203230820222300D06092A864886F70D01010105000382020F003082020A0282020100E272ECF0471022C344CA05795B59D83A2B242124EAAF88F87D5A0565C318480104C17E5A0335794AC3C1625BD25E82F70CFBB9FED2211D5C87BC26E3C4A67B99539704D8DF124A3E6545E7CE1B65A9703996166281CCE9E01B82BBEDA8E0426BE9BAC91B4B48FD9D461240E528D34C47FA628867840D574C0F71A9857F56E516E8A342BA47B6DDE8E36AF70A69E5F314E35C55DD87FF7E3C5C4DF9C91B0E9B4EEE7EACEC4DD3A223B7889B79A08A63471E7457BDC7AEFD94AE1D4A45C3C7F6A55307D569F873E56637B6A53077AACCBAF009C5285783F0A219F27E45B46CEB4922BA8E3A231C1D89B28F69441328BA625511828E597E7C4DBA87B7EE33DECDD9C2F1942D533BA4D016540F11210A7E58C3AE82C1C4D525770F76DB0D5EF76233B5A7FCCA1EF3868A5388DDC2321F3E76DE9F8F0C8A4A502DC85051060541579BA476D01CC66E164826CF32475916934B4AD49FBA7EED1FF3057743C72D62F160D58C28F1FE162382CF5A6B9F6E69FCD4A84957F73E920944C25D28BD2A5433889A9E974D2CAFBD0B7D4A3B5344BDC2C12DD534CF02A01409514A8AC2AA00116E9AD11DD73CD9F1C17ED8195012C4912B61056DFB328F87AC7AC095B68D07F528EEBD688BEFFE4D0643CD1725A0FEE25426B4E5F890FB0DD8A20C3173944D7BFB5214AB65510A03DAF2660392DF7C45971B4E3D7B1051A7E9838DB93FB492D11F0203010001A3633061300F0603551D130101FF040530030101FF300E0603551D0F0101FF0404030201C6301F0603551D2304183016801461B5E042DEB6AFA720EAF624C8A79D85A05853D8301D0603551D0E0416041461B5E042DEB6AFA720EAF624C8A79D85A05853D8300D06092A864886F70D01010B050003820201007AA78BDCED66F6DDC910DF50F1D190323D8FDA91B2C753AE71F9A7ECC468E20EFA8E1A5F2A92E383D1FCDAF2E57AC8ACA4172DE6B8DDEC2A1751A275692839BA583F1F50B3EDC319B716F5C6A85A3DA0D0773F510745AC6F9F94CBBF6C2E0F890992341939ED7AB25965B076ED27461D43CFD436BC688A9BD4DBC22B3FCE5D5499CA22C1798498FFBA4158BF454999BB091B968E584CFAC84842941B89C9F95266CB9D6DC40DE9BC5F37D5BA0861FFD54B8C63E8FEF7E0DC1913E9526AB6812C18646CDED83057FF8B19C7BFB7725E56AEC3F619D2FDAEE9B6A531B8324EC9BC3A1B291F8961B0FBC7FB880629C356A64D6210F0AB51B764F4245390833AA7AEA91102E0825423BD04BE34B4CED9AA3E549A48028B211812F898E0AAAAF9ABAE2BBFB56B839F22D058580516A7DDC793E97B8428E2D5EEA835F9CCCEB6F0275051338732D4647288D83540B7AD9BEE5A14A97E80983D5DD17774CAF89186D742E9DCA0EF30259FC83A60680F2D51F8F196B045F480A8B4918729432991398335626DB8E9FCF8FE9A4E28647E0D906903F2AB4D3E4ED18E2703449760DA788A658D1675FC0E2C729B788A6762B1AE2C460590113857D7762923A8C07D09DF87ABDA5B1F7A133381B2F7FE1CEFC29E655FE419E972AFC8351CBEFBD3F8DDE4D8C3394ED94360AB7536571BCB055AD843FC3725571A3DB556EBF2EFDB2630B1A0EE
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DE010808E41EC41930D44095F8FE596B582C8CA2
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DDFB16CD4931C973A2037D3FC83A4D7D775D05E4
Blob
0F00000001000000300000004EA1B34B10B982A96A38915843507820AD632C6AAD8343E337B34D660CD8366FA154544AE80668AE1FDF3931D57E1996030000000100000014000000DDFB16CD4931C973A2037D3FC83A4D7D775D05E41D0000000100000010000000A86DC6A233EB339610F3ED414927C559140000000100000014000000ECD7E382D2715D644CDF2E673FE7BA98AE1C0F4F620000000100000020000000552F7BDCF1A7AF9E6CE672017F4F12ABF77240C78E761AC203D1D9D20AC899885300000001000000230000003021301F06096086480186FD6C020130123010060A2B0601040182373C0101030200C00B00000001000000320000004400690067006900430065007200740020005400720075007300740065006400200052006F006F0074002000470034000000090000000100000034000000303206082B0601050507030106082B0601050507030206082B0601050507030406082B0601050507030306082B060105050703082000000001000000940500003082059030820378A0030201020210059B1B579E8E2132E23907BDA777755C300D06092A864886F70D01010C05003062310B300906035504061302555331153013060355040A130C446967694365727420496E6331193017060355040B13107777772E64696769636572742E636F6D3121301F060355040313184469676943657274205472757374656420526F6F74204734301E170D3133303830313132303030305A170D3338303131353132303030305A3062310B300906035504061302555331153013060355040A130C446967694365727420496E6331193017060355040B13107777772E64696769636572742E636F6D3121301F060355040313184469676943657274205472757374656420526F6F7420473430820222300D06092A864886F70D01010105000382020F003082020A0282020100BFE6907368DEBBE45D4A3C3022306933ECC2A7252EC9213DF28AD859C2E129A73D58AB769ACDAE7B1B840DC4301FF31BA43816EB56C6976D1DABB279F2CA11D2E45FD6053C520F521FC69E15A57EBE9FA95716595572AF689370C2B2BA75996A733294D11044102EDF82F30784E6743B6D71E22D0C1BEE20D5C9201D63292DCEEC5E4EC893F821619B34EB05C65EEC5B1ABCEBC9CFCDAC34405FB17A66EE77C848A86657579F54588E0C2BB74FA730D956EECA7B5DE3ADC94F5EE535E731CBDA935EDC8E8F80DAB69198409079C378C7B6B1C4B56A183803108DD8D437A42E057D88F5823E109170AB55824132D7DB04732A6E91017C214CD4BCAE1B03755D7866D93A31449A3340BF08D75A49A4C2E6A9A067DDA427BCA14F39B5115817F7245C468F64F7C169887698763D595D4276878997697A48F0E0A2121B669A74CADE4B1EE70E63AEE6D4EF92923A9E3DDC00E4452589B69A44192B7EC094B4D2616DEB33D9C5DF4B0400CC7D1C95C38FF721B2B211B7BB7FF2D58C702C4160AAB1631844951A76627EF680B0FBE864A633D18907E1BDB7E643A418B8A67701E10F940C211DB2542925896CE50E52514774BE26ACB64175DE7AAC5F8D3FC9BCD34111125BE51050EB31C5CA72162209DF7C4C753F63EC215FC420516B6FB1AB868B4FC2D6455F9D20FCA11EC5C08FA2B17E0A2699F5E4692F981D2DF5D9A9B21DE51B0203010001A3423040300F0603551D130101FF040530030101FF300E0603551D0F0101FF040403020186301D0603551D0E04160414ECD7E382D2715D644CDF2E673FE7BA98AE1C0F4F300D06092A864886F70D01010C05000382020100BB61D97DA96CBE17C4911BC3A1A2008DE364680F56CF77AE70F9FD9A4A99B9C9785C0C0C5FE4E61429560B36495D4463E0AD9C9618661B230D3D79E96D6BD654F8D23CC14340AE1D50F552FC903BBB9899696BC7C1A7A868A427DC9DF927AE3085B9F6674D3A3E8F5939225344EBC85D03CAED507A7D62210A80C87366D1A005605FE8A5B4A7AFA8F76D359C7C5A8AD6A23899F3788BF44DD2200BDE04EE8C9B4781720DC01432EF30592EAEE071F256E46A976F92506D968D687A9AB236147A06F224B9091150D708B1B8897A8423614229E5A3CDA22041D7D19C64D9EA26A18B14D74C19B25041713D3F4D7023860C4ADC81D2CC3294840D0809971C4FC0EE6B207430D2E03934108521150108E85532DE7149D92817504DE6BE4DD175ACD0CAFB41B843A5AAD3C305444F2C369BE2FAE245B823536C066F67557F46B54C3F6E285A7926D2A4A86297D21EE2ED4A8BBC1BFD474A0DDF67667EB25B41D03BE4F43BF40463E9EFC2540051A08A2AC9CE78CCD5EA870418B3CEAF4988AFF39299B6B3E6610FD28500E7501AE41B959D19A1B99CB19BB1001EEFD00F4F426CC90ABCEE43FA3A71A5C84D26A535FD895DBC85621D32D2A02B54ED9A57C1DBFA10CF19B78B4A1B8F01B6279553E8B6896D5BBC68D423E88B51A256F9F0A680A0D61EB3BC0F0F537529AAEA1377E4DE8C8121AD07104711AD873D07D175BCCFF3667E
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DDFB16CD4931C973A2037D3FC83A4D7D775D05E4
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DDE1D2A901802E1D875E84B3807E4BB1FD994134
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DDE1D2A901802E1D875E84B3807E4BB1FD994134
Blob
0F0000000100000014000000F55BCC78926D88127610037F48B59B94F3FA6101030000000100000014000000DDE1D2A901802E1D875E84B3807E4BB1FD994134680000000100000008000000008024EED112D2011D0000000100000010000000898D180D578F7C878D7FE510497BAE341400000001000000140000009FEE44B394D5FA914F2ED9559A0456DB2DC4DBA5620000000100000020000000E609078465A419780CB6AC4C1C0BFB4653D9D9CC6EB3946EB7F3D69997BAD59809000000010000003E000000303C06082B0601050507030106082B0601050507030206082B0601050507030306082B0601050507030406082B0601050507030806082B060105050703090B000000010000006000000045002D004700DC00560045004E00200045006C0065006B00740072006F006E0069006B00200053006500720074006900660069006B0061002000480069007A006D00650074002000530061001F016C00610079003101630031017300310100002000000001000000BA030000308203B63082029EA003020102021044998D3CC00327BD9C7695B9EADBACB5300D06092A864886F70D01010505003075310B300906035504061302545231283026060355040A131F456C656B74726F6E696B2042696C676920477576656E6C69676920412E532E313C303A06035504031333652D477576656E204B6F6B20456C656B74726F6E696B20536572746966696B612048697A6D6574205361676C61796963697369301E170D3037303130343131333234385A170D3137303130343131333234385A3075310B300906035504061302545231283026060355040A131F456C656B74726F6E696B2042696C676920477576656E6C69676920412E532E313C303A06035504031333652D477576656E204B6F6B20456C656B74726F6E696B20536572746966696B612048697A6D6574205361676C6179696369736930820122300D06092A864886F70D01010105000382010F003082010A0282010100C312209EB05E00658D4E46BB805CE92C0697D5F372C970B9E74B6580C14BBE7E3CD7543194DED512BA531602EA5863EF5BD8F3ED2A1AAA7148A3DC102D5F5FEB5C4B9C960842252811CC8A5A620150D5EB09532FF8C38FFEB3FCFD9DA2E35F7DBEED0BE060EB69EC33EDD88DFB12498300C98B978C3B732A32B312F7B94DF2F44D6DC7E6D6263708F2D9FD6B5CA3E5485C58BC42BE035A81BA1C350C00D3F5237E7130082638DC2511472DF3BA2310A5BFBC02F7435EC7FEB03750997B0F93CEE6432CC37E0DF21C436660CB61314787A34FAEBD566C4CBCBCF805CA64F4E934A12CB573E1C23EE8C8C93425085CF3EDA6C7949FAD884325D7E13960FEAC39590203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E041604149FEE44B394D5FA914F2ED9559A0456DB2DC4DBA5300D06092A864886F70D010105050003820101007F5FB9535B633D7532E7FAC4741ACB46DF46691C52CFAA4FC268EBFF80A951E83D6277893D0A7539F16E5D17876F6805C1946CD95DDFDAB259CBA5108ACACC39CD9FEB4EDE52FF0CF0F492A9F26C53AB9BD247A01F74F79B9AF12F159F7A643018073C2A0F67CAFC0F89619D65A53CE5BC135B08DBE3FFEDBB06BB6A06B17A4F65C682FD1E9C8BB50DEE48BBB8BDAA08B4FBA37CCB9FCD90765C869678570A66F9581A9DFD972960DE11A6901C191CEE01962234342E91F9B7C427D17BE6BFFB80445A16E5EBE0D40A38BCE491E3D5EB5CC1ACDF1B6A7C9EE575D2B69787DBCC872B433A8408AFAB3CDBF73C663186B09D5379EDF823DE42E32D82F10FE5FA97
2828
iexplore.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DD83C519D43481FAD4C22C03D702FE9F3B22F517
2828
iexplore.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\DBAC3C7AA4254DA1AA5CAAD68468CB88EEDDEEA8
Blob
0F00000001000000100000008590D169D67D104CDF4BF263BEFFA2A3030000000100000014000000DBAC3C7AA4254DA1AA5CAAD68468CB88EEDDEEA8090000000100000020000000301E06082B0601050507030406082B0601050507030206082B060105050703010B000000010000002800000047005400450020004300790062006500720054007200750073007400200052006F006F00740000002000000001000000500200003082024C308201B5020200FD300D06092A864886F70D0101040500306E310B300906035504061302555331183016060355040A130F47544520436F72706F726174696F6E31273025060355040B131E475445204379626572547275737420536F6C7574696F6E732C20496E632E311C301A06035504031313475445204379626572547275737420526F6F74301E170D3938303430333134353230315A170D3034303430333233353930305A306E310B300906035504061302555331183016060355040A130F47544520436F72706F726174696F6E31273025060355040B131E475445204379626572547275737420536F6C7574696F6E732C20496E632E311C301A06035504031313475445204379626572547275737420526F6F7430819F300D06092A864886F70D010101050003818D0030818902818100BA8EBD759012FAE57974B2D9F726D40E411DE936075672D5B869DA54D4B1D6786DAAE33B3DA3843725C7AFAF04DCB322B1E96DBE826DEB8D2FBDB4AE701EA2D66E203151E6565C7352B223504EBCFB9A6740C4861146C74322BAEA004F6C72CD619CDECBFAEE30D2E6FA5B9DC599DC20F839BF648C07563BBDDC6C5EF6BFE1D90203010001300D06092A864886F70D010104050003818100965F1D3CC67595B66BAF8700CDA5412B8BBFD08D315B3965D3F1D18F581E5222C33D86F2C29AF6DD485E71C3451C7C4CA259EEA151963DF7D534243AAAFD822665C54C420F0C8F69607CE7D6D51A4B79FAEE5AB54CA6CCA36B46D6D1C83254A03067D25D861191BCC3BA2A9CD578511AD45DDD76912245