VISACard_E_lottery_2016.doc
This report is generated from a file or URL submitted to this webservice on November 19th 2016 11:10:16 (UTC) and action script Heavy Anti-Evasion
Guest System: Windows 7 32 bit, Home Premium, 6.1 (build 7601), Service Pack 1, Office 2010 v14.0.4
Report generated by
Falcon Sandbox v5.40 © Hybrid Analysis
Incident Response
Risk Assessment
- Fingerprint
-
Reads the active computer name
Reads the cryptographic machine GUID - Evasive
- References security related windows services
- Spreading
- Opens the MountPointManager (often used to detect additional infection locations)
Indicators
Not all malicious and suspicious indicators are displayed. Get your own cloud service or the full version to view all details.
-
Malicious Indicators 2
-
Ransomware/Banking
-
Hides icons on the desktop
- details
-
"WINWORD.EXE" (Path: "HKCU\SOFTWARE\MICROSOFT\OFFICE\14.0\WORD\RESILIENCY\STARTUPITEMS"; Key: "*"H,2A2268003C0D00000400000000000000900000000100000088000000400043003A005C00550073006500720073005C0072004E0068006D00420063006C005C0041007000700044006100740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C00540065006D0070006C0061007400650073005C004E006F0072006D0061006C002E0064006F0074006D00000000000000
61025894,OPEN,HKCU,HKCU\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\COMMON\OPEN FIND\PLACES
61025917,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\OFFICE\14.0\COMMON\OPEN FIND\PLACES
61025938,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\COMMON\OPEN FIND
61025958,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\OFFICE\14.0\COMMON\OPEN FIND
61025978,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\COMMON\GENERAL
61026035,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER
61026052,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER
61026075,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER
61026090,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER
61026116,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER
61026131,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER
61026154,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER
61026170,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER
61026191,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER
61026207,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER
61026235,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\SHELLCOMPATIBILITY\APPLICATIONS\WINWORD.EXE
61026260,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\SHELLCOMPATIBILITY\APPLICATIONS\WINWORD.EXE\
61026283,QUERYVAL,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\SHELLCOMPATIBILITY\APPLICATIONS\WINWORD.EXE,VERSION,00000000010000002C000000310031002E002A003B00310030002E002A003B0039002E002A003B0038002E002A003B0037002E002A000000
61026294,QUERYVAL,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\SHELLCOMPATIBILITY\APPLICATIONS\WINWORD.EXE,VERSION,00000000010000002C000000310031002E002A003B00310030002E002A003B0039002E002A003B0038002E002A003B0037002E002A000000
61026844,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\SIDEBYSIDE
61027877,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\SIDEBYSIDE\ASSEMBLYSTORAGEROOTS
61028178,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER
61028197,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER
61028227,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\FOLDERDESCRIPTIONS
61028247,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\FOLDERDESCRIPTIONS\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}
61028273,QUERYVAL,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\FOLDERDESCRIPTIONS\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641},CATEGORY,00000000040000000400000004000000
61028283,QUERYVAL,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\FOLDERDESCRIPTIONS\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641},NAME,0000000001000000100000004400650073006B0074006F0070000000
61028302,QUERYVAL,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\FOLDERDESCRIPTIONS\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641},RELATIVEPATH,0000000001000000100000004400650073006B0074006F0070000000
61028315,QUERYVAL,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\FOLDERDESCRIPTIONS\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641},LOCALIZEDNAME,00000000020000005400000040002500530079007300740065006D0052006F006F00740025005C00730079007300740065006D00330032005C007300680065006C006C00330032002E0064006C006C002C002D00320031003700360039000000
61028329,QUERYVAL,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\FOLDERDESCRIPTIONS\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641},ICON,0000000002000000500000002500530079007300740065006D0052006F006F00740025005C00730079007300740065006D00330032005C0069006D006100670065007200650073002E0064006C006C002C002D003100380033000000
61028350,QUERYVAL,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\FOLDERDESCRIPTIONS\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641},ROAMABLE,00000000040000000400000001000000
61028359,QUERYVAL,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\FOLDERDESCRIPTIONS\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641},PRECREATE,00000000040000000400000001000000
61028369,QUERYVAL,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\FOLDERDESCRIPTIONS\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641},PUBLISHEXPANDEDPATH,00000000040000000400000001000000
61028378,QUERYVAL,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\FOLDERDESCRIPTIONS\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641},ATTRIBUTES,00000000040000000400000001000000
61028391,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\FOLDERDESCRIPTIONS\{B4BFCC3A-DB2C-424C-B029-7FE99A87C641}\PROPERTYBAG
61028457,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER
61028479,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\SESSIONINFO\1
61028503,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\SESSIONINFO\1\KNOWNFOLDERS
61028532,OPEN,HKU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000
61028544,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\USER SHELL FOLDERS
61028569,QUERYVAL,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\USER SHELL FOLDERS,DESKTOP,00000000020000002C00000025005500530045005200500052004F00460049004C00450025005C004400650073006B0074006F0070000000
61028638,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\KNOWNFOLDERSETTINGS
61028658,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\KNOWNFOLDERSETTINGS
61028707,QUERY,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES
61028716,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61028739,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61028760,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61028771,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61028795,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61028806,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61028829,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61028839,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61028861,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61028872,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61028894,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61028904,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61028926,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61028936,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61028960,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61028970,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61028992,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61029002,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61029025,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61029034,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61029057,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61029067,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61029089,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61029099,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61029125,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61029137,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61029159,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61029170,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61029190,QUERYVAL,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER,HIDEONDESKTOPPERUSER,0000000001000000020000000000
61029199,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61029209,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61029232,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61029243,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61029266,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61029276,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61029300,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61029309,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61029330,QUERYVAL,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER,PINTONAMESPACETREE,0000000001000000020000000000
61029339,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61029349,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61029375,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61029404,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\SHELLFOLDER
61029427,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\NONENUM
61029448,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\NONENUM
61029825,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\MOUNTPOINTS2\CPC\VOLUME
61029853,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\MOUNTPOINTS2\CPC\VOLUME\{8177F4E5-B53F-11E4-A9C2-806E6F6E6963}\
61029895,QUERYVAL,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\MOUNTPOINTS2\CPC\VOLUME\{8177F4E5-B53F-11E4-A9C2-806E6F6E6963},DATA,00000000030000005A050000000000000DF0ADBA41000000080000000000008400000000000000300000000000000000FF00E703FF00000016000000A0B6C2240440000001000000000000000000000000000000000000000000000000005C005C003F005C00530054004F005200410047004500230056006F006C0075006D00650023007B00380031003700370066003400650031002D0062003500330066002D0031003100650034002D0061003900630032002D003800300036006500360066003600650036003900360033007D002300300030003000300030003000300030003000360035003000300030003000300023007B00350033006600350036003300300064002D0062003600620066002D0031003100640030002D0039003400660032002D003000300061003000630039003100650066006200380062007D000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000005C005C003F005C0056006F006C0075006D0065007B00380031003700370066003400650035002D0062003500330066002D0031003100650034002D0061003900630032002D003800300036006500360066003600650036003900360033007D005C0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000004E005400460053000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF0000
61029977,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\MOUNTPOINTS2\CPC\VOLUME
61030001,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\MOUNTPOINTS2\CPC\VOLUME\{8177F4E5-B53F-11E4-A9C2-806E6F6E6963}\
61030033,QUERYVAL,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\MOUNTPOINTS2\CPC\VOLUME\{8177F4E5-B53F-11E4-A9C2-806E6F6E6963},GENERATION,00000000040000000400000001000000
61030083,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\MOUNTPOINTS2\CPC\VOLUME
61030107,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\MOUNTPOINTS2\CPC\VOLUME\{8177F4E5-B53F-11E4-A9C2-806E6F6E6963}\
61030139,QUERYVAL,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\MOUNTPOINTS2\CPC\VOLUME\{8177F4E5-B53F-11E4-A9C2-806E6F6E6963},GENERATION,00000000040000000400000001000000
61030151,QUERY,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES
61030158,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\DRIVE\SHELLEX\FOLDEREXTENSIONS
61030176,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\DRIVE\SHELLEX\FOLDEREXTENSIONS
61030201,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\DRIVE\SHELLEX\FOLDEREXTENSIONS
61030212,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\DRIVE\SHELLEX\FOLDEREXTENSIONS
61030232,QUERY,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES
61030239,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\DRIVE\SHELLEX\FOLDEREXTENSIONS\{FBEB8A05-BEEE-4442-804E-409D6C4515E9}
61030263,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\DRIVE\SHELLEX\FOLDEREXTENSIONS\{FBEB8A05-BEEE-4442-804E-409D6C4515E9}
61030283,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\DRIVE\SHELLEX\FOLDEREXTENSIONS\{FBEB8A05-BEEE-4442-804E-409D6C4515E9}
61030294,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\DRIVE\SHELLEX\FOLDEREXTENSIONS\{FBEB8A05-BEEE-4442-804E-409D6C4515E9}
61030319,QUERYVAL,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\DRIVE\SHELLEX\FOLDEREXTENSIONS\{FBEB8A05-BEEE-4442-804E-409D6C4515E9},DRIVEMASK,00000000040000000400000020000000
61030348,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\POLICIES\MICROSOFT\WINDOWS\EXPLORER
61030362,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\WINDOWS\EXPLORER
61030499,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES
61030528,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\COM3
61030539,QUERYVAL,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\COM3,COM+ENABLED,00000000040000000400000001000000
61035226,QUERY,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES
61035235,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}
61035257,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}
61035277,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}
61035289,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\TREATAS
61035310,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\TREATAS
61035327,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}
61035327,$STATUS,C0000023
61035334,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}
61035341,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}
61035353,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\PROGID
61035374,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\PROGID
61035391,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}
61035402,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}
61035421,QUERYVAL,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D},",0000000001000000300000004D0065006D006F007200790020004D006100700070006500640020004300610063006800650020004D00670072000000
61035433,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}
61035443,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}
61035462,QUERYVAL,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D},",0000000001000000300000004D0065006D006F007200790020004D006100700070006500640020004300610063006800650020004D00670072000000
61035474,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}
61035484,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\INPROCSERVER32
61035506,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\INPROCSERVER32
61035525,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\INPROCSERVER32
61035535,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\INPROCSERVER32
61035560,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\INPROCSERVER32
61035570,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\INPROCSERVER32
61035592,QUERYVAL,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\INPROCSERVER32,",0000000002000000440000002500530079007300740065006D0052006F006F00740025005C00730079007300740065006D00330032005C00700072006F0070007300790073002E0064006C006C000000
61035604,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\INPROCSERVER32
61035614,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\INPROCSERVER32
61035636,QUERYVAL,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\INPROCSERVER32,",0000000002000000440000002500530079007300740065006D0052006F006F00740025005C00730079007300740065006D00330032005C00700072006F0070007300790073002E0064006C006C000000
61035648,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\INPROCSERVER32
61035658,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\INPROCSERVER32
61035680,QUERYVAL,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\INPROCSERVER32,",0000000002000000440000002500530079007300740065006D0052006F006F00740025005C00730079007300740065006D00330032005C00700072006F0070007300790073002E0064006C006C000000
61035694,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\INPROCSERVER32
61035705,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\INPROCSERVER32
61035727,QUERYVAL,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\INPROCSERVER32,THREADINGMODEL,00000000010000000A00000042006F00740068000000
61035739,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}
61035749,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\INPROCHANDLER32
61035771,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\INPROCHANDLER32
61035788,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}
61035798,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\INPROCHANDLER
61035819,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\INPROCHANDLER
61035839,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\OLE
61035906,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES
61035921,QUERY,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES
61035929,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}
61035949,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}
61035965,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}
61035975,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\TREATAS
61035996,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{1F486A52-3CB1-48FD-8F50-B8DC300D9F9D}\TREATAS
61041454,OPEN,HKLM,\REGISTRY\MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\LSA\ACCESSPROVIDERS
61041477,QUERYVAL,HKLM,\REGISTRY\MACHINE\SYSTEM\CONTROLSET001\CONTROL\LSA\ACCESSPROVIDERS,MARTAEXTENSION,0000000001000000180000006E0074006D0061007200740061002E0064006C006C000000
61041488,QUERYVAL,HKLM,\REGISTRY\MACHINE\SYSTEM\CONTROLSET001\CONTROL\LSA\ACCESSPROVIDERS,MARTAEXTENSION,0000000001000000180000006E0074006D0061007200740061002E0064006C006C000000
61051253,OPEN,HKLM,\REGISTRY\MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\LDAP
61051272,QUERYVAL,HKLM,\REGISTRY\MACHINE\SYSTEM\CONTROLSET001\SERVICES\LDAP,LDAPCLIENTINTEGRITY,00000000040000000400000001000000
61051284,OPEN,HKLM,\REGISTRY\MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\LDAP
61051303,OPEN,HKLM,\REGISTRY\MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\LDAP
61051899,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER
61051918,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER
61051943,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\
61051964,QUERYVAL,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER,SHELLSTATE,000000000300000024000000240000003028000000000000000000000000000001000000120000000000000022000000
61051975,QUERYVAL,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER,SHELLSTATE,000000000300000024000000240000003028000000000000000000000000000001000000120000000000000022000000
61051989,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER
61052004,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER
61052028,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER
61052043,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER
61052065,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER
61052080,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER
61052102,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER
61052117,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER
61052139,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER
61052153,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\EXPLORER
61052175,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED
61052197,QUERYVAL,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED,HIDDEN,00000000040000000400000002000000
61052207,QUERYVAL,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED,SHOWCOMPCOLOR,00000000040000000400000001000000
61052216,QUERYVAL,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED,HIDEFILEEXT,00000000040000000400000001000000
61052225,QUERYVAL,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED,DONTPRETTYPATH,00000000040000000400000000000000
61052234,QUERYVAL,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED,SHOWINFOTIP,00000000040000000400000001000000
61052242,QUERYVAL,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED,HIDEICONS,00000000040000000400000000000000
61052251,QUERYVAL,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED,MAPNETDRVBTN,00000000040000000400000000000000
61052260,QUERYVAL,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED,WEBVIEW,00000000040000000400000001000000
61052270,QUERYVAL,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED,FILTER,00000000040000000400000000000000
61052283,QUERYVAL,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED,SEPARATEPROCESS,00000000040000000400000000000000
61052294,QUERYVAL,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED,AUTOCHECKSELECT,00000000040000000400000000000000
61052303,QUERYVAL,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED,ICONSONLY,00000000040000000400000000000000
61052312,QUERYVAL,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED,SHOWTYPEOVERLAY,00000000040000000400000001000000
61052333,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\SHELL\REGISTEREDAPPLICATIONS\URLASSOCIATIONS\DIRECTORY\OPENWITHPROGIDS
61052356,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\SHELL\ASSOCIATIONS\URLASSOCIATIONS\DIRECTORY
61052382,QUERY,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES
61052390,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\DIRECTORY
61052405,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\DIRECTORY
61052419,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\DIRECTORY
61052430,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\DIRECTORY\CURVER
61052446,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\DIRECTORY\CURVER
61052452,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\DIRECTORY
61052452,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\DIRECTORY
61052452,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\DIRECTORY\
61052452,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\DIRECTORY
61052452,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\DIRECTORY
61052452,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\DIRECTORY\
61052452,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\DIRECTORY
61052452,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\DIRECTORY\SHELLEX\ICONHANDLER
61052452,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\DIRECTORY\SHELLEX\ICONHANDLER
61052452,QUERY,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES
61052452,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\FOLDER
61052452,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\FOLDER
61052452,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\FOLDER
61052452,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\FOLDER\SHELLEX\ICONHANDLER
61052452,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\FOLDER\SHELLEX\ICONHANDLER
61052452,QUERY,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES
61052452,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\ALLFILESYSTEMOBJECTS
61052452,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\ALLFILESYSTEMOBJECTS
61052452,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\ALLFILESYSTEMOBJECTS
61052452,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\ALLFILESYSTEMOBJECTS\SHELLEX\ICONHANDLER
61052452,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\ALLFILESYSTEMOBJECTS\SHELLEX\ICONHANDLER
61052452,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\DIRECTORY
61052452,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\DIRECTORY
61052452,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\DIRECTORY
61052452,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\DIRECTORY\DOCOBJECT
61052452,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\DIRECTORY\DOCOBJECT
61052452,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\FOLDER
61052452,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\FOLDER
61052452,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\FOLDER
61052452,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\FOLDER\DOCOBJECT
61052452,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\FOLDER\DOCOBJECT
61052452,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\ALLFILESYSTEMOBJECTS
61052452,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\ALLFILESYSTEMOBJECTS
61052452,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\ALLFILESYSTEMOBJECTS
61052452,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\ALLFILESYSTEMOBJECTS\DOCOBJECT
61052452,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\ALLFILESYSTEMOBJECTS\DOCOBJECT
61052452,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\DIRECTORY
61052452,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\DIRECTORY
61052452,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\DIRECTORY
61052452,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\DIRECTORY\BROWSEINPLACE
61052452,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\DIRECTORY\BROWSEINPLACE
61052452,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\FOLDER
61052452,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\FOLDER
61052452,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\FOLDER
61052452,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\FOLDER\BROWSEINPLACE
61052452,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\FOLDER\BROWSEINPLACE
61052452,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\ALLFILESYSTEMOBJECTS
61052452,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\ALLFILESYSTEMOBJECTS
61052452,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\ALLFILESYSTEMOBJECTS
61052452,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\ALLFILESYSTEMOBJECTS\BROWSEINPLACE
61052452,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\ALLFILESYSTEMOBJECTS\BROWSEINPLACE
61052452,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\DIRECTORY
61052452,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\DIRECTORY\CLSID
61052452,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\DIRECTORY\CLSID
61052452,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\FOLDER
61052452,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\FOLDER\CLSID
61052452,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\FOLDER\CLSID
61052452,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\ALLFILESYSTEMOBJECTS
61052452,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\ALLFILESYSTEMOBJECTS\CLSID
61052452,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\ALLFILESYSTEMOBJECTS\CLSID
61052452,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\DIRECTORY
61052452,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\DIRECTORY
61052452,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\FOLDER
61052452,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\FOLDER
61052452,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\ALLFILESYSTEMOBJECTS
61052452,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\ALLFILESYSTEMOBJECTS
61052494,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\DIRECTORY
61052505,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\DIRECTORY
61052519,QUERYVAL,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\DIRECTORY,ALWAYSSHOWEXT,0000000001000000020000000000
61052528,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\DIRECTORY
61052538,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\DIRECTORY
61052554,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\FOLDER
61052564,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\FOLDER
61052579,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\ALLFILESYSTEMOBJECTS
61052589,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\ALLFILESYSTEMOBJECTS
61053260,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\OFFICE\14.0\COMMON\DRAWALERTS\FTP SITES
61053296,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\COMMON\OPEN FIND\PLACES
61053318,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\OFFICE\14.0\COMMON\OPEN FIND\PLACES
61053339,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\COMMON\OPEN FIND
61053359,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\OFFICE\14.0\COMMON\OPEN FIND
61069078,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\COMMON\OPEN FIND
61069105,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\OFFICE\14.0\COMMON\OPEN FIND
61077876,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\WORD\OPTIONS
61078070,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\OUTLOOK\SECURITY
61078093,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\OFFICE\14.0\OUTLOOK\SECURITY
61082846,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES
61082865,QUERY,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES
61082875,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\APPID\WINWORD.EXE
61082893,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\APPID\WINWORD.EXE
61082914,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\OLE\APPCOMPAT
61082932,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\OLE
61083659,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\CRYPTOGRAPHY\DEFAULTS\PROVIDER\MICROSOFT STRONG CRYPTOGRAPHIC PROVIDER
61083686,QUERYVAL,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\CRYPTOGRAPHY\DEFAULTS\PROVIDER\MICROSOFT STRONG CRYPTOGRAPHIC PROVIDER,TYPE,00000000040000000400000001000000
61083696,QUERYVAL,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\CRYPTOGRAPHY\DEFAULTS\PROVIDER\MICROSOFT STRONG CRYPTOGRAPHIC PROVIDER,IMAGE PATH,0000000001000000420000002500530079007300740065006D0052006F006F00740025005C00730079007300740065006D00330032005C0072007300610065006E0068002E0064006C006C000000
61083709,QUERYVAL,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\CRYPTOGRAPHY\DEFAULTS\PROVIDER\MICROSOFT STRONG CRYPTOGRAPHIC PROVIDER,IMAGE PATH,0000000001000000420000002500530079007300740065006D0052006F006F00740025005C00730079007300740065006D00330032005C0072007300610065006E0068002E0064006C006C000000
61083721,QUERYVAL,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\CRYPTOGRAPHY\DEFAULTS\PROVIDER\MICROSOFT STRONG CRYPTOGRAPHIC PROVIDER,IMAGE PATH,0000000001000000420000002500530079007300740065006D0052006F006F00740025005C00730079007300740065006D00330032005C0072007300610065006E0068002E0064006C006C000000
61083733,QUERYVAL,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\CRYPTOGRAPHY\DEFAULTS\PROVIDER\MICROSOFT STRONG CRYPTOGRAPHIC PROVIDER,IMAGE PATH,0000000001000000420000002500530079007300740065006D0052006F006F00740025005C00730079007300740065006D00330032005C0072007300610065006E0068002E0064006C006C000000
61086886,OPEN,HKLM,\REGISTRY\MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\LSA\FIPSALGORITHMPOLICY
61086905,QUERYVAL,HKLM,\REGISTRY\MACHINE\SYSTEM\CONTROLSET001\CONTROL\LSA\FIPSALGORITHMPOLICY,ENABLED,00000000040000000400000000000000
61086914,OPEN,HKLM,\REGISTRY\MACHINE\SYSTEM\CURRENTCONTROLSET\CONTROL\LSA
61086932,OPEN,HKLM,\REGISTRY\MACHINE\SYSTEM\CURRENTCONTROLSET\POLICIES\MICROSOFT\CRYPTOGRAPHY\CONFIGURATION
61086956,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\POLICIES\MICROSOFT\CRYPTOGRAPHY
61086980,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\CRYPTOGRAPHY
61086993,QUERYVAL,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\CRYPTOGRAPHY,MACHINEGUID,00000000010000004A000000650034003700630036003100640032002D0031006400610065002D0034003800300065002D0038003200370061002D006100650038006400370039003700360034003900640066000000
61087005,QUERYVAL,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\CRYPTOGRAPHY,MACHINEGUID,00000000010000004A000000650034003700630036003100640032002D0031006400610065002D0034003800300065002D0038003200370061002D006100650038006400370039003700360034003900640066000000
61087018,QUERYVAL,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\CRYPTOGRAPHY,MACHINEGUID,00000000010000004A000000650034003700630036003100640032002D0031006400610065002D0034003800300065002D0038003200370061002D006100650038006400370039003700360034003900640066000000
61087030,QUERYVAL,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\CRYPTOGRAPHY,MACHINEGUID,00000000010000004A000000650034003700630036003100640032002D0031006400610065002D0034003800300065002D0038003200370061002D006100650038006400370039003700360034003900640066000000
61087047,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\CRYPTOGRAPHY\OFFLOAD
61087099,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES
61087115,QUERY,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES
61087123,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\INTERFACE\{00000134-0000-0000-C000-000000000046}
61087144,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\INTERFACE\{00000134-0000-0000-C000-000000000046}
61087167,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\INTERFACE\{00000134-0000-0000-C000-000000000046}
61087177,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\INTERFACE\{00000134-0000-0000-C000-000000000046}\PROXYSTUBCLSID32
61087199,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\INTERFACE\{00000134-0000-0000-C000-000000000046}\PROXYSTUBCLSID32
61087218,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\INTERFACE\{00000134-0000-0000-C000-000000000046}\PROXYSTUBCLSID32
61087228,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\INTERFACE\{00000134-0000-0000-C000-000000000046}\PROXYSTUBCLSID32
61087252,QUERYVAL,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\INTERFACE\{00000134-0000-0000-C000-000000000046}\PROXYSTUBCLSID32,",00000000010000004E0000007B00300030003000300030003300320030002D0030003000300030002D0030003000300030002D0043003000300030002D003000300030003000300030003000300030003000340036007D000000
61087269,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\RPC\EXTENSIONS
61087281,QUERYVAL,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\RPC\EXTENSIONS,NDROLEEXTDLL,0000000002000000140000004F006C006500330032002E0064006C006C000000
61087306,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\RPC\EXTENSIONS
61087319,QUERYVAL,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\RPC\EXTENSIONS,REMOTERPCDLL,00000000020000002000000052007000630052007400520065006D006F00740065002E0064006C006C000000
61087661,OPEN,HKLM,\REGISTRY\MACHINE\SYSTEM\CURRENTCONTROLSET\SERVICES\BFE
61087901,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\SQMCLIENT\WINDOWS\DISABLEDPROCESSES\
61087924,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\SQMCLIENT\WINDOWS\DISABLEDSESSIONS\
61087941,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\SQMCLIENT\WINDOWS\DISABLEDSESSIONS\
61088249,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\COMMON\INTERNET
61088277,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\COMMON\INTERNET
61088301,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\COMMON\INTERNET
61088324,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\COMMON\INTERNET
61089408,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\WORD\OPTIONS
61090149,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\WORD\OPTIONS
61090479,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\COMMON\GENERAL
61096476,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED
61096506,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED
61096530,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED
61096552,QUERYVAL,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED,HIDEFILEEXT,00000000040000000400000001000000
61102776,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\COMMON\SECURITY
61102819,QUERY,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES
61102831,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}
61102875,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}
61102909,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}
61102925,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\TREATAS
61102970,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\TREATAS
61103002,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}
61103002,$STATUS,C0000023
61103012,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}
61103022,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}
61103038,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\PROGID
61103082,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\PROGID
61103115,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\PROGID
61103130,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\PROGID
61103172,QUERYVAL,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\PROGID,",0000000001000000300000004D00730078006D006C0032002E0053004100580058004D004C005200650061006400650072002E0036002E0030000000
61103192,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}
61103206,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\PROGID
61103248,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\PROGID
61103280,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\PROGID
61103294,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\PROGID
61103336,QUERYVAL,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\PROGID,",0000000001000000300000004D00730078006D006C0032002E0053004100580058004D004C005200650061006400650072002E0036002E0030000000
61103355,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}
61103369,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}
61103409,QUERYVAL,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5},",000000000100000026000000530041005800200058004D004C002000520065006100640065007200200036002E0030000000
61103424,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}
61103438,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}
61103477,QUERYVAL,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5},",000000000100000026000000530041005800200058004D004C002000520065006100640065007200200036002E0030000000
61103493,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}
61103507,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\INPROCSERVER32
61103552,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\INPROCSERVER32
61103588,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\INPROCSERVER32
61103602,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\INPROCSERVER32
61103651,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\INPROCSERVER32
61103665,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\INPROCSERVER32
61103711,QUERYVAL,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\INPROCSERVER32,",0000000002000000420000002500530079007300740065006D0052006F006F00740025005C00530079007300740065006D00330032005C006D00730078006D006C0036002E0064006C006C000000
61103728,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\INPROCSERVER32
61103742,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\INPROCSERVER32
61103788,QUERYVAL,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\INPROCSERVER32,",0000000002000000420000002500530079007300740065006D0052006F006F00740025005C00530079007300740065006D00330032005C006D00730078006D006C0036002E0064006C006C000000
61103806,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\INPROCSERVER32
61103819,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\INPROCSERVER32
61103865,QUERYVAL,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\INPROCSERVER32,",0000000002000000420000002500530079007300740065006D0052006F006F00740025005C00530079007300740065006D00330032005C006D00730078006D006C0036002E0064006C006C000000
61103883,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\INPROCSERVER32
61103897,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\INPROCSERVER32
61103942,QUERYVAL,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\INPROCSERVER32,THREADINGMODEL,00000000010000000A00000042006F00740068000000
61103958,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}
61103972,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\INPROCHANDLER32
61104019,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\INPROCHANDLER32
61104054,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}
61104068,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\INPROCHANDLER
61104113,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\INPROCHANDLER
61104212,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES
61104239,QUERY,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES
61104250,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}
61104291,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}
61104320,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}
61104334,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\TREATAS
61104378,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}\TREATAS
61104834,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\MSXML60
61104993,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\MSXML60
61105022,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\MSXML60
61105497,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\SECURITY
61105517,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\SECURITY
61105543,QUERY,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES
61105552,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID
61105568,QUERY,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID
61105575,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}
61105598,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}
61105614,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}
61105625,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0C-F192-11D4-A65F-0040963251E5}
61105797,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\COMMON\SECURITY
61105836,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\COMMON\OPENXMLFORMAT
61106272,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\MSXML60
61113426,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\WORD\OPTIONS
61113575,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\PUBLISHER\INTERNET
61113598,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\OFFICE\14.0\PUBLISHER\INTERNET
61113621,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\PUBLISHER\INTERNET
61113642,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\OFFICE\14.0\PUBLISHER\INTERNET
61113664,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\POWERPOINT\INTERNET
61113685,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\OFFICE\14.0\POWERPOINT\INTERNET
61113707,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\NETSCAPE\NETSCAPE NAVIGATOR
61113722,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\NETSCAPE\NETSCAPE NAVIGATOR GOLD
61113736,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\NETSCAPE\NETSCAPE NAVIGATOR
61113749,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\POWERPOINT\INTERNET
61113770,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\OFFICE\14.0\POWERPOINT\INTERNET
61113792,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\COMMON\INTERNET
61113816,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\COMMON\INTERNET
61113839,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\COMMON\INTERNET
61113863,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\COMMON\INTERNET
61113885,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\COMMON\INTERNET
61113908,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\WORD\INTERNET
61113928,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\OFFICE\14.0\WORD\INTERNET
61113947,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\POWERPOINT\INTERNET
61113968,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\OFFICE\14.0\POWERPOINT\INTERNET
61113989,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\POWERPOINT\INTERNET
61114010,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\OFFICE\14.0\POWERPOINT\INTERNET
61114031,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\COMMON\INTERNET
61114053,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\POWERPOINT\INTERNET
61114110,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\OFFICE\14.0\POWERPOINT\INTERNET
61114133,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\COMMON\INTERNET
61114156,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\COMMON\INTERNET
61114179,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\PUBLISHER\INTERNET
61114199,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\OFFICE\14.0\PUBLISHER\INTERNET
61114223,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\OFFICE\14.0\COMMON\INTERNET
61114241,QUERYVAL,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\OFFICE\14.0\COMMON\INTERNET,LOCATIONOFCOMPONENTS,0000000001000000020000000000
61114252,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\PUBLISHER\INTERNET
61114273,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\OFFICE\14.0\PUBLISHER\INTERNET
61114294,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\PUBLISHER\INTERNET
61114315,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\OFFICE\14.0\PUBLISHER\INTERNET
61114336,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\PUBLISHER\INTERNET
61114357,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\OFFICE\14.0\PUBLISHER\INTERNET
61114378,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\COMMON\INTERNET
61114405,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\COMMON\INTERNET
61114428,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\COMMON\INTERNET
61114453,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\WORD\INTERNET
61114474,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\OFFICE\14.0\WORD\INTERNET
61114494,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\COMMON\INTERNET
61121551,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\WORD\OPTIONS
61121901,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\WORD\OPTIONS
61122029,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\COMMON\INTERNET
61122056,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\COMMON\INTERNET
61122081,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\WORD\INTERNET
61122102,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\OFFICE\14.0\WORD\INTERNET
61122121,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\OFFICE\14.0\COMMON\INTERNET
61129470,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\SHARED TOOLS\PROOFING TOOLS
61129502,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\SHARED TOOLS\PROOFING TOOLS
61129771,QUERY,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES
61129781,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}
61129804,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}
61129824,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}
61129836,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}\TREATAS
61129857,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}\TREATAS
61129875,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}
61129875,$STATUS,C0000023
61129883,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}
61129890,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}
61129901,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}\PROGID
61129921,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}\PROGID
61129939,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}\PROGID
61129950,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}\PROGID
61129970,QUERYVAL,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}\PROGID,",00000000010000002E0000004D00730078006D006C0032002E004D00580058004D004C005700720069007400650072002E0036002E0030000000
61129985,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}
61129995,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}\PROGID
61130017,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}\PROGID
61130033,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}\PROGID
61130044,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}\PROGID
61130064,QUERYVAL,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}\PROGID,",00000000010000002E0000004D00730078006D006C0032002E004D00580058004D004C005700720069007400650072002E0036002E0030000000
61130076,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}
61130086,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}
61130106,QUERYVAL,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5},",0000000001000000200000004D00580058004D004C00570072006900740065007200200036002E0030000000
61130116,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}
61130126,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}
61130145,QUERYVAL,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5},",0000000001000000200000004D00580058004D004C00570072006900740065007200200036002E0030000000
61130155,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}
61130166,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}\INPROCSERVER32
61130187,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}\INPROCSERVER32
61130206,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}\INPROCSERVER32
61130217,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}\INPROCSERVER32
61130241,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}\INPROCSERVER32
61130251,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}\INPROCSERVER32
61130273,QUERYVAL,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}\INPROCSERVER32,",0000000002000000420000002500530079007300740065006D0052006F006F00740025005C00530079007300740065006D00330032005C006D00730078006D006C0036002E0064006C006C000000
61130285,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}\INPROCSERVER32
61130295,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}\INPROCSERVER32
61130316,QUERYVAL,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}\INPROCSERVER32,",0000000002000000420000002500530079007300740065006D0052006F006F00740025005C00530079007300740065006D00330032005C006D00730078006D006C0036002E0064006C006C000000
61130329,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}\INPROCSERVER32
61130344,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}\INPROCSERVER32
61130367,QUERYVAL,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}\INPROCSERVER32,",0000000002000000420000002500530079007300740065006D0052006F006F00740025005C00530079007300740065006D00330032005C006D00730078006D006C0036002E0064006C006C000000
61130379,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}\INPROCSERVER32
61130390,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}\INPROCSERVER32
61130412,QUERYVAL,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}\INPROCSERVER32,THREADINGMODEL,00000000010000000A00000042006F00740068000000
61130423,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}
61130434,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}\INPROCHANDLER32
61130455,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}\INPROCHANDLER32
61130472,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}
61130482,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}\INPROCHANDLER
61130503,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}\INPROCHANDLER
61130572,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES
61130587,QUERY,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES
61130595,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}
61130615,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}
61130631,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}
61130642,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}\TREATAS
61130662,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}\TREATAS
61130689,QUERY,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES
61130697,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID
61130712,QUERY,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID
61130719,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}
61130740,OPEN,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}
61130755,QUERY,HKCR,\REGISTRY\MACHINE\SOFTWARE\CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}
61130766,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000_CLASSES\CLSID\{88D96A0F-F192-11D4-A65F-0040963251E5}
61130875,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\POLICIES\MICROSOFT\SHARED TOOLS\PROOFING TOOLS
61130907,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\OLE
61130934,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\FOLDERDESCRIPTIONS
61130953,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\FOLDERDESCRIPTIONS\{352481E8-33BE-4251-BA85-6007CAEDCF9D}
61130979,QUERYVAL,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\FOLDERDESCRIPTIONS\{352481E8-33BE-4251-BA85-6007CAEDCF9D},CATEGORY,00000000040000000400000004000000
61130990,QUERYVAL,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\FOLDERDESCRIPTIONS\{352481E8-33BE-4251-BA85-6007CAEDCF9D},NAME,00000000010000000C000000430061006300680065000000
61131000,QUERYVAL,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\FOLDERDESCRIPTIONS\{352481E8-33BE-4251-BA85-6007CAEDCF9D},PARENTFOLDER,00000000010000004E0000007B00460031004200330032003700380035002D0036004600420041002D0034004600430046002D0039004400350035002D003700420038004500370046003100350037003000390031007D000000
61131017,QUERYVAL,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\FOLDERDESCRIPTIONS\{352481E8-33BE-4251-BA85-6007CAEDCF9D},RELATIVEPATH,0000000001000000560000004D006900630072006F0073006F00660074005C00570069006E0064006F00770073005C00540065006D0070006F007200610072007900200049006E007400650072006E00650074002000460069006C00650073000000
61131045,QUERYVAL,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\FOLDERDESCRIPTIONS\{352481E8-33BE-4251-BA85-6007CAEDCF9D},LOCALREDIRECTONLY,00000000040000000400000001000000
61131068,OPEN,HKLM,\REGISTRY\MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\FOLDERDESCRIPTIONS\{352481E8-33BE-4251-BA85-6007CAEDCF9D}\PROPERTYBAG
61131131,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\SESSIONINFO\1
61131154,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\SESSIONINFO\1\KNOWNFOLDERS
61131185,OPEN,HKU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000
61131197,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\USER SHELL FOLDERS
61131228,QUERYVAL,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\USER SHELL FOLDERS,CACHE,00000000020000008E00000025005500530045005200500052004F00460049004C00450025005C0041007000700044006100740061005C004C006F00630061006C005C004D006900630072006F0073006F00660074005C00570069006E0064006F00770073005C00540065006D0070006F007200610072007900200049006E007400650072006E00650074002000460069006C00650073000000
61137280,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\OFFICE\14.0\WORD
61137304,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\OFFICE\14.0\WORD\RESILIENCY
61137325,OPEN,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\OFFICE\14.0\WORD\RESILIENCY\STARTUPITEMS
61137347,DELETEVAL,HKCU,\REGISTRY\USER\S-1-5-21-4162757579-3804539371-4239455898-1000\SOFTWARE\MICROSOFT\OFFICE\14.0\WORD\RESILIENCY\STARTUPITEMS,*"H"; Value: "") - source
- Registry Access
- relevance
- 5/10
-
Hides icons on the desktop
-
System Security
-
References security related windows services
- details
-
"dWNjUK#[FQ%z)+zL bHN(4@g9gkE#X;Xa3"Tiu}2t"ycDv"
QTjll85Q#QQMs!M`t@0;9bfemcukYLpJG5eP!@h3;+" (Indicator: "bfe") - source
- File/Memory
- relevance
- 7/10
-
References security related windows services
-
Suspicious Indicators 8
-
Environment Awareness
-
Reads the active computer name
- details
- "WINWORD.EXE" (Path: "HKLM\SYSTEM\CONTROLSET001\CONTROL\COMPUTERNAME\ACTIVECOMPUTERNAME"; Key: "COMPUTERNAME")
- source
- Registry Access
- relevance
- 5/10
-
Reads the cryptographic machine GUID
- details
- "WINWORD.EXE" (Path: "HKLM\SOFTWARE\MICROSOFT\CRYPTOGRAPHY"; Key: "MACHINEGUID")
- source
- Registry Access
- relevance
- 10/10
-
Reads the active computer name
-
Installation/Persistance
-
Opens the MountPointManager (often used to detect additional infection locations)
- details
- "WINWORD.EXE" opened "MountPointManager"
- source
- API Call
- relevance
- 5/10
-
Opens the MountPointManager (often used to detect additional infection locations)
-
System Security
-
Hooks API calls
- details
-
"VariantClear@OLEAUT32.DLL" in "WINWORD.EXE"
"VariantChangeType@OLEAUT32.DLL" in "WINWORD.EXE"
"SysAllocStringByteLen@OLEAUT32.DLL" in "WINWORD.EXE"
"OleLoadFromStream@OLE32.DLL" in "WINWORD.EXE"
"SysFreeString@OLEAUT32.DLL" in "WINWORD.EXE" - source
- Hook Detection
- relevance
- 10/10
-
Queries sensitive IE security settings
- details
- "WINWORD.EXE" (Path: "HKCU\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SECURITY"; Key: "DISABLESECURITYSETTINGSCHECK")
- source
- Registry Access
- relevance
- 8/10
-
Hooks API calls
-
Unusual Characteristics
-
Contains embedded string with suspicious keywords
- details
- Found suspicious keyword "Lib" which indicates: "May run code from a DLL"
- source
- File/Memory
- relevance
- 10/10
-
Installs hooks/patches the running process
- details
-
"WINWORD.EXE" wrote bytes "e93655ccf1" to virtual address "0x756F3EAE" ("VariantClear@OLEAUT32.DLL")
"WINWORD.EXE" wrote bytes "30e8acd9" to virtual address "0x61F71F20" (part of module "GKWORD.DLL")
"WINWORD.EXE" wrote bytes "e509d423" to virtual address "0x623D42C4" (part of module "MSPROOF7.DLL")
"WINWORD.EXE" wrote bytes "7c6fcd48" to virtual address "0x69C8F530" (part of module "WWLIB.DLL")
"WINWORD.EXE" wrote bytes "bc1c18f4" to virtual address "0x61ED3408" (part of module "MSCSS7EN.DLL")
"WINWORD.EXE" wrote bytes "f574cd48" to virtual address "0x6990CA70" (part of module "GFX.DLL")
"WINWORD.EXE" wrote bytes "e92399cef1" to virtual address "0x756F5DEE" ("VariantChangeType@OLEAUT32.DLL")
"WINWORD.EXE" wrote bytes "e99e4861f0" to virtual address "0x76D63D01" ("SetUnhandledExceptionFilter@KERNEL32.DLL")
"WINWORD.EXE" wrote bytes "090987ac" to virtual address "0x626310AC" (part of module "MSPTLS.DLL")
"WINWORD.EXE" wrote bytes "e61311f4" to virtual address "0x61EA2A00" (part of module "CSS7DATA0009.DLL")
"WINWORD.EXE" wrote bytes "ac99f7f5" to virtual address "0x620F3408" (part of module "GKWORD.DLL")
"WINWORD.EXE" wrote bytes "c4cad57680bbd57652bad5769fbbd57608bbd57646ced5766138d676de2fd676d0d9d576000000001779a9764f91a9767f6fa976f4f7a97611f7a976f283a976857ea97600000000" to virtual address "0x6B041000" (part of module "MSIMG32.DLL")
"WINWORD.EXE" wrote bytes "e96033ccf1" to virtual address "0x756F4731" ("SysAllocStringByteLen@OLEAUT32.DLL")
"WINWORD.EXE" wrote bytes "2dd2b4d8" to virtual address "0x2FCE1B94" (part of module "WINWORD.EXE")
"WINWORD.EXE" wrote bytes "3461cd48" to virtual address "0x685D78E4" (part of module "OART.DLL")
"WINWORD.EXE" wrote bytes "99d8f1f5" to virtual address "0x6202EB90" (part of module "CSS7DATA000C.DLL")
"WINWORD.EXE" wrote bytes "614775af" to virtual address "0x62529904" (part of module "RICHED20.DLL")
"WINWORD.EXE" wrote bytes "e9c532daf0" to virtual address "0x76BB6143" ("OleLoadFromStream@OLE32.DLL")
"WINWORD.EXE" wrote bytes "e99a54cbf1" to virtual address "0x756F3E59" ("SysFreeString@OLEAUT32.DLL")
"WINWORD.EXE" wrote bytes "1a4941ac" to virtual address "0x675D0BA8" (part of module "MSO.DLL") - source
- Hook Detection
- relevance
- 10/10
-
Reads information about supported languages
- details
-
"WINWORD.EXE" (Path: "HKLM\SYSTEM\CONTROLSET001\CONTROL\NLS\LOCALE"; Key: "00000409")
"WINWORD.EXE" (Path: "HKLM\SYSTEM\CONTROLSET001\CONTROL\NLS\LOCALE"; Key: "00000401")
"WINWORD.EXE" (Path: "HKLM\SYSTEM\CONTROLSET001\CONTROL\NLS\LOCALE"; Key: "00000402")
"WINWORD.EXE" (Path: "HKLM\SYSTEM\CONTROLSET001\CONTROL\NLS\LOCALE"; Key: "00000403")
"WINWORD.EXE" (Path: "HKLM\SYSTEM\CONTROLSET001\CONTROL\NLS\LOCALE"; Key: "00000404")
"WINWORD.EXE" (Path: "HKLM\SYSTEM\CONTROLSET001\CONTROL\NLS\LOCALE"; Key: "00000405")
"WINWORD.EXE" (Path: "HKLM\SYSTEM\CONTROLSET001\CONTROL\NLS\LOCALE"; Key: "00000406")
"WINWORD.EXE" (Path: "HKLM\SYSTEM\CONTROLSET001\CONTROL\NLS\LOCALE"; Key: "00000407")
"WINWORD.EXE" (Path: "HKLM\SYSTEM\CONTROLSET001\CONTROL\NLS\LOCALE"; Key: "00000408")
"WINWORD.EXE" (Path: "HKLM\SYSTEM\CONTROLSET001\CONTROL\NLS\LOCALE"; Key: "0000040A")
"WINWORD.EXE" (Path: "HKLM\SYSTEM\CONTROLSET001\CONTROL\NLS\LOCALE"; Key: "0000040B")
"WINWORD.EXE" (Path: "HKLM\SYSTEM\CONTROLSET001\CONTROL\NLS\LOCALE"; Key: "0000040C")
"WINWORD.EXE" (Path: "HKLM\SYSTEM\CONTROLSET001\CONTROL\NLS\LOCALE"; Key: "0000040D")
"WINWORD.EXE" (Path: "HKLM\SYSTEM\CONTROLSET001\CONTROL\NLS\LOCALE"; Key: "0000040E")
"WINWORD.EXE" (Path: "HKLM\SYSTEM\CONTROLSET001\CONTROL\NLS\LOCALE"; Key: "0000040F")
"WINWORD.EXE" (Path: "HKLM\SYSTEM\CONTROLSET001\CONTROL\NLS\LOCALE"; Key: "00000410")
"WINWORD.EXE" (Path: "HKLM\SYSTEM\CONTROLSET001\CONTROL\NLS\LOCALE"; Key: "00000411")
"WINWORD.EXE" (Path: "HKLM\SYSTEM\CONTROLSET001\CONTROL\NLS\LOCALE"; Key: "00000412")
"WINWORD.EXE" (Path: "HKLM\SYSTEM\CONTROLSET001\CONTROL\NLS\LOCALE"; Key: "00000413") - source
- Registry Access
- relevance
- 3/10
-
Contains embedded string with suspicious keywords
-
Informative 7
-
External Systems
-
Sample was identified as clean by Antivirus engines
- details
- 0/54 Antivirus vendors marked sample as malicious (0% detection rate)
- source
- External System
- relevance
- 10/10
-
Sample was identified as clean by Antivirus engines
-
General
-
Creates a writable file in a temporary directory
- details
- "WINWORD.EXE" created file "%TEMP%\~DF98189FDE9F7B1AB8.TMP"
- source
- API Call
- relevance
- 1/10
-
Creates mutants
- details
-
"\Sessions\1\BaseNamedObjects\Local\10MU_ACBPIDS_S-1-5-5-0-61046"
"\Sessions\1\BaseNamedObjects\Global\552FFA80-3393-423d-8671-7BA046BB5906"
"\Sessions\1\BaseNamedObjects\Local\10MU_ACB10_S-1-5-5-0-61046"
"\Sessions\1\BaseNamedObjects\Local\ZonesCounterMutex"
"\Sessions\1\BaseNamedObjects\Local\ZoneAttributeCacheCounterMutex"
"\Sessions\1\BaseNamedObjects\Local\ZonesCacheCounterMutex"
"\Sessions\1\BaseNamedObjects\Local\ZonesLockedCacheCounterMutex"
"\Sessions\1\BaseNamedObjects\Global\MTX_MSO_Formal1_S-1-5-21-4162757579-3804539371-4239455898-1000"
"\Sessions\1\BaseNamedObjects\Global\MTX_MSO_AdHoc1_S-1-5-21-4162757579-3804539371-4239455898-1000" - source
- Created Mutant
- relevance
- 3/10
-
Loads rich edit control libraries
- details
- "WINWORD.EXE" loaded module "%COMMONPROGRAMFILES%\microsoft shared\OFFICE14\RICHED20.DLL" at 624E0000
- source
- Loaded Module
-
Creates a writable file in a temporary directory
-
Installation/Persistance
-
Dropped files
- details
-
"VISACard_E_lottery_2016.LNK" has type "MS Windows shortcut Item id list present Points to a file or directory Has Relative path Hidden Archive ctime=Sat Nov 19 10:11:41 2016 mtime=Sat Nov 19 10:11:41 2016 atime=Sat Nov 19 10:13:00 2016 length=555008 window=hide"
"index.dat" has type "data"
"~WRS{A4EDDCB2-FA35-4BD6-B4B8-77D5D696014C}.tmp" has type "FoxPro FPT blocks size 0 next free block index 218103808 1st used item "\375""
"~$SACard_E_lottery_2016.doc" has type "data"
"ExcludeDictionaryEN0409.lex" has type "Little-endian UTF-16 Unicode text with no line terminators"
"ExcludeDictionaryFR040c.lex" has type "Little-endian UTF-16 Unicode text with no line terminators" - source
- Binary File
- relevance
- 3/10
-
Touches files in the Windows directory
- details
-
"WINWORD.EXE" touched file "%WINDIR%\Globalization\Sorting\sortdefault.nls"
"WINWORD.EXE" touched file "%WINDIR%\Fonts\staticcache.dat"
"WINWORD.EXE" touched file "%WINDIR%\Microsoft.NET\Framework\v1.0.3705\clr.dll"
"WINWORD.EXE" touched file "%WINDIR%\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll"
"WINWORD.EXE" touched file "%WINDIR%\Microsoft.NET\Framework\v1.1.4322\clr.dll"
"WINWORD.EXE" touched file "%WINDIR%\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll"
"WINWORD.EXE" touched file "%WINDIR%\Microsoft.NET\Framework\v2.0.50727\clr.dll"
"WINWORD.EXE" touched file "%WINDIR%\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll"
"WINWORD.EXE" touched file "%WINDIR%\Microsoft.NET\Framework\v4.0.30319\clr.dll"
"WINWORD.EXE" touched file "%LOCALAPPDATA%\Microsoft\Windows\Caches"
"WINWORD.EXE" touched file "%LOCALAPPDATA%\Microsoft\Windows\Caches\cversions.1.db"
"WINWORD.EXE" touched file "%LOCALAPPDATA%\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000007.db"
"WINWORD.EXE" touched file "%WINDIR%\system32\rsaenh.dll"
"WINWORD.EXE" touched file "%WINDIR%\system32\en-US\KERNELBASE.dll.mui"
"WINWORD.EXE" touched file "%WINDIR%\System32\msxml6r.dll"
"WINWORD.EXE" touched file "%LOCALAPPDATA%\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{A4EDDCB2-FA35-4BD6-B4B8-77D5D696014C}.tmp"
"WINWORD.EXE" touched file "%WINDIR%\system32\en-US\MSCTF.dll.mui"
"WINWORD.EXE" touched file "%WINDIR%\System32"
"WINWORD.EXE" touched file "%LOCALAPPDATA%\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{18E508CA-36D8-4400-92BB-9475662DD351}.tmp" - source
- API Call
- relevance
- 7/10
-
Dropped files
-
Network Related
-
Found potential URL in binary/memory
- details
-
Pattern match: "http://schemas.openxmlformats.org/drawingml/2006/main"
Heuristic match: "E-mail: vis.acardclaim.centerverify@hotmail.com"
Pattern match: "6.HC/J\R"
Heuristic match: "F<BOl'rrHWh#QKqA(.pm"
Heuristic match: "Te|*=;:4QU 4g-FMes'bT#.Gp"
Pattern match: "0y.LBL/zAK:yW09=?uqc##"
Pattern match: "rsp.Xa/o#L"
Pattern match: "sGo.zj/bDTi1K0"
Heuristic match: "n|].ma"
Pattern match: "ww3.hdnux.com/photos/15/70/53/3640026/3/628x471.jpg#QQPK"
Pattern match: "Z.KHjz/a;X8v7:]`Mu"
Heuristic match: "J.t0ELzY.ve"
Heuristic match: "}%T.mo" - source
- File/Memory
- relevance
- 10/10
-
Found potential URL in binary/memory
File Details
VISACard_E_lottery_2016.doc
- Filename
- VISACard_E_lottery_2016.doc
- Size
- 542KiB (555008 bytes)
- Type
- doc office
- Description
- Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, Code page: 1252, Author: CHIDI, Template: Normal, Last Saved By: mS, Revision Number: 5, Name of Creating Application: Microsoft Office Word, Total Editing Time: 17:00, Create Time/Date: Mon Aug 1 20:45:00 2016, Last Saved Time/Date: Tue Nov 1 20:09:00 2016, Number of Pages: 3, Number of Words: 624, Number of Characters: 3559, Security: 0
- Architecture
- WINDOWS
- SHA256
- 1975a36f76abfc45b7acf2b87c8e24b6b611a648dce68d309f2972cfb8812a4a
- MD5
- 71a50f727969b0f5635125f0bc1ab6a5
- SHA1
- 442c8a45151d027e11831cb922cff45f81f7376d
Classification (TrID)
- 80.0% (.DOC) Microsoft Word document
- 20.0% (.) Generic OLE2 / Multistream Compound File
Screenshots
Loading content, please wait...
Hybrid Analysis
Tip: Click an analysed process below to view more details.
Analysed 1 process in total (System Resource Monitor).
- WINWORD.EXE /n "C:\VISACard_E_lottery_2016.doc" (PID: 3388)
Network Analysis
DNS Requests
No relevant DNS requests were made.
Contacted Hosts
No relevant hosts were contacted.
HTTP Traffic
No relevant HTTP requests were made.
Extracted Strings
Extracted Files
-
Informative 6
-
-
VISACard_E_lottery_2016.LNK
- Size
- 528B (528 bytes)
- Type
- MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Hidden, Archive, ctime=Sat Nov 19 10:11:41 2016, mtime=Sat Nov 19 10:11:41 2016, atime=Sat Nov 19 10:13:00 2016, length=555008, window=hide
- Runtime Process
- WINWORD.EXE (PID: 3388)
- MD5
- b554ad50f05a7a48c3cd77e24466fc27
- SHA1
- 53bf247450c9caf6c0ab4fbd9198f0bb17821349
- SHA256
- 2727b9d0bd4b6a9ea611529a0b956e902fbb86fed2c4fbbb8fe04291d887d7ca
-
index.dat
- Size
- 540B (540 bytes)
- Type
- data
- Runtime Process
- WINWORD.EXE (PID: 3388)
- MD5
- 302fc60212d356fb4d40a3c1583cc021
- SHA1
- 3d7d894eb4d2097f8d9f18709e97bd05772b4cd8
- SHA256
- 4eb67acb9831f7e444ec7c89d972031a0e0213fa6af45c84ac7c5304642cef95
-
ExcludeDictionaryEN0409.lex
- Size
- 2B (2 bytes)
- Type
- Little-endian UTF-16 Unicode text, with no line terminators
- Runtime Process
- WINWORD.EXE (PID: 3388)
- MD5
- f3b25701fe362ec84616a93a45ce9998
- SHA1
- d62636d8caec13f04e28442a0a6fa1afeb024bbb
- SHA256
- b3d510ef04275ca8e698e5b3cbb0ece3949ef9252f0cdc839e9ee347409a2209
-
ExcludeDictionaryFR040c.lex
- Size
- 2B (2 bytes)
- Type
- Little-endian UTF-16 Unicode text, with no line terminators
- Runtime Process
- WINWORD.EXE (PID: 3388)
- MD5
- f3b25701fe362ec84616a93a45ce9998
- SHA1
- d62636d8caec13f04e28442a0a6fa1afeb024bbb
- SHA256
- b3d510ef04275ca8e698e5b3cbb0ece3949ef9252f0cdc839e9ee347409a2209
-
~WRS{A4EDDCB2-FA35-4BD6-B4B8-77D5D696014C}.tmp
- Size
- 1KiB (1024 bytes)
- Type
- FoxPro FPT, blocks size 0, next free block index 218103808, 1st used item "\375"
- Runtime Process
- WINWORD.EXE (PID: 3388)
- MD5
- 5d4d94ee7e06bbb0af9584119797b23a
- SHA1
- dbb111419c704f116efa8e72471dd83e86e49677
- SHA256
- 4826c0d860af884d3343ca6460b0006a7a2ce7dbccc4d743208585d997cc5fd1
-
~$SACard_E_lottery_2016.doc
- Size
- 162B (162 bytes)
- Type
- data
- Runtime Process
- WINWORD.EXE (PID: 3388)
- MD5
- 791a9be2e0f666eb16d9f3cff051da41
- SHA1
- 273fa41fab9464a44873715d6b0cc09b1cd74848
- SHA256
- 518d2fc014f7babb21ceb7d8e1f7553d2663632c5e0654cb86b9d6db7b4b5097
-