Unpacked Pony | Sequential Behavior
Try VMRay Analyzer
VTI SCORE: 100/100
Dynamic Analysis Report
Classification: Trojan, Spyware

c71c3662a7ebba5fdd0d804fe9ff864789fa08e8286352c21b339b9db2c3db81 (SHA256)

p.exe

Windows Exe (x86-32)

Created at 2018-09-11 15:34:00

Monitored Processes

Process Overview
»
ID PID Monitor Reason Integrity Level Image Name Command Line Origin ID
#1 0xad4 Analysis Target High (Elevated) p.exe "C:\Users\Nd9E1FYi\Desktop\p.exe" -

Behavior Information - Sequential View

Process #1: p.exe
2390 0
»
Information Value
ID #1
File Name c:\users\nd9e1fyi\desktop\p.exe
Command Line "C:\Users\Nd9E1FYi\Desktop\p.exe"
Initial Working Directory C:\Users\Nd9E1FYi\Desktop\
Monitor Start Time: 00:00:20, Reason: Analysis Target
Unmonitor End Time: 00:00:43, Reason: Self Terminated
Monitor Duration 00:00:23
OS Process Information
»
Information Value
PID 0xad4
Parent PID 0x7d4 (c:\windows\explorer.exe)
Is Created or Modified Executable True
Integrity Level High (Elevated)
Username X2VS1CUM\Nd9E1FYi
Enabled Privileges SeChangeNotifyPrivilege, SeImpersonatePrivilege, SeCreateGlobalPrivilege
Thread IDs
0x C58
0x 844
0x CA8
0x DFC
0x DF0
0x A64
0x F98
0x FE0
0x C14
0x E98
Region
»
Name Start VA End VA Type Permissions Monitored Dumped YARA Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory rw True False False -
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory rw True False False -
private_0x0000000000020000 0x00020000 0x00023fff Private Memory rw True False False -
private_0x0000000000030000 0x00030000 0x00030fff Private Memory rw True False False -
pagefile_0x0000000000040000 0x00040000 0x00054fff Pagefile Backed Memory r True False False -
private_0x0000000000060000 0x00060000 0x0009ffff Private Memory rw True False False -
private_0x00000000000a0000 0x000a0000 0x0019ffff Private Memory rw True False False -
pagefile_0x00000000001a0000 0x001a0000 0x001a3fff Pagefile Backed Memory r True False False -
private_0x00000000001b0000 0x001b0000 0x001b1fff Private Memory rw True False False -
private_0x00000000001c0000 0x001c0000 0x001fffff Private Memory rw True False False -
private_0x0000000000200000 0x00200000 0x003fffff Private Memory rw True False False -
p.exe 0x00400000 0x00415fff Memory Mapped File rwx True True True
private_0x0000000000420000 0x00420000 0x0045ffff Private Memory rw True False False -
private_0x0000000000460000 0x00460000 0x00460fff Private Memory rw True False False -
pagefile_0x0000000000470000 0x00470000 0x00471fff Pagefile Backed Memory r True False False -
pagefile_0x0000000000480000 0x00480000 0x00480fff Pagefile Backed Memory rw True False False -
pagefile_0x0000000000490000 0x00490000 0x00490fff Pagefile Backed Memory r True False False -
pagefile_0x00000000004a0000 0x004a0000 0x004a0fff Pagefile Backed Memory r True False False -
private_0x00000000004b0000 0x004b0000 0x004b3fff Private Memory rw True False False -
private_0x00000000004c0000 0x004c0000 0x004cffff Private Memory rw True False False -
locale.nls 0x004d0000 0x0058dfff Memory Mapped File r False False False -
private_0x0000000000590000 0x00590000 0x0060ffff Private Memory rw True False False -
pagefile_0x0000000000610000 0x00610000 0x00611fff Pagefile Backed Memory r True False False -
private_0x0000000000620000 0x00620000 0x0062ffff Private Memory rw True False False -
windowsshell.manifest 0x00630000 0x00630fff Memory Mapped File r False False False -
counters.dat 0x00630000 0x00630fff Memory Mapped File rw True False False -
private_0x0000000000640000 0x00640000 0x0073ffff Private Memory rw True False False -
private_0x0000000000740000 0x00740000 0x0083ffff Private Memory rw True False False -
private_0x0000000000840000 0x00840000 0x0093ffff Private Memory rw True False False -
pagefile_0x0000000000940000 0x00940000 0x00ac7fff Pagefile Backed Memory r True False False -
pagefile_0x0000000000ad0000 0x00ad0000 0x00c50fff Pagefile Backed Memory r True False False -
pagefile_0x0000000000c60000 0x00c60000 0x0205ffff Pagefile Backed Memory r True False False -
private_0x0000000002060000 0x02060000 0x020fffff Private Memory rw True False False -
pagefile_0x0000000002060000 0x02060000 0x02061fff Pagefile Backed Memory r True False False -
private_0x0000000002070000 0x02070000 0x020affff Private Memory rw True False False -
private_0x00000000020b0000 0x020b0000 0x020effff Private Memory rw True False False -
private_0x00000000020f0000 0x020f0000 0x020fffff Private Memory rw True False False -
sortdefault.nls 0x02100000 0x02436fff Memory Mapped File r False False False -
private_0x0000000002440000 0x02440000 0x02540fff Private Memory rw True False False -
private_0x0000000002440000 0x02440000 0x0253ffff Private Memory rw True False False -
private_0x0000000002540000 0x02540000 0x0263ffff Private Memory rw True False False -
private_0x0000000002640000 0x02640000 0x0267ffff Private Memory rw True False False -
private_0x0000000002680000 0x02680000 0x0277ffff Private Memory rw True False False -
private_0x0000000002780000 0x02780000 0x027bffff Private Memory rw True False False -
private_0x00000000027c0000 0x027c0000 0x028bffff Private Memory rw True False False -
private_0x00000000028c0000 0x028c0000 0x028fffff Private Memory rw True False False -
private_0x0000000002900000 0x02900000 0x029fffff Private Memory rw True False False -
private_0x0000000002a00000 0x02a00000 0x02a3ffff Private Memory rw True False False -
private_0x0000000002a40000 0x02a40000 0x02b3ffff Private Memory rw True False False -
pagefile_0x0000000002b40000 0x02b40000 0x02b4ffff Pagefile Backed Memory r True False False -
private_0x0000000002b50000 0x02b50000 0x02b8ffff Private Memory rw True False False -
private_0x0000000002b90000 0x02b90000 0x02c8ffff Private Memory rw True False False -
wow64cpu.dll 0x6e310000 0x6e317fff Memory Mapped File rwx False False False -
wow64.dll 0x6e320000 0x6e36ffff Memory Mapped File rwx False False False -
wow64win.dll 0x6e370000 0x6e3e9fff Memory Mapped File rwx False False False -
samlib.dll 0x6f2d0000 0x6f2e2fff Memory Mapped File rwx False False False -
mlang.dll 0x6f2f0000 0x6f322fff Memory Mapped File rwx False False False -
secur32.dll 0x6f330000 0x6f339fff Memory Mapped File rwx False False False -
comctl32.dll 0x6f340000 0x6f54efff Memory Mapped File rwx False False False -
ieframe.dll 0x6f550000 0x700e8fff Memory Mapped File rwx False False False -
pstorec.dll 0x700f0000 0x700f7fff Memory Mapped File rwx False False False -
msi.dll 0x70100000 0x70488fff Memory Mapped File rwx False False False -
samcli.dll 0x70490000 0x704a4fff Memory Mapped File rwx False False False -
netutils.dll 0x704b0000 0x704b9fff Memory Mapped File rwx False False False -
wsock32.dll 0x704c0000 0x704c7fff Memory Mapped File rwx False False False -
userenv.dll 0x70b60000 0x70b78fff Memory Mapped File rwx False False False -
uxtheme.dll 0x70bf0000 0x70c64fff Memory Mapped File rwx False False False -
wininet.dll 0x70d50000 0x70f5cfff Memory Mapped File rwx False False False -
iertutil.dll 0x726a0000 0x7296afff Memory Mapped File rwx False False False -
propsys.dll 0x72ad0000 0x72c1afff Memory Mapped File rwx False False False -
bcrypt.dll 0x747e0000 0x747fafff Memory Mapped File rwx False False False -
apphelp.dll 0x74a90000 0x74b21fff Memory Mapped File rwx False False False -
cryptbase.dll 0x74b30000 0x74b39fff Memory Mapped File rwx False False False -
sspicli.dll 0x74b40000 0x74b5dfff Memory Mapped File rwx False False False -
windows.storage.dll 0x74b60000 0x75058fff Memory Mapped File rwx False False False -
advapi32.dll 0x75070000 0x750eafff Memory Mapped File rwx False False False -
oleaut32.dll 0x75210000 0x752a1fff Memory Mapped File rwx False False False -
kernelbase.dll 0x75310000 0x7548dfff Memory Mapped File rwx False False False -
kernel.appcore.dll 0x754f0000 0x754fbfff Memory Mapped File rwx False False False -
imm32.dll 0x75500000 0x7552afff Memory Mapped File rwx False False False -
shlwapi.dll 0x75540000 0x75584fff Memory Mapped File rwx False False False -
netapi32.dll 0x756b0000 0x756c2fff Memory Mapped File rwx False False False -
msasn1.dll 0x756d0000 0x756ddfff Memory Mapped File rwx False False False -
shell32.dll 0x756f0000 0x76aeefff Memory Mapped File rwx False False False -
sechost.dll 0x76c60000 0x76ca3fff Memory Mapped File rwx False False False -
ole32.dll 0x76d10000 0x76dfafff Memory Mapped File rwx False False False -
crypt32.dll 0x76e00000 0x76f77fff Memory Mapped File rwx False False False -
rpcrt4.dll 0x76f80000 0x7702cfff Memory Mapped File rwx False False False -
profapi.dll 0x77030000 0x7703efff Memory Mapped File rwx False False False -
gdi32.dll 0x77040000 0x7718efff Memory Mapped File rwx False False False -
combase.dll 0x77230000 0x773ecfff Memory Mapped File rwx False False False -
cfgmgr32.dll 0x773f0000 0x77426fff Memory Mapped File rwx False False False -
clbcatq.dll 0x77840000 0x778c3fff Memory Mapped File rwx False False False -
ws2_32.dll 0x77930000 0x7798efff Memory Mapped File rwx False False False -
shcore.dll 0x779e0000 0x77a6cfff Memory Mapped File rwx False False False -
bcryptprimitives.dll 0x77a70000 0x77ac7fff Memory Mapped File rwx False False False -
kernel32.dll 0x77ad0000 0x77baffff Memory Mapped File rwx False False False -
user32.dll 0x77bb0000 0x77cf6fff Memory Mapped File rwx False False False -
powrprof.dll 0x77d00000 0x77d43fff Memory Mapped File rwx False False False -
msvcrt.dll 0x77d50000 0x77e0dfff Memory Mapped File rwx False False False -
ntdll.dll 0x77e10000 0x77f8afff Memory Mapped File rwx False False False -
pagefile_0x000000007feb0000 0x7feb0000 0x7ffaffff Pagefile Backed Memory r True False False -
pagefile_0x000000007ffb0000 0x7ffb0000 0x7ffd2fff Pagefile Backed Memory r True False False -
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory r True False False -
private_0x000000007fff0000 0x7fff0000 0x7ff91873ffff Private Memory r True False False -
ntdll.dll 0x7ff918740000 0x7ff918900fff Memory Mapped File rwx False False False -
private_0x00007ff918901000 0x7ff918901000 0x7ffffffeffff Private Memory r True False False -
Threads
Thread 0xc58
1628 0
»
Category Operation Information Success Count Logfile
System Get Time type = Ticks, time = 132890 True 249
Fn
Module Load module_name = ole32.dll, base_address = 0x76d10000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = StgOpenStorage, address_out = 0x76d41b90 True 1
Fn
Module Load module_name = crypt32.dll, base_address = 0x76e00000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\crypt32.dll, function = CryptUnprotectData, address_out = 0x76e23140 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\crypt32.dll, function = CertOpenSystemStoreA, address_out = 0x76e7e4f0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\crypt32.dll, function = CertEnumCertificatesInStore, address_out = 0x76e548f0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\crypt32.dll, function = CertCloseStore, address_out = 0x76e41d20 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\crypt32.dll, function = CryptAcquireCertificatePrivateKey, address_out = 0x76e57190 True 1
Fn
Module Load module_name = advapi32.dll, base_address = 0x75070000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = AllocateAndInitializeSid, address_out = 0x7508f660 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CheckTokenMembership, address_out = 0x7508fb50 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = FreeSid, address_out = 0x75090440 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CredEnumerateA, address_out = 0x750a6670 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CredFree, address_out = 0x75093930 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptGetUserKey, address_out = 0x750a6c30 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptExportKey, address_out = 0x7508fb30 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptDestroyKey, address_out = 0x75090400 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = CryptReleaseContext, address_out = 0x75090650 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = RevertToSelf, address_out = 0x7508fc20 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = OpenProcessToken, address_out = 0x7508f520 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = ImpersonateLoggedOnUser, address_out = 0x75090ff0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = GetTokenInformation, address_out = 0x7508f370 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = ConvertSidToStringSidA, address_out = 0x7508f160 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = LogonUserA, address_out = 0x750a5270 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = LookupPrivilegeValueA, address_out = 0x750a4dc0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\advapi32.dll, function = AdjustTokenPrivileges, address_out = 0x75090980 True 1
Fn
Module Load module_name = shell32.dll, base_address = 0x756f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\shell32.dll, function = SHGetFolderPathA, address_out = 0x758a9b10 True 1
Fn
Module Load module_name = netapi32.dll, base_address = 0x756b0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\netapi32.dll, function = NetApiBufferFree, address_out = 0x704b16d0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\netapi32.dll, function = NetUserEnum, address_out = 0x7049c010 True 1
Fn
Module Load module_name = kernel32.dll, base_address = 0x77ad0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = WTSGetActiveConsoleSessionId, address_out = 0x77aee5e0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = ProcessIdToSessionId, address_out = 0x77ae8fa0 True 1
Fn
Module Load module_name = msi.dll, base_address = 0x70100000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\msi.dll, function = MsiGetComponentPathA, address_out = 0x702419d0 True 1
Fn
Module Load module_name = pstorec.dll, base_address = 0x700f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\pstorec.dll, function = PStoreCreateInstance, address_out = 0x700f1290 True 1
Fn
System Get Time type = Ticks, time = 138656 True 249
Fn
User Lookup Privilege privilege = SeImpersonatePrivilege, luid = 29 True 1
Fn
User Lookup Privilege privilege = SeTcbPrivilege, luid = 7 True 1
Fn
User Lookup Privilege privilege = SeChangeNotifyPrivilege, luid = 23 True 1
Fn
User Lookup Privilege privilege = SeCreateTokenPrivilege, luid = 2 True 1
Fn
User Lookup Privilege privilege = SeBackupPrivilege, luid = 17 True 1
Fn
User Lookup Privilege privilege = SeRestorePrivilege, luid = 18 True 1
Fn
User Lookup Privilege privilege = SeIncreaseQuotaPrivilege, luid = 5 True 1
Fn
User Lookup Privilege privilege = SeAssignPrimaryTokenPrivilege, luid = 3 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AddressBook True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AddressBook, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AddressBook True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AddressBook, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AddressBook True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AddressBook, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Connection Manager True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Connection Manager, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Connection Manager True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Connection Manager, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Connection Manager True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Connection Manager, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DirectDrawEx True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DirectDrawEx, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DirectDrawEx True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DirectDrawEx, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DirectDrawEx True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DirectDrawEx, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DXM_Runtime True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DXM_Runtime, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DXM_Runtime True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DXM_Runtime, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DXM_Runtime True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DXM_Runtime, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Fontcore True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Fontcore, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Fontcore True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Fontcore, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Fontcore True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Fontcore, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome, value_name = UninstallString, data = 0, type = REG_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome, value_name = UninstallString, data = 34 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome, value_name = DisplayName, data = 0, type = REG_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Google Chrome, value_name = DisplayName, data = 71 True 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE40 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE40, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE40 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE40, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE40 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE40, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE4Data True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE4Data, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE4Data True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE4Data, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE4Data True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE4Data, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE5BAKEX True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE5BAKEX, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE5BAKEX True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE5BAKEX, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE5BAKEX True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE5BAKEX, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IEData True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IEData, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IEData True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IEData, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IEData True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IEData, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MobileOptionPack True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MobileOptionPack, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MobileOptionPack True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MobileOptionPack, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MobileOptionPack True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MobileOptionPack, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MPlayer2 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MPlayer2, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MPlayer2 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MPlayer2, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MPlayer2 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MPlayer2, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SchedulingAgent True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SchedulingAgent, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SchedulingAgent True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SchedulingAgent, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SchedulingAgent True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SchedulingAgent, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WIC True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WIC, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WIC True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WIC, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WIC True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WIC, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}, value_name = UninstallString, data = 0, type = REG_EXPAND_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}, value_name = UninstallString, data = 77 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}, value_name = DisplayName, data = 0, type = REG_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}, value_name = DisplayName, data = 77 True 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2151757 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2151757, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2151757 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2151757, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2151757 False 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2467173 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2467173, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2467173 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2467173, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2467173 False 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2524860 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2524860, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2524860 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2524860, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2524860 False 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2544655 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2544655, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2544655 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2544655, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2544655 False 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2549743 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2549743, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2549743 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2549743, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2549743 False 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2565063 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2565063, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2565063 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2565063, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB2565063 False 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB982573 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB982573, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB982573 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB982573, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}.KB982573 False 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}, value_name = UninstallString, data = 0, type = REG_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}, value_name = UninstallString, data = 34 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}, value_name = DisplayName, data = 0, type = REG_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}, value_name = DisplayName, data = 77 True 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3c3aafc8-d898-43ec-998f-965ffdae065a} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3c3aafc8-d898-43ec-998f-965ffdae065a}, value_name = UninstallString, data = 0, type = REG_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3c3aafc8-d898-43ec-998f-965ffdae065a}, value_name = UninstallString, data = 34 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3c3aafc8-d898-43ec-998f-965ffdae065a} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3c3aafc8-d898-43ec-998f-965ffdae065a}, value_name = DisplayName, data = 0, type = REG_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3c3aafc8-d898-43ec-998f-965ffdae065a}, value_name = DisplayName, data = 77 True 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3D82C954-2957-418B-908F-FE78BF3A8BEB} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3D82C954-2957-418B-908F-FE78BF3A8BEB}, value_name = UninstallString, data = 0, type = REG_EXPAND_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3D82C954-2957-418B-908F-FE78BF3A8BEB}, value_name = UninstallString, data = 77 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3D82C954-2957-418B-908F-FE78BF3A8BEB} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3D82C954-2957-418B-908F-FE78BF3A8BEB}, value_name = DisplayName, data = 0, type = REG_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3D82C954-2957-418B-908F-FE78BF3A8BEB}, value_name = DisplayName, data = 65 True 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4A03706F-666A-4037-7777-5F2748764D10} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4A03706F-666A-4037-7777-5F2748764D10}, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4A03706F-666A-4037-7777-5F2748764D10} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4A03706F-666A-4037-7777-5F2748764D10}, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4A03706F-666A-4037-7777-5F2748764D10} False 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{582EA838-9199-3518-A05C-DB09462F68EC} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{582EA838-9199-3518-A05C-DB09462F68EC}, value_name = UninstallString, data = 0, type = REG_EXPAND_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{582EA838-9199-3518-A05C-DB09462F68EC}, value_name = UninstallString, data = 77 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{582EA838-9199-3518-A05C-DB09462F68EC} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{582EA838-9199-3518-A05C-DB09462F68EC}, value_name = DisplayName, data = 0, type = REG_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{582EA838-9199-3518-A05C-DB09462F68EC}, value_name = DisplayName, data = 77 True 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{68306422-7C57-373F-8860-D26CE4BA2A15} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{68306422-7C57-373F-8860-D26CE4BA2A15}, value_name = UninstallString, data = 0, type = REG_EXPAND_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{68306422-7C57-373F-8860-D26CE4BA2A15}, value_name = UninstallString, data = 77 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{68306422-7C57-373F-8860-D26CE4BA2A15} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{68306422-7C57-373F-8860-D26CE4BA2A15}, value_name = DisplayName, data = 0, type = REG_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{68306422-7C57-373F-8860-D26CE4BA2A15}, value_name = DisplayName, data = 77 True 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}, value_name = UninstallString, data = 0, type = REG_EXPAND_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}, value_name = UninstallString, data = 77 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}, value_name = DisplayName, data = 0, type = REG_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}, value_name = DisplayName, data = 77 True 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9BE518E6-ECC6-35A9-88E4-87755C07200F} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9BE518E6-ECC6-35A9-88E4-87755C07200F}, value_name = UninstallString, data = 0, type = REG_EXPAND_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9BE518E6-ECC6-35A9-88E4-87755C07200F}, value_name = UninstallString, data = 77 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9BE518E6-ECC6-35A9-88E4-87755C07200F} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9BE518E6-ECC6-35A9-88E4-87755C07200F}, value_name = DisplayName, data = 0, type = REG_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9BE518E6-ECC6-35A9-88E4-87755C07200F}, value_name = DisplayName, data = 77 True 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-0804-1033-1959-001824214663} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-0804-1033-1959-001824214663}, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-0804-1033-1959-001824214663} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-0804-1033-1959-001824214663}, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-0804-1033-1959-001824214663} False 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-0804-1033-1959-001824237067} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-0804-1033-1959-001824237067}, value_name = UninstallString, data = 0, type = REG_EXPAND_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-0804-1033-1959-001824237067}, value_name = UninstallString, data = 77 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-0804-1033-1959-001824237067} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-0804-1033-1959-001824237067}, value_name = DisplayName, data = 0, type = REG_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-0804-1033-1959-001824237067}, value_name = DisplayName, data = 65 True 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1033-7B44-AC0F074E4100} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}, value_name = UninstallString, data = 0, type = REG_EXPAND_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}, value_name = UninstallString, data = 77 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1033-7B44-AC0F074E4100} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}, value_name = DisplayName, data = 0, type = REG_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}, value_name = DisplayName, data = 65 True 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B175520C-86A2-35A7-8619-86DC379688B9} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B175520C-86A2-35A7-8619-86DC379688B9}, value_name = UninstallString, data = 0, type = REG_EXPAND_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B175520C-86A2-35A7-8619-86DC379688B9}, value_name = UninstallString, data = 77 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B175520C-86A2-35A7-8619-86DC379688B9} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B175520C-86A2-35A7-8619-86DC379688B9}, value_name = DisplayName, data = 0, type = REG_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{B175520C-86A2-35A7-8619-86DC379688B9}, value_name = DisplayName, data = 77 True 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}, value_name = UninstallString, data = 0, type = REG_EXPAND_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}, value_name = UninstallString, data = 77 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}, value_name = DisplayName, data = 0, type = REG_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}, value_name = DisplayName, data = 77 True 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}, value_name = UninstallString, data = 0, type = REG_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}, value_name = UninstallString, data = 34 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}, value_name = DisplayName, data = 0, type = REG_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}, value_name = DisplayName, data = 77 True 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{e52a6842-b0ac-476e-b48f-378a97a67346} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{e52a6842-b0ac-476e-b48f-378a97a67346}, value_name = UninstallString, data = 0, type = REG_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{e52a6842-b0ac-476e-b48f-378a97a67346}, value_name = UninstallString, data = 34 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{e52a6842-b0ac-476e-b48f-378a97a67346} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{e52a6842-b0ac-476e-b48f-378a97a67346}, value_name = DisplayName, data = 0, type = REG_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{e52a6842-b0ac-476e-b48f-378a97a67346}, value_name = DisplayName, data = 77 True 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{e6e75766-da0f-4ba2-9788-6ea593ce702d} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{e6e75766-da0f-4ba2-9788-6ea593ce702d}, value_name = UninstallString, data = 0, type = REG_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{e6e75766-da0f-4ba2-9788-6ea593ce702d}, value_name = UninstallString, data = 34 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{e6e75766-da0f-4ba2-9788-6ea593ce702d} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{e6e75766-da0f-4ba2-9788-6ea593ce702d}, value_name = DisplayName, data = 0, type = REG_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{e6e75766-da0f-4ba2-9788-6ea593ce702d}, value_name = DisplayName, data = 77 True 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}, value_name = UninstallString, data = 0, type = REG_EXPAND_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}, value_name = UninstallString, data = 77 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}, value_name = DisplayName, data = 0, type = REG_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}, value_name = DisplayName, data = 77 True 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2151757 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2151757, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2151757 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2151757, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2151757 False 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2467173 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2467173, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2467173 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2467173, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2467173 False 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2524860 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2524860, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2524860 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2524860, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2524860 False 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2544655 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2544655, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2544655 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2544655, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2544655 False 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2549743 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2549743, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2549743 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2549743, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2549743 False 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2565063 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2565063, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2565063 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2565063, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB2565063 False 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB982573 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB982573, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB982573 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB982573, value_name = UninstallString, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}.KB982573 False 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{f325f05b-f963-4640-a43b-c8a494cdda0f} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{f325f05b-f963-4640-a43b-c8a494cdda0f}, value_name = UninstallString, data = 0, type = REG_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{f325f05b-f963-4640-a43b-c8a494cdda0f}, value_name = UninstallString, data = 34 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{f325f05b-f963-4640-a43b-c8a494cdda0f} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{f325f05b-f963-4640-a43b-c8a494cdda0f}, value_name = DisplayName, data = 0, type = REG_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{f325f05b-f963-4640-a43b-c8a494cdda0f}, value_name = DisplayName, data = 77 True 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}, value_name = UninstallString, data = 0, type = REG_EXPAND_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}, value_name = UninstallString, data = 77 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185} True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}, value_name = DisplayName, data = 0, type = REG_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}, value_name = DisplayName, data = 77 True 1
Fn
Registry Enumerate Keys reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall False 1
Fn
System Get Time type = Ticks, time = 139156 True 249
Fn
System Get Info type = Operating System True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77ad0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetNativeSystemInfo, address_out = 0x77aeac70 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = IsWow64Process, address_out = 0x77ae9f10 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR False 3
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Local\Temp\HWID, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE False 1
Fn
Registry Create Key reg_name = HKEY_CURRENT_USER\Software\WinRAR True 1
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\Software\WinRAR, value_name = HWID, size = 38, type = REG_BINARY True 1
Fn
Data
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\WinRAR True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR, value_name = HWID, type = REG_BINARY True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\WinRAR, value_name = HWID, data = 123 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x77ad0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetNativeSystemInfo, address_out = 0x77aeac70 True 1
Fn
System Get Info type = Hardware Information True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Far\Plugins\FTP\Hosts False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Far2\Plugins\FTP\Hosts False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Far Manager\Plugins\FTP\Hosts False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Far\SavedDialogHistory\FTPHost False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Far2\SavedDialogHistory\FTPHost False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Far Manager\SavedDialogHistory\FTPHost False 1
Fn
System Get Info type = Windows Directory, result_out = C:\Windows True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Ghisler\Windows Commander False 3
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Ghisler\Windows Commander False 3
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Ghisler\Total Commander False 3
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Ghisler\Total Commander False 3
Fn
File Create filename = C:\Windows\wcx_ftp.ini, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Ghisler\Windows Commander False 3
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Ghisler\Windows Commander False 3
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Ghisler\Total Commander False 3
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Ghisler\Total Commander False 3
Fn
File Create filename = C:\Users\Nd9E1FYi\wcx_ftp.ini, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Ghisler\Windows Commander False 3
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Ghisler\Windows Commander False 3
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Ghisler\Total Commander False 3
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Ghisler\Total Commander False 3
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Roaming\GHISLER\wcx_ftp.ini, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Ghisler\Windows Commander False 3
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Ghisler\Windows Commander False 3
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Ghisler\Total Commander False 3
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Ghisler\Total Commander False 3
Fn
File Create filename = C:\ProgramData\GHISLER\wcx_ftp.ini, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Ghisler\Windows Commander False 3
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Ghisler\Windows Commander False 3
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Ghisler\Total Commander False 3
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Ghisler\Total Commander False 3
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Local\GHISLER\wcx_ftp.ini, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Ghisler\Windows Commander False 6
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Ghisler\Total Commander False 6
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Ghisler\Windows Commander False 6
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Ghisler\Total Commander False 6
Fn
System Get Info type = Windows Directory, result_out = C:\Windows True 1
Fn
Ini Read file_name_orig = C:\Windows\win.ini, section_name = WS_FTP, key_name = DIR False 1
Fn
Ini Read file_name_orig = C:\Windows\win.ini, section_name = WS_FTP, key_name = DEFDIR False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Roaming\GlobalSCAPE\CuteFTP\sm.dat, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Roaming\GlobalSCAPE\CuteFTP Pro\sm.dat, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Roaming\GlobalSCAPE\CuteFTP Lite\sm.dat, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Roaming\CuteFTP\sm.dat, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\ProgramData\GlobalSCAPE\CuteFTP\sm.dat, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\ProgramData\GlobalSCAPE\CuteFTP Pro\sm.dat, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\ProgramData\GlobalSCAPE\CuteFTP Lite\sm.dat, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\ProgramData\CuteFTP\sm.dat, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Local\GlobalSCAPE\CuteFTP\sm.dat, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Local\GlobalSCAPE\CuteFTP Pro\sm.dat, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Local\GlobalSCAPE\CuteFTP Lite\sm.dat, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Local\CuteFTP\sm.dat, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Program Files (x86)\GlobalSCAPE\CuteFTP\sm.dat, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Program Files (x86)\GlobalSCAPE\CuteFTP Pro\sm.dat, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Program Files (x86)\GlobalSCAPE\CuteFTP Lite\sm.dat, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Program Files (x86)\CuteFTP\sm.dat, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\GlobalSCAPE\CuteFTP 6 Home\QCToolbar False 3
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\GlobalSCAPE\CuteFTP 6 Professional\QCToolbar False 3
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\GlobalSCAPE\CuteFTP 7 Home\QCToolbar False 3
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\GlobalSCAPE\CuteFTP 7 Professional\QCToolbar False 3
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\GlobalSCAPE\CuteFTP 8 Home\QCToolbar False 3
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\GlobalSCAPE\CuteFTP 8 Professional\QCToolbar False 3
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\FlashFXP\3 False 3
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\FlashFXP False 3
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\FlashFXP\3 False 6
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\FlashFXP\4 False 12
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\FlashFXP\3 False 3
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\FlashFXP False 3
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\FlashFXP\3 False 6
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\FlashFXP\4 False 12
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Roaming\FlashFXP\3\Sites.dat, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Roaming\FlashFXP\4\Sites.dat, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Roaming\FlashFXP\3\Quick.dat, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Roaming\FlashFXP\4\Quick.dat, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Roaming\FlashFXP\3\History.dat, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Roaming\FlashFXP\4\History.dat, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\ProgramData\FlashFXP\3\Sites.dat, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\ProgramData\FlashFXP\4\Sites.dat, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\ProgramData\FlashFXP\3\Quick.dat, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\ProgramData\FlashFXP\4\Quick.dat, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\ProgramData\FlashFXP\3\History.dat, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\ProgramData\FlashFXP\4\History.dat, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Local\FlashFXP\3\Sites.dat, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Local\FlashFXP\4\Sites.dat, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Local\FlashFXP\3\Quick.dat, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Local\FlashFXP\4\Quick.dat, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Local\FlashFXP\3\History.dat, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Local\FlashFXP\4\History.dat, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\FileZilla False 58
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\FileZilla Client False 3
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\FileZilla False 3
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\FileZilla Client False 3
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Roaming\FileZilla\sitemanager.xml, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Roaming\FileZilla\recentservers.xml, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Roaming\FileZilla\filezilla.xml, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\ProgramData\FileZilla\sitemanager.xml, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\ProgramData\FileZilla\recentservers.xml, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\ProgramData\FileZilla\filezilla.xml, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Local\FileZilla\sitemanager.xml, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Local\FileZilla\recentservers.xml, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Local\FileZilla\filezilla.xml, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\BPFTP\Bullet Proof FTP\Main False 3
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\BulletProof Software\BulletProof FTP Client\Main False 3
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\BPFTP\Bullet Proof FTP\Options False 3
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\BulletProof Software\BulletProof FTP Client\Options False 3
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\BPFTP False 3
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\TurboFTP False 3
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\TurboFTP False 3
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\TurboFTP False 3
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\TurboFTP False 3
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Sota\FFFTP False 6
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Sota\FFFTP\Options False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\CoffeeCup Software\Internet\Profiles False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\FTPWare\COREFTP\Sites False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\FTP Explorer\FTP Explorer\Workspace\MFCToolBar-224 False 3
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\FTP Explorer\Profiles False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\VanDyke\SecureFX False 3
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Cryer\WebSitePublisher False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\ExpanDrive\Sessions False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\ExpanDrive False 3
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Roaming\ExpanDrive\drives.js, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Local\ExpanDrive\drives.js, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\ProgramData\ExpanDrive\drives.js, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\NCH Software\ClassicFTP\FTPAccounts False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\NCH Software\ClassicFTP\FTPAccounts False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\NCH Software\Fling\Accounts False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\NCH Software\Fling\Accounts False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\FTPClient\Sites False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\FTPClient\Sites False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\SoftX.org\FTPClient\Sites False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\SoftX.org\FTPClient\Sites False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Roaming\SharedSettings.ccs, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Roaming\SharedSettings.sqlite, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Roaming\SharedSettings_1_0_5.ccs, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Roaming\SharedSettings_1_0_5.sqlite, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\ProgramData\SharedSettings.ccs, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\ProgramData\SharedSettings.sqlite, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\ProgramData\SharedSettings_1_0_5.ccs, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\ProgramData\SharedSettings_1_0_5.sqlite, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Local\SharedSettings.ccs, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Local\SharedSettings.sqlite, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Local\SharedSettings_1_0_5.ccs, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Local\SharedSettings_1_0_5.sqlite, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Roaming\CoffeeCup Software\SharedSettings.ccs, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Roaming\CoffeeCup Software\SharedSettings.sqlite, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Roaming\CoffeeCup Software\SharedSettings_1_0_5.ccs, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Roaming\CoffeeCup Software\SharedSettings_1_0_5.sqlite, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\ProgramData\CoffeeCup Software\SharedSettings.ccs, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\ProgramData\CoffeeCup Software\SharedSettings.sqlite, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\ProgramData\CoffeeCup Software\SharedSettings_1_0_5.ccs, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\ProgramData\CoffeeCup Software\SharedSettings_1_0_5.sqlite, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Local\CoffeeCup Software\SharedSettings.ccs, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Local\CoffeeCup Software\SharedSettings.sqlite, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Local\CoffeeCup Software\SharedSettings_1_0_5.ccs, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Local\CoffeeCup Software\SharedSettings_1_0_5.sqlite, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\LeapWare False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\LeapWare False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Martin Prikryl False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Martin Prikryl False 1
Fn
System Get Info type = Windows Directory, result_out = C:\Windows True 1
Fn
File Create filename = C:\Windows\32BitFtp.ini, desired_access = FILE_READ_ATTRIBUTES False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\South River Technologies\WebDrive\Connections False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\South River Technologies\WebDrive\Connections False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Opera Software False 6
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\Opera.HTML\shell\open\command False 3
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\AceBIT False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\AceBIT False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{CB1F2C0F-8094-4AAC-BCF5-41A64E27F777} False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{9EA55529-E122-4757-BC79-E4825F80732C} False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs False 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox False 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs False 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox False 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs False 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox False 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs False 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox False 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Mozilla, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Mozilla, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Mozilla, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs True 1
Fn
Registry Read Value reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs False 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox False 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla False 2
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla, value_name = PathToExe, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\LeechFTP False 6
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\CLSID\{11C1D741-A95B-11d2-8A80-0080ADB32FF4}\InProcServer32 False 3
Fn
COM Create interface = 3C374A41-BAE4-11CF-BF7D-00AA006946EE, cls_context = CLSCTX_INPROC_SERVER, CLSCTX_LOCAL_SERVER True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IntelliForms\Storage2 False 102
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Adobe\Common False 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Local\Google\Chrome\User Data\Default\Web Data, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Users\Nd9E1FYi\AppData\Local\Google\Chrome\User Data\Default\Web Data, size = 4096, size_out = 4096 True 16
Fn
Data
File Read filename = C:\Users\Nd9E1FYi\AppData\Local\Google\Chrome\User Data\Default\Web Data, size = 4096, size_out = 0 True 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Users\Nd9E1FYi\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal, size = 4096, size_out = 0 True 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Local\Google\Chrome\User Data\Default\Login Data, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Users\Nd9E1FYi\AppData\Local\Google\Chrome\User Data\Default\Login Data, size = 4096, size_out = 4096 True 4
Fn
Data
File Read filename = C:\Users\Nd9E1FYi\AppData\Local\Google\Chrome\User Data\Default\Login Data, size = 4096, size_out = 2048 True 1
Fn
Data
File Read filename = C:\Users\Nd9E1FYi\AppData\Local\Google\Chrome\User Data\Default\Login Data, size = 4096, size_out = 0 True 1
Fn
File Create filename = C:\Users\Nd9E1FYi\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal, desired_access = GENERIC_READ, share_mode = FILE_SHARE_READ, FILE_SHARE_WRITE True 1
Fn
File Read filename = C:\Users\Nd9E1FYi\AppData\Local\Google\Chrome\User Data\Default\Login Data-journal, size = 4096, size_out = 0 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\ChromePlus False 3
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\FlashPeak\BlazeFtp\Settings False 12
Fn
Registry Open Key reg_name = HKEY_CLASSES_ROOT\FTP++.Link\shell\open\command False 3
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F9043C88-F6F2-101A-A3C9-08002B2F49FB}\1.2\0\win32 False 3
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Robo-FTP 3.7\FTPServers False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Robo-FTP 3.7\FTPServers False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\SOFTWARE\Robo-FTP 3.7\Scripts False 3
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Robo-FTP 3.7\Scripts False 3
Fn
System Open Certificate Store - True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\LinasFTP\Site Manager False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\SimonTatham\PuTTY\Sessions False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\SimonTatham\PuTTY\Sessions False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\CoffeeCup Software False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\CoffeeCup Software False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\MAS-Soft\FTPInfo\Setup False 3
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\FTP False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Nico Mak Computing\WinZip\FTP False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Nico Mak Computing\WinZip\mru\jobs False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Nico Mak Computing\WinZip\mru\jobs False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Live Mail False 3
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows Mail False 3
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\RimArts\B2\Settings False 3
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\RimArts\B2\Settings False 3
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\RimArts\B2\Settings False 3
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\RimArts\B2\Settings False 3
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Poco Systems Inc False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Poco Systems Inc False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\IncrediMail False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\IncrediMail False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\RIT\The Bat! False 6
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\RIT\The Bat!\Users depot False 6
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\RIT\The Bat! False 6
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\RIT\The Bat!\Users depot False 6
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Internet Account Manager\Accounts False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Identities False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Account Manager True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Account Manager, value_name = Outlook, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Account Manager True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Account Manager, value_name = Outlook, type = REG_NONE False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Account Manager True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Account Manager, value_name = Outlook, data = 0, type = REG_SZ True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Account Manager, value_name = Outlook, data = 83 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\OMI Account Manager\Accounts False 2
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Microsoft Outlook Internet Settings False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs False 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox False 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs True 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox\TaskBarIDs False 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla\Firefox False 1
Fn
Registry Enumerate Keys reg_name = HKEY_CURRENT_USER\Software\Mozilla False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Mozilla False 1
Fn
User Lookup Privilege privilege = SeImpersonatePrivilege, luid = 29 True 1
Fn
User Lookup Privilege privilege = SeTcbPrivilege, luid = 7 True 1
Fn
User Lookup Privilege privilege = SeChangeNotifyPrivilege, luid = 23 True 1
Fn
User Lookup Privilege privilege = SeCreateTokenPrivilege, luid = 2 True 1
Fn
User Lookup Privilege privilege = SeBackupPrivilege, luid = 17 True 1
Fn
User Lookup Privilege privilege = SeRestorePrivilege, luid = 18 True 1
Fn
User Lookup Privilege privilege = SeIncreaseQuotaPrivilege, luid = 5 True 1
Fn
User Lookup Privilege privilege = SeAssignPrimaryTokenPrivilege, luid = 3 True 1
Fn
User Lookup Privilege privilege = SeImpersonatePrivilege, luid = 29 True 1
Fn
User Lookup Privilege privilege = SeTcbPrivilege, luid = 7 True 1
Fn
User Lookup Privilege privilege = SeChangeNotifyPrivilege, luid = 23 True 1
Fn
User Lookup Privilege privilege = SeCreateTokenPrivilege, luid = 2 True 1
Fn
User Lookup Privilege privilege = SeBackupPrivilege, luid = 17 True 1
Fn
User Lookup Privilege privilege = SeRestorePrivilege, luid = 18 True 1
Fn
User Lookup Privilege privilege = SeIncreaseQuotaPrivilege, luid = 5 True 1
Fn
User Lookup Privilege privilege = SeAssignPrimaryTokenPrivilege, luid = 3 True 1
Fn
User Logon user_name = Guest, password = Guest False 1
Fn
User Logon user_name = Guest, password = guest False 1
Fn
User Logon user_name = Guest, password = 123456 False 1
Fn
User Logon user_name = Guest, password = password False 1
Fn
User Logon user_name = Guest, password = phpbb False 1
Fn
User Logon user_name = Guest, password = qwerty False 1
Fn
User Logon user_name = Guest, password = 12345 False 1
Fn
User Logon user_name = Guest, password = jesus False 1
Fn
User Logon user_name = Guest, password = 12345678 False 1
Fn
User Logon user_name = Guest, password = 1234 False 1
Fn
User Logon user_name = Guest, password = abc123 False 1
Fn
User Logon user_name = Guest, password = letmein False 1
Fn
User Logon user_name = Guest, password = test False 1
Fn
User Logon user_name = Guest, password = love False 1
Fn
User Logon user_name = Guest, password = 123 False 1
Fn
User Logon user_name = Guest, password = password1 False 1
Fn
User Logon user_name = Guest, password = hello False 1
Fn
User Logon user_name = Guest, password = monkey False 1
Fn
User Logon user_name = Guest, password = dragon False 1
Fn
User Logon user_name = Guest, password = trustno1 False 1
Fn
User Logon user_name = Guest, password = 111111 False 1
Fn
User Logon user_name = Guest, password = iloveyou False 1
Fn
User Logon user_name = Guest, password = 1234567 False 1
Fn
User Logon user_name = Guest, password = shadow False 1
Fn
User Logon user_name = Guest, password = 123456789 False 1
Fn
User Logon user_name = Guest, password = christ False 1
Fn
User Logon user_name = Guest, password = sunshine False 1
Fn
User Logon user_name = Guest, password = master False 1
Fn
User Logon user_name = Guest, password = computer False 1
Fn
User Logon user_name = Guest, password = princess False 1
Fn
User Logon user_name = Guest, password = tigger False 1
Fn
User Logon user_name = Guest, password = football False 1
Fn
User Logon user_name = Guest, password = angel False 1
Fn
User Logon user_name = Guest, password = jesus1 False 1
Fn
User Logon user_name = Guest, password = 123123 False 1
Fn
User Logon user_name = Guest, password = whatever False 1
Fn
User Logon user_name = Guest, password = freedom False 1
Fn
User Logon user_name = Guest, password = killer False 1
Fn
User Logon user_name = Guest, password = asdf False 1
Fn
User Logon user_name = Guest, password = soccer False 1
Fn
User Logon user_name = Guest, password = superman False 1
Fn
User Logon user_name = Guest, password = michael False 1
Fn
User Logon user_name = Guest, password = cheese False 1
Fn
User Logon user_name = Guest, password = internet False 1
Fn
User Logon user_name = Guest, password = joshua False 1
Fn
User Logon user_name = Guest, password = fuckyou False 1
Fn
User Logon user_name = Guest, password = blessed False 1
Fn
User Logon user_name = Guest, password = baseball False 1
Fn
User Logon user_name = Guest, password = starwars False 1
Fn
User Logon user_name = Guest, password = 000000 False 1
Fn
User Logon user_name = Guest, password = purple False 1
Fn
User Logon user_name = Guest, password = jordan False 1
Fn
User Logon user_name = Guest, password = faith False 1
Fn
User Logon user_name = Guest, password = summer False 1
Fn
User Logon user_name = Guest, password = ashley False 1
Fn
User Logon user_name = Guest, password = buster False 1
Fn
User Logon user_name = Guest, password = heaven False 1
Fn
User Logon user_name = Guest, password = pepper False 1
Fn
User Logon user_name = Guest, password = 7777777 False 1
Fn
User Logon user_name = Guest, password = hunter False 1
Fn
User Logon user_name = Guest, password = lovely False 1
Fn
User Logon user_name = Guest, password = andrew False 1
Fn
User Logon user_name = Guest, password = thomas False 1
Fn
User Logon user_name = Guest, password = angels False 1
Fn
User Logon user_name = Guest, password = charlie False 1
Fn
User Logon user_name = Guest, password = daniel False 1
Fn
User Logon user_name = Guest, password = 1111 False 1
Fn
User Logon user_name = Guest, password = jennifer False 1
Fn
User Logon user_name = Guest, password = single False 1
Fn
User Logon user_name = Guest, password = hannah False 1
Fn
User Logon user_name = Guest, password = qazwsx False 1
Fn
User Logon user_name = Guest, password = happy False 1
Fn
User Logon user_name = Guest, password = matrix False 1
Fn
User Logon user_name = Guest, password = pass False 1
Fn
User Logon user_name = Guest, password = aaaaaa False 1
Fn
User Logon user_name = Guest, password = 654321 False 1
Fn
User Logon user_name = Guest, password = amanda False 1
Fn
User Logon user_name = Guest, password = nothing False 1
Fn
User Logon user_name = Guest, password = ginger False 1
Fn
User Logon user_name = Guest, password = mother False 1
Fn
User Logon user_name = Guest, password = snoopy False 1
Fn
User Logon user_name = Guest, password = jessica False 1
Fn
User Logon user_name = Guest, password = welcome False 1
Fn
User Logon user_name = Guest, password = pokemon False 1
Fn
User Logon user_name = Guest, password = iloveyou1 False 1
Fn
User Logon user_name = Guest, password = 11111 False 1
Fn
User Logon user_name = Guest, password = mustang False 1
Fn
User Logon user_name = Guest, password = helpme False 1
Fn
User Logon user_name = Guest, password = justin False 1
Fn
User Logon user_name = Guest, password = jasmine False 1
Fn
User Logon user_name = Guest, password = orange False 1
Fn
User Logon user_name = Guest, password = testing False 1
Fn
User Logon user_name = Guest, password = apple False 1
Fn
User Logon user_name = Guest, password = michelle False 1
Fn
User Logon user_name = Guest, password = peace False 1
Fn
User Logon user_name = Guest, password = secret False 1
Fn
User Logon user_name = Guest, password = 1 False 1
Fn
User Logon user_name = Guest, password = grace False 1
Fn
User Logon user_name = Guest, password = william False 1
Fn
User Logon user_name = Guest, password = iloveyou2 False 1
Fn
User Logon user_name = Guest, password = nicole False 1
Fn
User Logon user_name = Guest, password = 666666 False 1
Fn
User Logon user_name = Guest, password = muffin False 1
Fn
User Logon user_name = Guest, password = gateway False 1
Fn
User Logon user_name = Guest, password = fuckyou1 False 1
Fn
User Logon user_name = Guest, password = asshole False 1
Fn
User Logon user_name = Guest, password = hahaha False 1
Fn
User Logon user_name = Guest, password = poop False 1
Fn
User Logon user_name = Guest, password = blessing False 1
Fn
User Logon user_name = Guest, password = blahblah False 1
Fn
User Logon user_name = Guest, password = myspace1 False 1
Fn
User Logon user_name = Guest, password = matthew False 1
Fn
User Logon user_name = Guest, password = canada False 1
Fn
User Logon user_name = Guest, password = silver False 1
Fn
User Logon user_name = Guest, password = robert False 1
Fn
User Logon user_name = Guest, password = forever False 1
Fn
User Logon user_name = Guest, password = asdfgh False 1
Fn
User Logon user_name = Guest, password = rachel False 1
Fn
User Logon user_name = Guest, password = rainbow False 1
Fn
User Logon user_name = Guest, password = guitar False 1
Fn
User Logon user_name = Guest, password = peanut False 1
Fn
User Logon user_name = Guest, password = batman False 1
Fn
User Logon user_name = Guest, password = cookie False 1
Fn
User Logon user_name = Guest, password = bailey False 1
Fn
User Logon user_name = Guest, password = soccer1 False 1
Fn
User Logon user_name = Guest, password = mickey False 1
Fn
User Logon user_name = Guest, password = biteme False 1
Fn
User Logon user_name = Guest, password = hello1 False 1
Fn
User Logon user_name = Guest, password = eminem False 1
Fn
User Logon user_name = Guest, password = dakota False 1
Fn
User Logon user_name = Guest, password = samantha False 1
Fn
User Logon user_name = Guest, password = compaq False 1
Fn
User Logon user_name = Guest, password = diamond False 1
Fn
User Logon user_name = Guest, password = taylor False 1
Fn
User Logon user_name = Guest, password = forum False 1
Fn
User Logon user_name = Guest, password = john316 False 1
Fn
User Logon user_name = Guest, password = richard False 1
Fn
User Logon user_name = Guest, password = blink182 False 1
Fn
User Logon user_name = Guest, password = peaches False 1
Fn
User Logon user_name = Guest, password = cool False 1
Fn
User Logon user_name = Guest, password = flower False 1
Fn
User Logon user_name = Guest, password = scooter False 1
Fn
User Logon user_name = Guest, password = banana False 1
Fn
User Logon user_name = Guest, password = james False 1
Fn
User Logon user_name = Guest, password = asdfasdf False 1
Fn
User Logon user_name = Guest, password = victory False 1
Fn
User Logon user_name = Guest, password = london False 1
Fn
User Logon user_name = Guest, password = 123qwe False 1
Fn
User Logon user_name = Guest, password = 123321 False 1
Fn
User Logon user_name = Guest, password = startrek False 1
Fn
User Logon user_name = Guest, password = george False 1
Fn
User Logon user_name = Guest, password = winner False 1
Fn
User Logon user_name = Guest, password = maggie False 1
Fn
User Logon user_name = Guest, password = trinity False 1
Fn
User Logon user_name = Guest, password = online False 1
Fn
User Logon user_name = Guest, password = 123abc False 1
Fn
User Logon user_name = Guest, password = chicken False 1
Fn
User Logon user_name = Guest, password = junior False 1
Fn
User Logon user_name = Guest, password = chris False 1
Fn
User Logon user_name = Guest, password = passw0rd False 1
Fn
User Logon user_name = Guest, password = austin False 1
Fn
User Logon user_name = Guest, password = sparky False 1
Fn
User Logon user_name = Guest, password = admin False 1
Fn
User Logon user_name = Guest, password = merlin False 1
Fn
User Logon user_name = Guest, password = google False 1
Fn
User Logon user_name = Guest, password = friends False 1
Fn
User Logon user_name = Guest, password = hope False 1
Fn
User Logon user_name = Guest, password = shalom False 1
Fn
User Logon user_name = Guest, password = nintendo False 1
Fn
User Logon user_name = Guest, password = looking False 1
Fn
User Logon user_name = Guest, password = harley False 1
Fn
User Logon user_name = Guest, password = smokey False 1
Fn
User Logon user_name = Guest, password = 7777 False 1
Fn
User Logon user_name = Guest, password = joseph False 1
Fn
User Logon user_name = Guest, password = lucky False 1
Fn
User Logon user_name = Guest, password = digital False 1
Fn
User Logon user_name = Guest, password = a False 1
Fn
User Logon user_name = Guest, password = thunder False 1
Fn
User Logon user_name = Guest, password = spirit False 1
Fn
User Logon user_name = Guest, password = bandit False 1
Fn
User Logon user_name = Guest, password = enter False 1
Fn
User Logon user_name = Guest, password = anthony False 1
Fn
User Logon user_name = Guest, password = corvette False 1
Fn
User Logon user_name = Guest, password = hockey False 1
Fn
User Logon user_name = Guest, password = power False 1
Fn
User Logon user_name = Guest, password = benjamin False 1
Fn
User Logon user_name = Guest, password = iloveyou! False 1
Fn
User Logon user_name = Guest, password = 1q2w3e False 1
Fn
User Logon user_name = Guest, password = viper False 1
Fn
User Logon user_name = Guest, password = genesis False 1
Fn
User Logon user_name = Guest, password = knight False 1
Fn
User Logon user_name = Guest, password = qwerty1 False 1
Fn
User Logon user_name = Guest, password = creative False 1
Fn
User Logon user_name = Guest, password = foobar False 1
Fn
User Logon user_name = Guest, password = adidas False 1
Fn
User Logon user_name = Guest, password = rotimi False 1
Fn
User Logon user_name = Guest, password = slayer False 1
Fn
User Logon user_name = Guest, password = wisdom False 1
Fn
User Logon user_name = Guest, password = praise False 1
Fn
User Logon user_name = Guest, password = zxcvbnm False 1
Fn
User Logon user_name = Guest, password = samuel False 1
Fn
User Logon user_name = Guest, password = mike False 1
Fn
User Logon user_name = Guest, password = dallas False 1
Fn
User Logon user_name = Guest, password = green False 1
Fn
User Logon user_name = Guest, password = testtest False 1
Fn
User Logon user_name = Guest, password = maverick False 1
Fn
User Logon user_name = Guest, password = onelove False 1
Fn
User Logon user_name = Guest, password = david False 1
Fn
User Logon user_name = Guest, password = mylove False 1
Fn
User Logon user_name = Guest, password = church False 1
Fn
User Logon user_name = Guest, password = friend False 1
Fn
User Logon user_name = Guest, password = god False 1
Fn
User Logon user_name = Guest, password = destiny False 1
Fn
User Logon user_name = Guest, password = none False 1
Fn
User Logon user_name = Guest, password = microsoft False 1
Fn
User Logon user_name = Guest, password = 222222 False 1
Fn
User Logon user_name = Guest, password = bubbles False 1
Fn
User Logon user_name = Guest, password = 11111111 False 1
Fn
User Logon user_name = Guest, password = cocacola False 1
Fn
User Logon user_name = Guest, password = jordan23 False 1
Fn
User Logon user_name = Guest, password = ilovegod False 1
Fn
User Logon user_name = Guest, password = football1 False 1
Fn
User Logon user_name = Guest, password = loving False 1
Fn
User Logon user_name = Guest, password = nathan False 1
Fn
User Logon user_name = Guest, password = emmanuel False 1
Fn
User Logon user_name = Guest, password = scooby False 1
Fn
User Logon user_name = Guest, password = fuckoff False 1
Fn
User Logon user_name = Guest, password = sammy False 1
Fn
User Logon user_name = Guest, password = maxwell False 1
Fn
User Logon user_name = Guest, password = jason False 1
Fn
User Logon user_name = Guest, password = john False 1
Fn
User Logon user_name = Guest, password = 1q2w3e4r False 1
Fn
User Logon user_name = Guest, password = baby False 1
Fn
User Logon user_name = Guest, password = red123 False 1
Fn
User Logon user_name = Guest, password = blabla False 1
Fn
User Logon user_name = Guest, password = prince False 1
Fn
User Logon user_name = Guest, password = qwert False 1
Fn
User Logon user_name = Guest, password = chelsea False 1
Fn
User Logon user_name = Guest, password = 55555 False 1
Fn
User Logon user_name = Guest, password = angel1 False 1
Fn
User Logon user_name = Guest, password = hardcore False 1
Fn
User Logon user_name = Guest, password = dexter False 1
Fn
User Logon user_name = Guest, password = saved False 1
Fn
User Logon user_name = Guest, password = 112233 False 1
Fn
User Logon user_name = Guest, password = hallo False 1
Fn
User Logon user_name = Guest, password = jasper False 1
Fn
User Logon user_name = Guest, password = danielle False 1
Fn
User Logon user_name = Guest, password = kitten False 1
Fn
User Logon user_name = Guest, password = cassie False 1
Fn
User Logon user_name = Guest, password = stella False 1
Fn
User Logon user_name = Guest, password = prayer False 1
Fn
User Lookup Privilege privilege = SeImpersonatePrivilege, luid = 29 True 1
Fn
User Lookup Privilege privilege = SeTcbPrivilege, luid = 7 True 1
Fn
User Lookup Privilege privilege = SeChangeNotifyPrivilege, luid = 23 True 1
Fn
User Lookup Privilege privilege = SeCreateTokenPrivilege, luid = 2 True 1
Fn
User Lookup Privilege privilege = SeBackupPrivilege, luid = 17 True 1
Fn
User Lookup Privilege privilege = SeRestorePrivilege, luid = 18 True 1
Fn
User Lookup Privilege privilege = SeIncreaseQuotaPrivilege, luid = 5 True 1
Fn
User Lookup Privilege privilege = SeAssignPrimaryTokenPrivilege, luid = 3 True 1
Fn
User Logon user_name = DefaultAccount, password = DefaultAccount False 1
Fn
User Logon user_name = DefaultAccount, password = defaultaccount False 1
Fn
User Lookup Privilege privilege = SeImpersonatePrivilege, luid = 29 True 1
Fn
For performance reasons, the remaining 9 entries are omitted.
The remaining entries can be found in glog.xml.
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image