Unpacked Pony | Grouped Behavior
Try VMRay Analyzer
VTI SCORE: 100/100
Dynamic Analysis Report
Classification: Trojan, Spyware

c71c3662a7ebba5fdd0d804fe9ff864789fa08e8286352c21b339b9db2c3db81 (SHA256)

p.exe

Windows Exe (x86-32)

Created at 2018-09-11 15:34:00

Monitored Processes

Process Overview
»
ID PID Monitor Reason Integrity Level Image Name Command Line Origin ID
#1 0xad4 Analysis Target High (Elevated) p.exe "C:\Users\Nd9E1FYi\Desktop\p.exe" -

Behavior Information - Grouped by Category

Process #1: p.exe
2390 0
»
Information Value
ID #1
File Name c:\users\nd9e1fyi\desktop\p.exe
Command Line "C:\Users\Nd9E1FYi\Desktop\p.exe"
Initial Working Directory C:\Users\Nd9E1FYi\Desktop\
Monitor Start Time: 00:00:20, Reason: Analysis Target
Unmonitor End Time: 00:00:43, Reason: Self Terminated
Monitor Duration 00:00:23
OS Process Information
»
Information Value
PID 0xad4
Parent PID 0x7d4 (c:\windows\explorer.exe)
Is Created or Modified Executable True
Integrity Level High (Elevated)
Username X2VS1CUM\Nd9E1FYi
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x C58
0x 844
0x CA8
0x DFC
0x DF0
0x A64
0x F98
0x FE0
0x C14
0x E98
Region
»
Name Start VA End VA Type Permissions Monitored Dumped YARA Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory rw True False False -
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory rw True False False -
private_0x0000000000020000 0x00020000 0x00023fff Private Memory rw True False False -
private_0x0000000000030000 0x00030000 0x00030fff Private Memory rw True False False -
pagefile_0x0000000000040000 0x00040000 0x00054fff Pagefile Backed Memory r True False False -
private_0x0000000000060000 0x00060000 0x0009ffff Private Memory rw True False False -
private_0x00000000000a0000 0x000a0000 0x0019ffff Private Memory rw True False False -
pagefile_0x00000000001a0000 0x001a0000 0x001a3fff Pagefile Backed Memory r True False False -
private_0x00000000001b0000 0x001b0000 0x001b1fff Private Memory rw True False False -
private_0x00000000001c0000 0x001c0000 0x001fffff Private Memory rw True False False -
private_0x0000000000200000 0x00200000 0x003fffff Private Memory rw True False False -
p.exe 0x00400000 0x00415fff Memory Mapped File rwx True True True
private_0x0000000000420000 0x00420000 0x0045ffff Private Memory rw True False False -
private_0x0000000000460000 0x00460000 0x00460fff Private Memory rw True False False -
pagefile_0x0000000000470000 0x00470000 0x00471fff Pagefile Backed Memory r True False False -
pagefile_0x0000000000480000 0x00480000 0x00480fff Pagefile Backed Memory rw True False False -
pagefile_0x0000000000490000 0x00490000 0x00490fff Pagefile Backed Memory r True False False -
pagefile_0x00000000004a0000 0x004a0000 0x004a0fff Pagefile Backed Memory r True False False -
private_0x00000000004b0000 0x004b0000 0x004b3fff Private Memory rw True False False -
private_0x00000000004c0000 0x004c0000 0x004cffff Private Memory rw True False False -
locale.nls 0x004d0000 0x0058dfff Memory Mapped File r False False False -
private_0x0000000000590000 0x00590000 0x0060ffff Private Memory rw True False False -
pagefile_0x0000000000610000 0x00610000 0x00611fff Pagefile Backed Memory r True False False -
private_0x0000000000620000 0x00620000 0x0062ffff Private Memory rw True False False -
windowsshell.manifest 0x00630000 0x00630fff Memory Mapped File r False False False -
counters.dat 0x00630000 0x00630fff Memory Mapped File rw True False False -
private_0x0000000000640000 0x00640000 0x0073ffff Private Memory rw True False False -
private_0x0000000000740000 0x00740000 0x0083ffff Private Memory rw True False False -
private_0x0000000000840000 0x00840000 0x0093ffff Private Memory rw True False False -
pagefile_0x0000000000940000 0x00940000 0x00ac7fff Pagefile Backed Memory r True False False -
pagefile_0x0000000000ad0000 0x00ad0000 0x00c50fff Pagefile Backed Memory r True False False -
pagefile_0x0000000000c60000 0x00c60000 0x0205ffff Pagefile Backed Memory r True False False -
private_0x0000000002060000 0x02060000 0x020fffff Private Memory rw True False False -
pagefile_0x0000000002060000 0x02060000 0x02061fff Pagefile Backed Memory r True False False -
private_0x0000000002070000 0x02070000 0x020affff Private Memory rw True False False -
private_0x00000000020b0000 0x020b0000 0x020effff Private Memory rw True False False -
private_0x00000000020f0000 0x020f0000 0x020fffff Private Memory rw True False False -
sortdefault.nls 0x02100000 0x02436fff Memory Mapped File r False False False -
private_0x0000000002440000 0x02440000 0x02540fff Private Memory rw True False False -
private_0x0000000002440000 0x02440000 0x0253ffff Private Memory rw True False False -
private_0x0000000002540000 0x02540000 0x0263ffff Private Memory rw True False False -
private_0x0000000002640000 0x02640000 0x0267ffff Private Memory rw True False False -
private_0x0000000002680000 0x02680000 0x0277ffff Private Memory rw True False False -
private_0x0000000002780000 0x02780000 0x027bffff Private Memory rw True False False -
private_0x00000000027c0000 0x027c0000 0x028bffff Private Memory rw True False False -
private_0x00000000028c0000 0x028c0000 0x028fffff Private Memory rw True False False -
private_0x0000000002900000 0x02900000 0x029fffff Private Memory rw True False False -
private_0x0000000002a00000 0x02a00000 0x02a3ffff Private Memory rw True False False -
private_0x0000000002a40000 0x02a40000 0x02b3ffff Private Memory rw True False False -
pagefile_0x0000000002b40000 0x02b40000 0x02b4ffff Pagefile Backed Memory r True False False -
private_0x0000000002b50000 0x02b50000 0x02b8ffff Private Memory rw True False False -
private_0x0000000002b90000 0x02b90000 0x02c8ffff Private Memory rw True False False -
wow64cpu.dll 0x6e310000 0x6e317fff Memory Mapped File rwx False False False -
wow64.dll 0x6e320000 0x6e36ffff Memory Mapped File rwx False False False -
wow64win.dll 0x6e370000 0x6e3e9fff Memory Mapped File rwx False False False -
samlib.dll 0x6f2d0000 0x6f2e2fff Memory Mapped File rwx False False False -
mlang.dll 0x6f2f0000 0x6f322fff Memory Mapped File rwx False False False -
secur32.dll 0x6f330000 0x6f339fff Memory Mapped File rwx False False False -
comctl32.dll 0x6f340000 0x6f54efff Memory Mapped File rwx False False False -
ieframe.dll 0x6f550000 0x700e8fff Memory Mapped File rwx False False False -
pstorec.dll 0x700f0000 0x700f7fff Memory Mapped File rwx False False False -
msi.dll 0x70100000 0x70488fff Memory Mapped File rwx False False False -
samcli.dll 0x70490000 0x704a4fff Memory Mapped File rwx False False False -
netutils.dll 0x704b0000 0x704b9fff Memory Mapped File rwx False False False -
wsock32.dll 0x704c0000 0x704c7fff Memory Mapped File rwx False False False -
userenv.dll 0x70b60000 0x70b78fff Memory Mapped File rwx False False False -
uxtheme.dll 0x70bf0000 0x70c64fff Memory Mapped File rwx False False False -
wininet.dll 0x70d50000 0x70f5cfff Memory Mapped File rwx False False False -
iertutil.dll 0x726a0000 0x7296afff Memory Mapped File rwx False False False -
propsys.dll 0x72ad0000 0x72c1afff Memory Mapped File rwx False False False -
bcrypt.dll 0x747e0000 0x747fafff Memory Mapped File rwx False False False -
apphelp.dll 0x74a90000 0x74b21fff Memory Mapped File rwx False False False -
cryptbase.dll 0x74b30000 0x74b39fff Memory Mapped File rwx False False False -
sspicli.dll 0x74b40000 0x74b5dfff Memory Mapped File rwx False False False -
windows.storage.dll 0x74b60000 0x75058fff Memory Mapped File rwx False False False -
advapi32.dll 0x75070000 0x750eafff Memory Mapped File rwx False False False -
oleaut32.dll 0x75210000 0x752a1fff Memory Mapped File rwx False False False -
kernelbase.dll 0x75310000 0x7548dfff Memory Mapped File rwx False False False -
kernel.appcore.dll 0x754f0000 0x754fbfff Memory Mapped File rwx False False False -
imm32.dll 0x75500000 0x7552afff Memory Mapped File rwx False False False -
shlwapi.dll 0x75540000 0x75584fff Memory Mapped File rwx False False False -
netapi32.dll 0x756b0000 0x756c2fff Memory Mapped File rwx False False False -
msasn1.dll 0x756d0000 0x756ddfff Memory Mapped File rwx False False False -
shell32.dll 0x756f0000 0x76aeefff Memory Mapped File rwx False False False -
sechost.dll 0x76c60000 0x76ca3fff Memory Mapped File rwx False False False -
ole32.dll 0x76d10000 0x76dfafff Memory Mapped File rwx False False False -
crypt32.dll 0x76e00000 0x76f77fff Memory Mapped File rwx False False False -
rpcrt4.dll 0x76f80000 0x7702cfff Memory Mapped File rwx False False False -
profapi.dll 0x77030000 0x7703efff Memory Mapped File rwx False False False -
gdi32.dll 0x77040000 0x7718efff Memory Mapped File rwx False False False -
combase.dll 0x77230000 0x773ecfff Memory Mapped File rwx False False False -
cfgmgr32.dll 0x773f0000 0x77426fff Memory Mapped File rwx False False False -
clbcatq.dll 0x77840000 0x778c3fff Memory Mapped File rwx False False False -
ws2_32.dll 0x77930000 0x7798efff Memory Mapped File rwx False False False -
shcore.dll 0x779e0000 0x77a6cfff Memory Mapped File rwx False False False -
bcryptprimitives.dll 0x77a70000 0x77ac7fff Memory Mapped File rwx False False False -
kernel32.dll 0x77ad0000 0x77baffff Memory Mapped File rwx False False False -
user32.dll 0x77bb0000 0x77cf6fff Memory Mapped File rwx False False False -
powrprof.dll 0x77d00000 0x77d43fff Memory Mapped File rwx False False False -
msvcrt.dll 0x77d50000 0x77e0dfff Memory Mapped File rwx False False False -
ntdll.dll 0x77e10000 0x77f8afff Memory Mapped File rwx False False False -
pagefile_0x000000007feb0000 0x7feb0000 0x7ffaffff Pagefile Backed Memory r True False False -
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory r True False False -
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory r True False False -
private_0x000000007fff0000 0x7fff0000 0x7ff91873ffff Private Memory r True False False -
ntdll.dll 0x7ff918740000 0x7ff918900fff Memory Mapped File rwx False False False -
private_0x00007ff918901000 0x7ff918901000 0x7ffffffeffff Private Memory r True False False -
Host Behavior
COM (1)
»
Operation Class Interface Additional Information Success Count Logfile
Create 3C374A40-BAE4-11CF-BF7D-00AA006946EE 3C374A41-BAE4-11CF-BF7D-00AA006946EE cls_context = CLSCTX_INPROC_SERVER, CLSCTX_LOCAL_SERVER True 1
Fn
File (106)
»
Operation Filename Additional Information Success Count Logfile
Create C:\Users\Nd9E1FYi\AppData\Local\Temp\HWID desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Create C:\Windows\wcx_ftp.ini desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\wcx_ftp.ini desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Roaming\GHISLER\wcx_ftp.ini desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\ProgramData\GHISLER\wcx_ftp.ini desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Local\GHISLER\wcx_ftp.ini desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Roaming\GlobalSCAPE\CuteFTP\sm.dat desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Roaming\GlobalSCAPE\CuteFTP Pro\sm.dat desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Roaming\GlobalSCAPE\CuteFTP Lite\sm.dat desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Roaming\CuteFTP\sm.dat desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\ProgramData\GlobalSCAPE\CuteFTP\sm.dat desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\ProgramData\GlobalSCAPE\CuteFTP Pro\sm.dat desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\ProgramData\GlobalSCAPE\CuteFTP Lite\sm.dat desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\ProgramData\CuteFTP\sm.dat desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Local\GlobalSCAPE\CuteFTP\sm.dat desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Local\GlobalSCAPE\CuteFTP Pro\sm.dat desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Local\GlobalSCAPE\CuteFTP Lite\sm.dat desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Local\CuteFTP\sm.dat desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Program Files (x86)\GlobalSCAPE\CuteFTP\sm.dat desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Program Files (x86)\GlobalSCAPE\CuteFTP Pro\sm.dat desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Program Files (x86)\GlobalSCAPE\CuteFTP Lite\sm.dat desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Program Files (x86)\CuteFTP\sm.dat desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Roaming\FlashFXP\3\Sites.dat desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Roaming\FlashFXP\4\Sites.dat desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Roaming\FlashFXP\3\Quick.dat desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Roaming\FlashFXP\4\Quick.dat desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Roaming\FlashFXP\3\History.dat desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Roaming\FlashFXP\4\History.dat desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\ProgramData\FlashFXP\3\Sites.dat desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\ProgramData\FlashFXP\4\Sites.dat desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\ProgramData\FlashFXP\3\Quick.dat desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\ProgramData\FlashFXP\4\Quick.dat desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\ProgramData\FlashFXP\3\History.dat desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\ProgramData\FlashFXP\4\History.dat desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Local\FlashFXP\3\Sites.dat desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Local\FlashFXP\4\Sites.dat desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Local\FlashFXP\3\Quick.dat desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Local\FlashFXP\4\Quick.dat desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Local\FlashFXP\3\History.dat desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Local\FlashFXP\4\History.dat desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Roaming\FileZilla\sitemanager.xml desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Roaming\FileZilla\recentservers.xml desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Roaming\FileZilla\filezilla.xml desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\ProgramData\FileZilla\sitemanager.xml desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\ProgramData\FileZilla\recentservers.xml desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\ProgramData\FileZilla\filezilla.xml desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Local\FileZilla\sitemanager.xml desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Local\FileZilla\recentservers.xml desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Local\FileZilla\filezilla.xml desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Roaming\ExpanDrive\drives.js desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Local\ExpanDrive\drives.js desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\ProgramData\ExpanDrive\drives.js desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Roaming\SharedSettings.ccs desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Roaming\SharedSettings.sqlite desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Roaming\SharedSettings_1_0_5.ccs desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Roaming\SharedSettings_1_0_5.sqlite desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\ProgramData\SharedSettings.ccs desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\ProgramData\SharedSettings.sqlite desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\ProgramData\SharedSettings_1_0_5.ccs desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\ProgramData\SharedSettings_1_0_5.sqlite desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Local\SharedSettings.ccs desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Local\SharedSettings.sqlite desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Local\SharedSettings_1_0_5.ccs desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Local\SharedSettings_1_0_5.sqlite desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Roaming\CoffeeCup Software\SharedSettings.ccs desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Roaming\CoffeeCup Software\SharedSettings.sqlite desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Roaming\CoffeeCup Software\SharedSettings_1_0_5.ccs desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Roaming\CoffeeCup Software\SharedSettings_1_0_5.sqlite desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\ProgramData\CoffeeCup Software\SharedSettings.ccs desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\ProgramData\CoffeeCup Software\SharedSettings.sqlite desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\ProgramData\CoffeeCup Software\SharedSettings_1_0_5.ccs desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\ProgramData\CoffeeCup Software\SharedSettings_1_0_5.sqlite desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Local\CoffeeCup Software\SharedSettings.ccs desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Local\CoffeeCup Software\SharedSettings.sqlite desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Local\CoffeeCup Software\SharedSettings_1_0_5.ccs desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Local\CoffeeCup Software\SharedSettings_1_0_5.sqlite desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Windows\32BitFtp.ini desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Local\Google\Chrome\User Data\Default\Web Data desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Local\Google\Chrome\User Data\Default\Login Data desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Create C:\Users\Nd9E1FYi\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
Read C:\Users\Nd9E1FYi\AppData\Local\Google\Chrome\User Data\Default\Web Data size = 4096, size_out = 4096 True 16
Fn
Data
Read C:\Users\Nd9E1FYi\AppData\Local\Google\Chrome\User Data\Default\Web Data size = 4096, size_out = 0 True 1
Fn
Read C:\Users\Nd9E1FYi\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal size = 4096, size_out = 0 True 1
Fn
Read C:\Users\Nd9E1FYi\AppData\Local\Google\Chrome\User Data\Default\Login Data size = 4096, size_out = 4096 True 4
Fn
Data
Read C:\Users\Nd9E1FYi\AppData\Local\Google\Chrome\User Data\Default\Login Data size = 4096, size_out = 2048 True 1
Fn
Data
Read C:\Users\Nd9E1FYi\AppData\Local\Google\Chrome\User Data\Default\Login Data size = 4096, size_out = 0 True 1
Fn
Read C:\Users\Nd9E1FYi\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal size = 4096, size_out = 0 True 1
Fn
Registry (949)
»
Operation Key Additional Information Success Count Logfile
Create Key HKEY_CURRENT_USER\Software\WinRAR - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AddressBook - True 3
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Connection Manager - True 3
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DirectDrawEx - True 3
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DXM_Runtime - True 3
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Fontcore - True 3
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome - True 2
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE40 - True 3
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE4Data - True 3
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE5BAKEX - True 3
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IEData - True 3
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MobileOptionPack - True 3
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MPlayer2 - True 3
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SchedulingAgent - True 3
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WIC - True 3
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E} - True 2
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2151757 - True 2
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2151757 - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2467173 - True 2
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2467173 - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2524860 - True 2
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2524860 - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2544655 - True 2
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2544655 - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2549743 - True 2
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2549743 - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2565063 - True 2
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2565063 - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB982573 - True 2
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB982573 - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f} - True 2
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3c3aafc8-d898-43ec-998f-965ffdae065a} - True 2
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3D82C954-2957-418B-908F-FE78BF3A8BEB} - True 2
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4A03706F-666A-4037-7777-5F2748764D10} - True 2
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4A03706F-666A-4037-7777-5F2748764D10} - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{582EA838-9199-3518-A05C-DB09462F68EC} - True 2
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{68306422-7C57-373F-8860-D26CE4BA2A15} - True 2
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2} - True 2
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9BE518E6-ECC6-35A9-88E4-87755C07200F} - True 2
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-0804-1033-1959-001824214663} - True 2
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-0804-1033-1959-001824214663} - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-0804-1033-1959-001824237067} - True 2
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1033-7B44-AC0F074E4100} - True 2
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B175520C-86A2-35A7-8619-86DC379688B9} - True 2
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB} - True 2
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6} - True 2
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{e52a6842-b0ac-476e-b48f-378a97a67346} - True 2
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{e6e75766-da0f-4ba2-9788-6ea593ce702d} - True 2
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5} - True 2
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2151757 - True 2
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2151757 - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2467173 - True 2
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2467173 - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2524860 - True 2
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2524860 - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2544655 - True 2
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2544655 - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2549743 - True 2
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2549743 - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2565063 - True 2
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2565063 - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB982573 - True 2
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB982573 - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{f325f05b-f963-4640-a43b-c8a494cdda0f} - True 2
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185} - True 2
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR - False 3
Fn
Open Key HKEY_CURRENT_USER\Software\WinRAR - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\Far\Plugins\FTP\Hosts - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\Far2\Plugins\FTP\Hosts - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\Far Manager\Plugins\FTP\Hosts - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\Far\SavedDialogHistory\FTPHost - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\Far2\SavedDialogHistory\FTPHost - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\Far Manager\SavedDialogHistory\FTPHost - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\Ghisler\Windows Commander - False 21
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Ghisler\Windows Commander - False 21
Fn
Open Key HKEY_CURRENT_USER\Software\Ghisler\Total Commander - False 21
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Ghisler\Total Commander - False 21
Fn
Open Key HKEY_CURRENT_USER\Software\GlobalSCAPE\CuteFTP 6 Home\QCToolbar - False 3
Fn
Open Key HKEY_CURRENT_USER\Software\GlobalSCAPE\CuteFTP 6 Professional\QCToolbar - False 3
Fn
Open Key HKEY_CURRENT_USER\Software\GlobalSCAPE\CuteFTP 7 Home\QCToolbar - False 3
Fn
Open Key HKEY_CURRENT_USER\Software\GlobalSCAPE\CuteFTP 7 Professional\QCToolbar - False 3
Fn
Open Key HKEY_CURRENT_USER\Software\GlobalSCAPE\CuteFTP 8 Home\QCToolbar - False 3
Fn
Open Key HKEY_CURRENT_USER\Software\GlobalSCAPE\CuteFTP 8 Professional\QCToolbar - False 3
Fn
Open Key HKEY_CURRENT_USER\Software\FlashFXP\3 - False 9
Fn
Open Key HKEY_CURRENT_USER\Software\FlashFXP - False 3
Fn
Open Key HKEY_CURRENT_USER\Software\FlashFXP\4 - False 12
Fn
Open Key HKEY_LOCAL_MACHINE\Software\FlashFXP\3 - False 9
Fn
Open Key HKEY_LOCAL_MACHINE\Software\FlashFXP - False 3
Fn
Open Key HKEY_LOCAL_MACHINE\Software\FlashFXP\4 - False 12
Fn
Open Key HKEY_CURRENT_USER\Software\FileZilla - False 58
Fn
Open Key HKEY_CURRENT_USER\Software\FileZilla Client - False 3
Fn
Open Key HKEY_LOCAL_MACHINE\Software\FileZilla - False 3
Fn
Open Key HKEY_LOCAL_MACHINE\Software\FileZilla Client - False 3
Fn
Open Key HKEY_CURRENT_USER\Software\BPFTP\Bullet Proof FTP\Main - False 3
Fn
Open Key HKEY_CURRENT_USER\Software\BulletProof Software\BulletProof FTP Client\Main - False 3
Fn
Open Key HKEY_CURRENT_USER\Software\BPFTP\Bullet Proof FTP\Options - False 3
Fn
Open Key HKEY_CURRENT_USER\Software\BulletProof Software\BulletProof FTP Client\Options - False 3
Fn
Open Key HKEY_CURRENT_USER\Software\BPFTP - False 3
Fn
Open Key HKEY_CURRENT_USER\Software\TurboFTP - False 6
Fn
Open Key HKEY_LOCAL_MACHINE\Software\TurboFTP - False 6
Fn
Open Key HKEY_CURRENT_USER\Software\Sota\FFFTP - False 6
Fn
Open Key HKEY_CURRENT_USER\Software\Sota\FFFTP\Options - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\CoffeeCup Software\Internet\Profiles - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\FTPWare\COREFTP\Sites - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\FTP Explorer\FTP Explorer\Workspace\MFCToolBar-224 - False 3
Fn
Open Key HKEY_CURRENT_USER\Software\FTP Explorer\Profiles - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\VanDyke\SecureFX - False 3
Fn
Open Key HKEY_CURRENT_USER\Software\Cryer\WebSitePublisher - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\ExpanDrive\Sessions - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\ExpanDrive - False 3
Fn
Open Key HKEY_LOCAL_MACHINE\Software\NCH Software\ClassicFTP\FTPAccounts - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\NCH Software\ClassicFTP\FTPAccounts - False 1
Fn
Open Key HKEY_CURRENT_USER\SOFTWARE\NCH Software\Fling\Accounts - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\NCH Software\Fling\Accounts - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\FTPClient\Sites - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\FTPClient\Sites - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\SoftX.org\FTPClient\Sites - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\SoftX.org\FTPClient\Sites - False 1
Fn
Open Key HKEY_CURRENT_USER\SOFTWARE\LeapWare - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\LeapWare - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\Martin Prikryl - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Martin Prikryl - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\South River Technologies\WebDrive\Connections - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\South River Technologies\WebDrive\Connections - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\Opera Software - False 6
Fn
Open Key HKEY_CLASSES_ROOT\Opera.HTML\shell\open\command - False 3
Fn
Open Key HKEY_CURRENT_USER\Software\AceBIT - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\AceBIT - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{CB1F2C0F-8094-4AAC-BCF5-41A64E27F777} - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9EA55529-E122-4757-BC79-E4825F80732C} - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\Mozilla - True 8
Fn
Open Key HKEY_CURRENT_USER\Software\Mozilla\Firefox - True 14
Fn
Open Key HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs - True 14
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Mozilla - False 9
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Mozilla - True 1
Fn
Open Key HKEY_CURRENT_USER\Software\LeechFTP - False 6
Fn
Open Key HKEY_CLASSES_ROOT\CLSID\{11C1D741-A95B-11d2-8A80-0080ADB32FF4}\InProcServer32 - False 3
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IntelliForms\Storage2 - False 102
Fn
Open Key HKEY_CURRENT_USER\Software\Adobe\Common - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\ChromePlus - False 3
Fn
Open Key HKEY_CURRENT_USER\Software\FlashPeak\BlazeFtp\Settings - False 12
Fn
Open Key HKEY_CLASSES_ROOT\FTP++.Link\shell\open\command - False 3
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F9043C88-F6F2-101A-A3C9-08002B2F49FB}\1.2\0\win32 - False 3
Fn
Open Key HKEY_CURRENT_USER\SOFTWARE\Robo-FTP 3.7\FTPServers - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Robo-FTP 3.7\FTPServers - False 1
Fn
Open Key HKEY_CURRENT_USER\SOFTWARE\Robo-FTP 3.7\Scripts - False 3
Fn
Open Key HKEY_LOCAL_MACHINE\SOFTWARE\Robo-FTP 3.7\Scripts - False 3
Fn
Open Key HKEY_CURRENT_USER\Software\LinasFTP\Site Manager - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\SimonTatham\PuTTY\Sessions - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\SimonTatham\PuTTY\Sessions - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\CoffeeCup Software - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\CoffeeCup Software - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\MAS-Soft\FTPInfo\Setup - False 3
Fn
Open Key HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\FTP - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Nico Mak Computing\WinZip\FTP - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\mru\jobs - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Nico Mak Computing\WinZip\mru\jobs - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Windows Live Mail - False 3
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Windows Mail - False 3
Fn
Open Key HKEY_CURRENT_USER\Software\RimArts\B2\Settings - False 6
Fn
Open Key HKEY_LOCAL_MACHINE\Software\RimArts\B2\Settings - False 6
Fn
Open Key HKEY_CURRENT_USER\Software\Poco Systems Inc - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Poco Systems Inc - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\IncrediMail - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\IncrediMail - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\RIT\The Bat! - False 6
Fn
Open Key HKEY_CURRENT_USER\Software\RIT\The Bat!\Users depot - False 6
Fn
Open Key HKEY_LOCAL_MACHINE\Software\RIT\The Bat! - False 6
Fn
Open Key HKEY_LOCAL_MACHINE\Software\RIT\The Bat!\Users depot - False 6
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager\Accounts - False 1
Fn
Open Key HKEY_CURRENT_USER\Identities - False 1
Fn
Open Key HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Account Manager - True 3
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\OMI Account Manager\Accounts - False 2
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Microsoft Outlook Internet Settings - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook - False 1
Fn
Open Key HKEY_CURRENT_USER\Software\Mozilla - True 2
Fn
Open Key HKEY_CURRENT_USER\Software\Mozilla\Firefox - True 2
Fn
Open Key HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs - True 2
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AddressBook value_name = UninstallString, type = REG_NONE False 3
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Connection Manager value_name = UninstallString, type = REG_NONE False 3
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DirectDrawEx value_name = UninstallString, type = REG_NONE False 3
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DXM_Runtime value_name = UninstallString, type = REG_NONE False 3
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Fontcore value_name = UninstallString, type = REG_NONE False 3
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome value_name = UninstallString, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome value_name = UninstallString, data = 34 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome value_name = DisplayName, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome value_name = DisplayName, data = 71 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE40 value_name = UninstallString, type = REG_NONE False 3
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE4Data value_name = UninstallString, type = REG_NONE False 3
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE5BAKEX value_name = UninstallString, type = REG_NONE False 3
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IEData value_name = UninstallString, type = REG_NONE False 3
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MobileOptionPack value_name = UninstallString, type = REG_NONE False 3
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MPlayer2 value_name = UninstallString, type = REG_NONE False 3
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SchedulingAgent value_name = UninstallString, type = REG_NONE False 3
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WIC value_name = UninstallString, type = REG_NONE False 3
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E} value_name = UninstallString, data = 0, type = REG_EXPAND_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E} value_name = UninstallString, data = 77 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E} value_name = DisplayName, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E} value_name = DisplayName, data = 77 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2151757 value_name = UninstallString, type = REG_NONE False 2
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2467173 value_name = UninstallString, type = REG_NONE False 2
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2524860 value_name = UninstallString, type = REG_NONE False 2
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2544655 value_name = UninstallString, type = REG_NONE False 2
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2549743 value_name = UninstallString, type = REG_NONE False 2
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2565063 value_name = UninstallString, type = REG_NONE False 2
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB982573 value_name = UninstallString, type = REG_NONE False 2
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f} value_name = UninstallString, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f} value_name = UninstallString, data = 34 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f} value_name = DisplayName, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f} value_name = DisplayName, data = 77 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3c3aafc8-d898-43ec-998f-965ffdae065a} value_name = UninstallString, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3c3aafc8-d898-43ec-998f-965ffdae065a} value_name = UninstallString, data = 34 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3c3aafc8-d898-43ec-998f-965ffdae065a} value_name = DisplayName, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3c3aafc8-d898-43ec-998f-965ffdae065a} value_name = DisplayName, data = 77 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3D82C954-2957-418B-908F-FE78BF3A8BEB} value_name = UninstallString, data = 0, type = REG_EXPAND_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3D82C954-2957-418B-908F-FE78BF3A8BEB} value_name = UninstallString, data = 77 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3D82C954-2957-418B-908F-FE78BF3A8BEB} value_name = DisplayName, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3D82C954-2957-418B-908F-FE78BF3A8BEB} value_name = DisplayName, data = 65 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4A03706F-666A-4037-7777-5F2748764D10} value_name = UninstallString, type = REG_NONE False 2
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{582EA838-9199-3518-A05C-DB09462F68EC} value_name = UninstallString, data = 0, type = REG_EXPAND_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{582EA838-9199-3518-A05C-DB09462F68EC} value_name = UninstallString, data = 77 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{582EA838-9199-3518-A05C-DB09462F68EC} value_name = DisplayName, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{582EA838-9199-3518-A05C-DB09462F68EC} value_name = DisplayName, data = 77 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{68306422-7C57-373F-8860-D26CE4BA2A15} value_name = UninstallString, data = 0, type = REG_EXPAND_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{68306422-7C57-373F-8860-D26CE4BA2A15} value_name = UninstallString, data = 77 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{68306422-7C57-373F-8860-D26CE4BA2A15} value_name = DisplayName, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{68306422-7C57-373F-8860-D26CE4BA2A15} value_name = DisplayName, data = 77 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2} value_name = UninstallString, data = 0, type = REG_EXPAND_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2} value_name = UninstallString, data = 77 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2} value_name = DisplayName, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2} value_name = DisplayName, data = 77 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9BE518E6-ECC6-35A9-88E4-87755C07200F} value_name = UninstallString, data = 0, type = REG_EXPAND_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9BE518E6-ECC6-35A9-88E4-87755C07200F} value_name = UninstallString, data = 77 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9BE518E6-ECC6-35A9-88E4-87755C07200F} value_name = DisplayName, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9BE518E6-ECC6-35A9-88E4-87755C07200F} value_name = DisplayName, data = 77 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-0804-1033-1959-001824214663} value_name = UninstallString, type = REG_NONE False 2
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-0804-1033-1959-001824237067} value_name = UninstallString, data = 0, type = REG_EXPAND_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-0804-1033-1959-001824237067} value_name = UninstallString, data = 77 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-0804-1033-1959-001824237067} value_name = DisplayName, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-0804-1033-1959-001824237067} value_name = DisplayName, data = 65 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1033-7B44-AC0F074E4100} value_name = UninstallString, data = 0, type = REG_EXPAND_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1033-7B44-AC0F074E4100} value_name = UninstallString, data = 77 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1033-7B44-AC0F074E4100} value_name = DisplayName, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1033-7B44-AC0F074E4100} value_name = DisplayName, data = 65 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B175520C-86A2-35A7-8619-86DC379688B9} value_name = UninstallString, data = 0, type = REG_EXPAND_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B175520C-86A2-35A7-8619-86DC379688B9} value_name = UninstallString, data = 77 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B175520C-86A2-35A7-8619-86DC379688B9} value_name = DisplayName, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B175520C-86A2-35A7-8619-86DC379688B9} value_name = DisplayName, data = 77 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB} value_name = UninstallString, data = 0, type = REG_EXPAND_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB} value_name = UninstallString, data = 77 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB} value_name = DisplayName, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB} value_name = DisplayName, data = 77 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6} value_name = UninstallString, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6} value_name = UninstallString, data = 34 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6} value_name = DisplayName, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6} value_name = DisplayName, data = 77 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{e52a6842-b0ac-476e-b48f-378a97a67346} value_name = UninstallString, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{e52a6842-b0ac-476e-b48f-378a97a67346} value_name = UninstallString, data = 34 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{e52a6842-b0ac-476e-b48f-378a97a67346} value_name = DisplayName, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{e52a6842-b0ac-476e-b48f-378a97a67346} value_name = DisplayName, data = 77 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{e6e75766-da0f-4ba2-9788-6ea593ce702d} value_name = UninstallString, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{e6e75766-da0f-4ba2-9788-6ea593ce702d} value_name = UninstallString, data = 34 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{e6e75766-da0f-4ba2-9788-6ea593ce702d} value_name = DisplayName, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{e6e75766-da0f-4ba2-9788-6ea593ce702d} value_name = DisplayName, data = 77 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5} value_name = UninstallString, data = 0, type = REG_EXPAND_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5} value_name = UninstallString, data = 77 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5} value_name = DisplayName, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5} value_name = DisplayName, data = 77 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2151757 value_name = UninstallString, type = REG_NONE False 2
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2467173 value_name = UninstallString, type = REG_NONE False 2
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2524860 value_name = UninstallString, type = REG_NONE False 2
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2544655 value_name = UninstallString, type = REG_NONE False 2
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2549743 value_name = UninstallString, type = REG_NONE False 2
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2565063 value_name = UninstallString, type = REG_NONE False 2
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB982573 value_name = UninstallString, type = REG_NONE False 2
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{f325f05b-f963-4640-a43b-c8a494cdda0f} value_name = UninstallString, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{f325f05b-f963-4640-a43b-c8a494cdda0f} value_name = UninstallString, data = 34 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{f325f05b-f963-4640-a43b-c8a494cdda0f} value_name = DisplayName, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{f325f05b-f963-4640-a43b-c8a494cdda0f} value_name = DisplayName, data = 77 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185} value_name = UninstallString, data = 0, type = REG_EXPAND_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185} value_name = UninstallString, data = 77 True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185} value_name = DisplayName, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185} value_name = DisplayName, data = 77 True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR value_name = HWID, type = REG_BINARY True 1
Fn
Read Value HKEY_CURRENT_USER\Software\WinRAR value_name = HWID, data = 123 True 1
Fn
Read Value HKEY_CURRENT_USER\Software\Mozilla\Firefox value_name = PathToExe, type = REG_NONE False 9
Fn
Read Value HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs value_name = PathToExe, type = REG_NONE False 9
Fn
Read Value HKEY_CURRENT_USER\Software\Mozilla value_name = PathToExe, type = REG_NONE False 3
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Mozilla value_name = PathToExe, type = REG_NONE False 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Account Manager value_name = Outlook, type = REG_NONE False 2
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Account Manager value_name = Outlook, data = 0, type = REG_SZ True 1
Fn
Read Value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Account Manager value_name = Outlook, data = 83 True 1
Fn
Write Value HKEY_CURRENT_USER\Software\WinRAR value_name = HWID, size = 38, type = REG_BINARY True 1
Fn
Data
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - True 1
Fn
Enumerate Keys HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall - False 1
Fn
Enumerate Keys HKEY_CURRENT_USER\Software\Mozilla - True 5
Fn
Enumerate Keys HKEY_CURRENT_USER\Software\Mozilla\Firefox - True 5
Fn
Enumerate Keys HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs - False 5
Fn
Enumerate Keys HKEY_CURRENT_USER\Software\Mozilla\Firefox - False 5
Fn
Enumerate Keys HKEY_CURRENT_USER\Software\Mozilla - False 5
Fn
Enumerate Keys HKEY_CURRENT_USER\Software\Mozilla - True 2
Fn
Enumerate Keys HKEY_CURRENT_USER\Software\Mozilla\Firefox - True 2
Fn
Enumerate Keys HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs - False 2
Fn
Enumerate Keys HKEY_CURRENT_USER\Software\Mozilla\Firefox - False 2
Fn
Enumerate Keys HKEY_CURRENT_USER\Software\Mozilla - False 2
Fn
Module (43)
»
Operation Module Additional Information Success Count Logfile
Load ole32.dll base_address = 0x76d10000 True 1
Fn
Load crypt32.dll base_address = 0x76e00000 True 1
Fn
Load advapi32.dll base_address = 0x75070000 True 1
Fn
Load shell32.dll base_address = 0x756f0000 True 1
Fn
Load netapi32.dll base_address = 0x756b0000 True 1
Fn
Load kernel32.dll base_address = 0x77ad0000 True 1
Fn
Load msi.dll base_address = 0x70100000 True 1
Fn
Load pstorec.dll base_address = 0x700f0000 True 1
Fn
Get Handle c:\windows\syswow64\kernel32.dll base_address = 0x77ad0000 True 2
Fn
Get Address c:\windows\syswow64\ole32.dll function = StgOpenStorage, address_out = 0x76d41b90 True 1
Fn
Get Address c:\windows\syswow64\crypt32.dll function = CryptUnprotectData, address_out = 0x76e23140 True 1
Fn
Get Address c:\windows\syswow64\crypt32.dll function = CertOpenSystemStoreA, address_out = 0x76e7e4f0 True 1
Fn
Get Address c:\windows\syswow64\crypt32.dll function = CertEnumCertificatesInStore, address_out = 0x76e548f0 True 1
Fn
Get Address c:\windows\syswow64\crypt32.dll function = CertCloseStore, address_out = 0x76e41d20 True 1
Fn
Get Address c:\windows\syswow64\crypt32.dll function = CryptAcquireCertificatePrivateKey, address_out = 0x76e57190 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = AllocateAndInitializeSid, address_out = 0x7508f660 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = CheckTokenMembership, address_out = 0x7508fb50 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = FreeSid, address_out = 0x75090440 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = CredEnumerateA, address_out = 0x750a6670 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = CredFree, address_out = 0x75093930 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = CryptGetUserKey, address_out = 0x750a6c30 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = CryptExportKey, address_out = 0x7508fb30 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = CryptDestroyKey, address_out = 0x75090400 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = CryptReleaseContext, address_out = 0x75090650 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = RevertToSelf, address_out = 0x7508fc20 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = OpenProcessToken, address_out = 0x7508f520 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = ImpersonateLoggedOnUser, address_out = 0x75090ff0 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = GetTokenInformation, address_out = 0x7508f370 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = ConvertSidToStringSidA, address_out = 0x7508f160 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = LogonUserA, address_out = 0x750a5270 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = LookupPrivilegeValueA, address_out = 0x750a4dc0 True 1
Fn
Get Address c:\windows\syswow64\advapi32.dll function = AdjustTokenPrivileges, address_out = 0x75090980 True 1
Fn
Get Address c:\windows\syswow64\shell32.dll function = SHGetFolderPathA, address_out = 0x758a9b10 True 1
Fn
Get Address c:\windows\syswow64\netapi32.dll function = NetApiBufferFree, address_out = 0x704b16d0 True 1
Fn
Get Address c:\windows\syswow64\netapi32.dll function = NetUserEnum, address_out = 0x7049c010 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = WTSGetActiveConsoleSessionId, address_out = 0x77aee5e0 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = ProcessIdToSessionId, address_out = 0x77ae8fa0 True 1
Fn
Get Address c:\windows\syswow64\msi.dll function = MsiGetComponentPathA, address_out = 0x702419d0 True 1
Fn
Get Address c:\windows\syswow64\pstorec.dll function = PStoreCreateInstance, address_out = 0x700f1290 True 1
Fn
Get Address c:\windows\syswow64\kernel32.dll function = GetNativeSystemInfo, address_out = 0x77aeac70 True 2
Fn
Get Address c:\windows\syswow64\kernel32.dll function = IsWow64Process, address_out = 0x77ae9f10 True 1
Fn
User (295)
»
Operation Additional Information Success Count Logfile
Lookup Privilege privilege = SeImpersonatePrivilege, luid = 29 True 5
Fn
Lookup Privilege privilege = SeTcbPrivilege, luid = 7 True 5
Fn
Lookup Privilege privilege = SeChangeNotifyPrivilege, luid = 23 True 5
Fn
Lookup Privilege privilege = SeCreateTokenPrivilege, luid = 2 True 5
Fn
Lookup Privilege privilege = SeBackupPrivilege, luid = 17 True 5
Fn
Lookup Privilege privilege = SeRestorePrivilege, luid = 18 True 5
Fn
Lookup Privilege privilege = SeIncreaseQuotaPrivilege, luid = 5 True 5
Fn
Lookup Privilege privilege = SeAssignPrimaryTokenPrivilege, luid = 3 True 5
Fn
Logon user_name = Guest, password = Guest False 1
Fn
Logon user_name = Guest, password = guest False 1
Fn
Logon user_name = Guest, password = 123456 False 1
Fn
Logon user_name = Guest, password = password False 1
Fn
Logon user_name = Guest, password = phpbb False 1
Fn
Logon user_name = Guest, password = qwerty False 1
Fn
Logon user_name = Guest, password = 12345 False 1
Fn
Logon user_name = Guest, password = jesus False 1
Fn
Logon user_name = Guest, password = 12345678 False 1
Fn
Logon user_name = Guest, password = 1234 False 1
Fn
Logon user_name = Guest, password = abc123 False 1
Fn
Logon user_name = Guest, password = letmein False 1
Fn
Logon user_name = Guest, password = test False 1
Fn
Logon user_name = Guest, password = love False 1
Fn
Logon user_name = Guest, password = 123 False 1
Fn
Logon user_name = Guest, password = password1 False 1
Fn
Logon user_name = Guest, password = hello False 1
Fn
Logon user_name = Guest, password = monkey False 1
Fn
Logon user_name = Guest, password = dragon False 1
Fn
Logon user_name = Guest, password = trustno1 False 1
Fn
Logon user_name = Guest, password = 111111 False 1
Fn
Logon user_name = Guest, password = iloveyou False 1
Fn
Logon user_name = Guest, password = 1234567 False 1
Fn
Logon user_name = Guest, password = shadow False 1
Fn
Logon user_name = Guest, password = 123456789 False 1
Fn
Logon user_name = Guest, password = christ False 1
Fn
Logon user_name = Guest, password = sunshine False 1
Fn
Logon user_name = Guest, password = master False 1
Fn
Logon user_name = Guest, password = computer False 1
Fn
Logon user_name = Guest, password = princess False 1
Fn
Logon user_name = Guest, password = tigger False 1
Fn
Logon user_name = Guest, password = football False 1
Fn
Logon user_name = Guest, password = angel False 1
Fn
Logon user_name = Guest, password = jesus1 False 1
Fn
Logon user_name = Guest, password = 123123 False 1
Fn
Logon user_name = Guest, password = whatever False 1
Fn
Logon user_name = Guest, password = freedom False 1
Fn
Logon user_name = Guest, password = killer False 1
Fn
Logon user_name = Guest, password = asdf False 1
Fn
Logon user_name = Guest, password = soccer False 1
Fn
Logon user_name = Guest, password = superman False 1
Fn
Logon user_name = Guest, password = michael False 1
Fn
Logon user_name = Guest, password = cheese False 1
Fn
Logon user_name = Guest, password = internet False 1
Fn
Logon user_name = Guest, password = joshua False 1
Fn
Logon user_name = Guest, password = fuckyou False 1
Fn
Logon user_name = Guest, password = blessed False 1
Fn
Logon user_name = Guest, password = baseball False 1
Fn
Logon user_name = Guest, password = starwars False 1
Fn
Logon user_name = Guest, password = 000000 False 1
Fn
Logon user_name = Guest, password = purple False 1
Fn
Logon user_name = Guest, password = jordan False 1
Fn
Logon user_name = Guest, password = faith False 1
Fn
Logon user_name = Guest, password = summer False 1
Fn
Logon user_name = Guest, password = ashley False 1
Fn
Logon user_name = Guest, password = buster False 1
Fn
Logon user_name = Guest, password = heaven False 1
Fn
Logon user_name = Guest, password = pepper False 1
Fn
Logon user_name = Guest, password = 7777777 False 1
Fn
Logon user_name = Guest, password = hunter False 1
Fn
Logon user_name = Guest, password = lovely False 1
Fn
Logon user_name = Guest, password = andrew False 1
Fn
Logon user_name = Guest, password = thomas False 1
Fn
Logon user_name = Guest, password = angels False 1
Fn
Logon user_name = Guest, password = charlie False 1
Fn
Logon user_name = Guest, password = daniel False 1
Fn
Logon user_name = Guest, password = 1111 False 1
Fn
Logon user_name = Guest, password = jennifer False 1
Fn
Logon user_name = Guest, password = single False 1
Fn
Logon user_name = Guest, password = hannah False 1
Fn
Logon user_name = Guest, password = qazwsx False 1
Fn
Logon user_name = Guest, password = happy False 1
Fn
Logon user_name = Guest, password = matrix False 1
Fn
Logon user_name = Guest, password = pass False 1
Fn
Logon user_name = Guest, password = aaaaaa False 1
Fn
Logon user_name = Guest, password = 654321 False 1
Fn
Logon user_name = Guest, password = amanda False 1
Fn
Logon user_name = Guest, password = nothing False 1
Fn
Logon user_name = Guest, password = ginger False 1
Fn
Logon user_name = Guest, password = mother False 1
Fn
Logon user_name = Guest, password = snoopy False 1
Fn
Logon user_name = Guest, password = jessica False 1
Fn
Logon user_name = Guest, password = welcome False 1
Fn
Logon user_name = Guest, password = pokemon False 1
Fn
Logon user_name = Guest, password = iloveyou1 False 1
Fn
Logon user_name = Guest, password = 11111 False 1
Fn
Logon user_name = Guest, password = mustang False 1
Fn
Logon user_name = Guest, password = helpme False 1
Fn
Logon user_name = Guest, password = justin False 1
Fn
Logon user_name = Guest, password = jasmine False 1
Fn
Logon user_name = Guest, password = orange False 1
Fn
Logon user_name = Guest, password = testing False 1
Fn
Logon user_name = Guest, password = apple False 1
Fn
Logon user_name = Guest, password = michelle False 1
Fn
Logon user_name = Guest, password = peace False 1
Fn
Logon user_name = Guest, password = secret False 1
Fn
Logon user_name = Guest, password = 1 False 1
Fn
Logon user_name = Guest, password = grace False 1
Fn
Logon user_name = Guest, password = william False 1
Fn
Logon user_name = Guest, password = iloveyou2 False 1
Fn
Logon user_name = Guest, password = nicole False 1
Fn
Logon user_name = Guest, password = 666666 False 1
Fn
Logon user_name = Guest, password = muffin False 1
Fn
Logon user_name = Guest, password = gateway False 1
Fn
Logon user_name = Guest, password = fuckyou1 False 1
Fn
Logon user_name = Guest, password = asshole False 1
Fn
Logon user_name = Guest, password = hahaha False 1
Fn
Logon user_name = Guest, password = poop False 1
Fn
Logon user_name = Guest, password = blessing False 1
Fn
Logon user_name = Guest, password = blahblah False 1
Fn
Logon user_name = Guest, password = myspace1 False 1
Fn
Logon user_name = Guest, password = matthew False 1
Fn
Logon user_name = Guest, password = canada False 1
Fn
Logon user_name = Guest, password = silver False 1
Fn
Logon user_name = Guest, password = robert False 1
Fn
Logon user_name = Guest, password = forever False 1
Fn
Logon user_name = Guest, password = asdfgh False 1
Fn
Logon user_name = Guest, password = rachel False 1
Fn
Logon user_name = Guest, password = rainbow False 1
Fn
Logon user_name = Guest, password = guitar False 1
Fn
Logon user_name = Guest, password = peanut False 1
Fn
Logon user_name = Guest, password = batman False 1
Fn
Logon user_name = Guest, password = cookie False 1
Fn
Logon user_name = Guest, password = bailey False 1
Fn
Logon user_name = Guest, password = soccer1 False 1
Fn
Logon user_name = Guest, password = mickey False 1
Fn
Logon user_name = Guest, password = biteme False 1
Fn
Logon user_name = Guest, password = hello1 False 1
Fn
Logon user_name = Guest, password = eminem False 1
Fn
Logon user_name = Guest, password = dakota False 1
Fn
Logon user_name = Guest, password = samantha False 1
Fn
Logon user_name = Guest, password = compaq False 1
Fn
Logon user_name = Guest, password = diamond False 1
Fn
Logon user_name = Guest, password = taylor False 1
Fn
Logon user_name = Guest, password = forum False 1
Fn
Logon user_name = Guest, password = john316 False 1
Fn
Logon user_name = Guest, password = richard False 1
Fn
Logon user_name = Guest, password = blink182 False 1
Fn
Logon user_name = Guest, password = peaches False 1
Fn
Logon user_name = Guest, password = cool False 1
Fn
Logon user_name = Guest, password = flower False 1
Fn
Logon user_name = Guest, password = scooter False 1
Fn
Logon user_name = Guest, password = banana False 1
Fn
Logon user_name = Guest, password = james False 1
Fn
Logon user_name = Guest, password = asdfasdf False 1
Fn
Logon user_name = Guest, password = victory False 1
Fn
Logon user_name = Guest, password = london False 1
Fn
Logon user_name = Guest, password = 123qwe False 1
Fn
Logon user_name = Guest, password = 123321 False 1
Fn
Logon user_name = Guest, password = startrek False 1
Fn
Logon user_name = Guest, password = george False 1
Fn
Logon user_name = Guest, password = winner False 1
Fn
Logon user_name = Guest, password = maggie False 1
Fn
Logon user_name = Guest, password = trinity False 1
Fn
Logon user_name = Guest, password = online False 1
Fn
Logon user_name = Guest, password = 123abc False 1
Fn
Logon user_name = Guest, password = chicken False 1
Fn
Logon user_name = Guest, password = junior False 1
Fn
Logon user_name = Guest, password = chris False 1
Fn
Logon user_name = Guest, password = passw0rd False 1
Fn
Logon user_name = Guest, password = austin False 1
Fn
Logon user_name = Guest, password = sparky False 1
Fn
Logon user_name = Guest, password = admin False 1
Fn
Logon user_name = Guest, password = merlin False 1
Fn
Logon user_name = Guest, password = google False 1
Fn
Logon user_name = Guest, password = friends False 1
Fn
Logon user_name = Guest, password = hope False 1
Fn
Logon user_name = Guest, password = shalom False 1
Fn
Logon user_name = Guest, password = nintendo False 1
Fn
Logon user_name = Guest, password = looking False 1
Fn
Logon user_name = Guest, password = harley False 1
Fn
Logon user_name = Guest, password = smokey False 1
Fn
Logon user_name = Guest, password = 7777 False 1
Fn
Logon user_name = Guest, password = joseph False 1
Fn
Logon user_name = Guest, password = lucky False 1
Fn
Logon user_name = Guest, password = digital False 1
Fn
Logon user_name = Guest, password = a False 1
Fn
Logon user_name = Guest, password = thunder False 1
Fn
Logon user_name = Guest, password = spirit False 1
Fn
Logon user_name = Guest, password = bandit False 1
Fn
Logon user_name = Guest, password = enter False 1
Fn
Logon user_name = Guest, password = anthony False 1
Fn
Logon user_name = Guest, password = corvette False 1
Fn
Logon user_name = Guest, password = hockey False 1
Fn
Logon user_name = Guest, password = power False 1
Fn
Logon user_name = Guest, password = benjamin False 1
Fn
Logon user_name = Guest, password = iloveyou! False 1
Fn
Logon user_name = Guest, password = 1q2w3e False 1
Fn
Logon user_name = Guest, password = viper False 1
Fn
Logon user_name = Guest, password = genesis False 1
Fn
Logon user_name = Guest, password = knight False 1
Fn
Logon user_name = Guest, password = qwerty1 False 1
Fn
Logon user_name = Guest, password = creative False 1
Fn
Logon user_name = Guest, password = foobar False 1
Fn
Logon user_name = Guest, password = adidas False 1
Fn
Logon user_name = Guest, password = rotimi False 1
Fn
Logon user_name = Guest, password = slayer False 1
Fn
Logon user_name = Guest, password = wisdom False 1
Fn
Logon user_name = Guest, password = praise False 1
Fn
Logon user_name = Guest, password = zxcvbnm False 1
Fn
Logon user_name = Guest, password = samuel False 1
Fn
Logon user_name = Guest, password = mike False 1
Fn
Logon user_name = Guest, password = dallas False 1
Fn
Logon user_name = Guest, password = green False 1
Fn
Logon user_name = Guest, password = testtest False 1
Fn
Logon user_name = Guest, password = maverick False 1
Fn
Logon user_name = Guest, password = onelove False 1
Fn
Logon user_name = Guest, password = david False 1
Fn
Logon user_name = Guest, password = mylove False 1
Fn
Logon user_name = Guest, password = church False 1
Fn
Logon user_name = Guest, password = friend False 1
Fn
Logon user_name = Guest, password = god False 1
Fn
Logon user_name = Guest, password = destiny False 1
Fn
Logon user_name = Guest, password = none False 1
Fn
Logon user_name = Guest, password = microsoft False 1
Fn
Logon user_name = Guest, password = 222222 False 1
Fn
Logon user_name = Guest, password = bubbles False 1
Fn
Logon user_name = Guest, password = 11111111 False 1
Fn
Logon user_name = Guest, password = cocacola False 1
Fn
Logon user_name = Guest, password = jordan23 False 1
Fn
Logon user_name = Guest, password = ilovegod False 1
Fn
Logon user_name = Guest, password = football1 False 1
Fn
Logon user_name = Guest, password = loving False 1
Fn
Logon user_name = Guest, password = nathan False 1
Fn
Logon user_name = Guest, password = emmanuel False 1
Fn
Logon user_name = Guest, password = scooby False 1
Fn
Logon user_name = Guest, password = fuckoff False 1
Fn
Logon user_name = Guest, password = sammy False 1
Fn
Logon user_name = Guest, password = maxwell False 1
Fn
Logon user_name = Guest, password = jason False 1
Fn
Logon user_name = Guest, password = john False 1
Fn
Logon user_name = Guest, password = 1q2w3e4r False 1
Fn
Logon user_name = Guest, password = baby False 1
Fn
Logon user_name = Guest, password = red123 False 1
Fn
Logon user_name = Guest, password = blabla False 1
Fn
Logon user_name = Guest, password = prince False 1
Fn
Logon user_name = Guest, password = qwert False 1
Fn
Logon user_name = Guest, password = chelsea False 1
Fn
Logon user_name = Guest, password = 55555 False 1
Fn
Logon user_name = Guest, password = angel1 False 1
Fn
Logon user_name = Guest, password = hardcore False 1
Fn
Logon user_name = Guest, password = dexter False 1
Fn
Logon user_name = Guest, password = saved False 1
Fn
Logon user_name = Guest, password = 112233 False 1
Fn
Logon user_name = Guest, password = hallo False 1
Fn
Logon user_name = Guest, password = jasper False 1
Fn
Logon user_name = Guest, password = danielle False 1
Fn
Logon user_name = Guest, password = kitten False 1
Fn
Logon user_name = Guest, password = cassie False 1
Fn
Logon user_name = Guest, password = stella False 1
Fn
Logon user_name = Guest, password = prayer False 1
Fn
Logon user_name = DefaultAccount, password = DefaultAccount False 1
Fn
Logon user_name = DefaultAccount, password = defaultaccount False 1
Fn
Logon user_name = Administrator, password = Administrator False 1
Fn
Logon user_name = Administrator, password = administrator False 1
Fn
System (753)
»
Operation Additional Information Success Count Logfile
Open Certificate Store - True 1
Fn
Get Time type = Ticks, time = 132890 True 249
Fn
Get Time type = Ticks, time = 138656 True 249
Fn
Get Time type = Ticks, time = 139156 True 249
Fn
Get Info type = Operating System True 1
Fn
Get Info type = Hardware Information True 1
Fn
Get Info type = Windows Directory, result_out = C:\Windows True 3
Fn
Ini (2)
»
Operation Filename Additional Information Success Count Logfile
Read C:\Windows\win.ini section_name = WS_FTP, key_name = DIR False 1
Fn
Read C:\Windows\win.ini section_name = WS_FTP, key_name = DEFDIR False 1
Fn
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image