iron25072014.exe is part of and developed by according to the iron25072014.exe version information.
iron25072014.exe's description is " "
iron25072014.exe is digitally signed by STMSetup.
iron25072014.exe is usually located in the 'c:\downloads\' folder.
Some of the anti-virus scanners at VirusTotal detected iron25072014.exe.
If you have additional information about the file, please share it with the FreeFixer users by posting a comment at the bottom of this page.
The following is the available information on iron25072014.exe:
| Property | Value |
|---|---|
| Product name | |
| Company name | |
| File description | |
| Comments | This installation was built with Inno Setup. |
| Legal copyright | |
| Product version | |
| File version |
Here's a screenshot of the file properties when displayed by Windows Explorer:
| Product name | .. |
| Company name | .. |
| File description | .. |
| Comments | This installation was built with Inn.. |
| Legal copyright | .. |
| Product version | |
| File version |
iron25072014.exe has a valid digital signature.
| Property | Value |
|---|---|
| Signer name | STMSetup |
| Certificate issuer name | COMODO Code Signing CA 2 |
| Certificate serial number | 4cc8af2c057fc32a3fa7f44eaadd7eea |
49 of the 73 anti-virus programs at VirusTotal detected the iron25072014.exe file. That's a 67% detection rate.
| Scanner | Detection Name |
|---|---|
| Alibaba | AdWare:Win32/InstallCore.9d3073f2 |
| Antiy-AVL | GrayWare[Adware]/Win32.InstallCore.genb |
| APEX | Malicious |
| Avast | Win32:Adware-gen [Adw] |
| AVG | Win32:Adware-gen [Adw] |
| Avira | PUA/InstallCore.Gen9 |
| Bkav | W32.HfsAdware.F829 |
| CAT-QuickHeal | PUA.Stmsetup.Gen |
| Comodo | Application.Win32.InstallCore.DIS@5j5psu |
| CrowdStrike | win/malicious_confidence_100% (D) |
| Cylance | Unsafe |
| Cyren | W32/A-6c5f2e7b!Eldorado |
| DrWeb | Trojan.InstallCore.1903 |
| Emsisoft | Application.InstallCore (A) |
| Endgame | malicious (high confidence) |
| ESET-NOD32 | Win32/InstallCore.Gen.A potentially unwanted |
| F-Prot | W32/A-6c5f2e7b!Eldorado |
| F-Secure | PotentialRisk.PUA/InstallCore.Gen9 |
| FireEye | Generic.mg.8a8092df66056fb7 |
| Fortinet | Riskware/InstallCore |
| GData | Win32.Adware.InstallCore.FQ |
| Ikarus | PUA.InstallCore |
| Invincea | heuristic |
| Jiangmin | Trojan.Heur2.ce |
| K7AntiVirus | Unwanted-Program ( 004a9d551 ) |
| K7GW | Unwanted-Program ( 004a9d551 ) |
| Kaspersky | not-a-virus:HEUR:AdWare.Win32.DealPly.gen |
| Malwarebytes | PUP.Optional.InstallCore |
| MAX | malware (ai score=99) |
| MaxSecure | Trojan.Malware.4653826.susgen |
| McAfee | Artemis!8A8092DF6605 |
| McAfee-GW-Edition | Artemis |
| Microsoft | PUA:Win32/InstallCore |
| NANO-Antivirus | Virus.Win32.Gen.ccmw |
| Qihoo-360 | Win32/Virus.Adware.f22 |
| Rising | PUF.InstallCore!1.AB2C (CLASSIC) |
| SentinelOne | DFI - Malicious PE |
| Sophos | Install Core Click run software (PUA) |
| Symantec | PUA.InstallCore |
| Tencent | Win32.Adware.Vosteran.Ecke |
| TrendMicro | ADW_InstaCore |
| TrendMicro-HouseCall | ADW_InstaCore |
| VBA32 | Malware-Cryptor.InstallCore.gen |
| VIPRE | InstallCore (fs) |
| ViRobot | Adware.Installcore.718888 |
| Webroot | Pua.Adware.Gen |
| Yandex | PUA.InstallCore! |
| Zillya | Adware.AddLyricsCRT.Win32.618 |
| ZoneAlarm | not-a-virus:AdWare.Win32.DealPly.heur |
The following information was gathered by executing the file inside Cuckoo Sandbox.
Successfully executed process in sandbox.
{
"file_created": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A8B9.log",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\ProgressBar.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_tb.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\ie6_main.css",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\sponsored.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Resume_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_wi.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close_Hover.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\BG.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Quick_Specs.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Loader.gif",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Pause_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\button-bg.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\main.css",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg2.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Icon_Generic.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\progress-bar.css",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\bootstrap_37556.html",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\checkbox.css",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg-corner.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\form.bmp.Mask",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\csshover3.htc",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\TR.locale",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button_Hover.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button_Hover.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\button.css",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\browse.css",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Progress.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\EN.locale",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A82C.log"
],
"directory_created": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\",
"C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\"
],
"dll_loaded": [
"IEFRAME.dll",
"C:\\Windows\\System32\\mswsock.dll",
"urlmon.dll",
"mshtml.dll",
"apphelp.dll",
"gdi32.dll",
"DNSAPI.dll",
"SHELL32.dll",
"kernel32.dll",
"UxTheme.dll",
"oleaut32.dll",
"C:\\Windows\\system32\\ole32.dll",
"dwmapi.dll",
"C:\\Windows\\system32\\napinsp.dll",
"ImgUtil.dll",
"ntmarta.dll",
"URLMON.DLL",
"C:\\Windows\\system32\\Msimtf.dll",
"API-MS-WIN-Service-Management-L1-1-0.dll",
"VERSION.dll",
"C:\\Windows\\syswow64\\MSCTF.dll",
"KERNEL32.DLL",
"API-MS-Win-Core-LocalRegistry-L1-1-0.dll",
"OLEAUT32.DLL",
"RASMAN.DLL",
"IPHLPAPI.DLL",
"advapi32.dll",
"comctl32",
"ole32.dll",
"comdlg32.dll",
"API-MS-WIN-Service-winsvc-L1-1-0.dll",
"olepro32.dll",
"rtutils.dll",
"version.dll",
"C:\\Windows\\SysWOW64\\oleaut32.dll",
"wininet.dll",
"ADVAPI32.dll",
"OLEAUT32.dll",
"C:\\Windows\\system32\\pnrpnsp.dll",
"DHCPCSVC.DLL",
"C:\\Windows\\System32\\winrnr.dll",
"API-MS-Win-Security-SDDL-L1-1-0.dll",
"comctl32.dll",
"WININET.dll",
"Kernel32",
"SXS.DLL",
"MLANG.dll",
"Kernel32.dll",
"powrprof.dll",
"shell32.dll",
"rpcrt4.dll",
"SETUPAPI.dll",
"WS2_32.dll",
"user32.dll"
],
"file_opened": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A8B9.log",
"C:\\",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\ProgressBar.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_tb.png",
"C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Internet Explorer\\MSIMGSIZ.DAT",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\ie6_main.css",
"C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches\\cversions.1.db",
"C:\\Users\\cuck\\AppData\\Local\\Temp",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\sponsored.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Resume_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_wi.png",
"C:\\Users\\cuck\\AppData",
"C:\\Windows\\SysWOW64\\ieframe.dll",
"C:\\Users\\cuck\\AppData\\Local",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close_Hover.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\BG.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Quick_Specs.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Loader.gif",
"C:\\Users",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Pause_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\button-bg.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\main.css",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg2.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Icon_Generic.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\progress-bar.css",
"\\\\?\\pipe\\0K1C1T1I1E1C1F1N1C1T1H_TEST",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\checkbox.css",
"C:\\Users\\desktop.ini",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg-corner.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\form.bmp.Mask",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\csshover3.htc",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\TR.locale",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button_Hover.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\bootstrap_37556.html",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button_Hover.png",
"C:\\Windows\\Globalization\\Sorting\\sortdefault.nls",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\button.css",
"C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches\\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000004.db",
"C:\\Users\\cuck",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\browse.css",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Progress.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\EN.locale",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A82C.log"
],
"command_line": [
"\"C:\\Users\\cuck\\AppData\\Local\\Temp\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin\" \/_ShowProgress \/PrTxt:TG9hZGluZy4uLg=="
],
"connects_host": [
"rp.kralprogramcdn.com",
"info.kralprogramcdn.com"
],
"regkey_opened": [
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/pjpeg\\Bits",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows NT\\DnsClient",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/tiff\\Bits",
"HKEY_CLASSES_ROOT\\Directory",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer\\Main",
"HKEY_CLASSES_ROOT\\PROTOCOLS\\Name-Space Handler\\about\\",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_PROTOCOL_LOCKDOWN",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_IEDDE_REGISTER_URLECHO",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Settings",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\DxTrans",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Blocked",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_BROWSER_EMULATION",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\PROTOCOLS\\Handler\\about",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced",
"HKEY_CURRENT_USER\\SOFTWARE\\Classes\\PROTOCOLS\\Filter\\text\/html",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_IPERSISTMONIKER_LOAD_REDIRECTED_URL_KB976425",
"HKEY_CURRENT_USER\\Software\\Policies",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\DocObject",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder",
"HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\LayoutIcon\\0409\\0000041d",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\KnownClasses",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\PageSetup",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows NT\\Rpc",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_IGNORE_POLICIES_ZONEMAP_IF_ESC_ENABLED_KB918915",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Styles",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\ShellEx\\IconHandler",
"HKEY_CLASSES_ROOT\\MIME\\Database\\Content Type",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_ZONES_CHECK_ZONEMAP_POLICY_KB941001",
"HKEY_CURRENT_USER\\Interface\\{2A1C9EB2-DF62-4154-B800-63278FCB8037}",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\Clsid",
"HKEY_CURRENT_USER\\Keyboard Layout\\Toggle",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocHandler",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\TravelLog",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{55272A00-42CB-11CE-8135-00AA004BB851}\\ProxyStubClsid32",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Ftp",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\",
"HKEY_CLASSES_ROOT\\Drive\\shellex\\FolderExtensions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_IEDDE_REGISTER_PROTOCOL",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_PROTOCOL_LOCKDOWN",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Ftp",
"HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\LSA\\AccessProviders",
"HKEY_CLASSES_ROOT\\.png",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/jpeg\\Bits",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/x-png",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer",
"HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\(Default)",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_ZONE_ELEVATION",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International",
"HKEY_CURRENT_USER\\Software\\Borland\\Delphi\\Locales",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Low Rights",
"HKEY_CLASSES_ROOT\\.css",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Services",
"HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\Tcpip\\Parameters",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\MediaTypeClass",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_ACTIVEX_INACTIVATE_MODE_REMOVAL_REVERT",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Services",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer\\Zoom",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_MIME_SNIFFING",
"HKEY_CURRENT_USER\\Software\\Microsoft\\windows\\CurrentVersion\\Internet Settings\\Zones",
"HKEY_CURRENT_USER\\Software\\Borland\\Locales",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\MenuExt",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\ActiveDesktop",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Recovery",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Domains\\",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer",
"HKEY_LOCAL_MACHINE\\Software",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B}\\1.1\\0",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Url History",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.html\\Clsid",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html\\UserChoice",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SAFE_BINDTOOBJECT",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\ActiveX Compatibility",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B}\\1.1\\0\\win32",
"HKEY_CLASSES_ROOT\\PROTOCOLS\\Name-Space Handler\\",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\(Default)",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\Explorer",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SCRIPTURL_MITIGATION",
"HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\DnsCache\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_BINARY_CALLER_SERVICE_PROVIDER",
"HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\ShellEx\\IconHandler",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Ranges\\",
"HKEY_CLASSES_ROOT\\CLSID\\{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}\\InProcServer32",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/png\\Bits",
"HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\DirectSwitchHotkeys",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\IETld",
"HKEY_LOCAL_MACHINE\\System\\Setup",
"HKEY_CLASSES_ROOT\\SystemFileAssociations\\.html",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SHOW_FAILED_CONNECT_CONTENT_KB942615",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_READ_ZONE_STRINGS_FROM_REGISTRY",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\4",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\3",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\2",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\1",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\0",
"HKEY_CLASSES_ROOT\\FirefoxURL-E7CF176E110C211B\\shell\\open\\command",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_ADDITIONAL_IE8_MEMORY_CLEANUP",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\BrowseInPlace",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer\\BrowserEmulation",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\Feature_Enable_Compat_Logging",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{2A1C9EB2-DF62-4154-B800-63278FCB8037}\\ProxyStubClsid32",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Activities",
"HKEY_CURRENT_USER\\Interface\\{BCD1DE7E-2DB1-418B-B047-4A74E101F8C1}",
"HKEY_CLASSES_ROOT\\SystemFileAssociations\\document",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Setup",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_RESTRICT_FILEDOWNLOAD",
"HKEY_CLASSES_ROOT\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}",
"HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocServer32",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocHandler32",
"HKEY_CLASSES_ROOT\\PROTOCOLS\\Name-Space Handler\\*\\",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Nls\\CodePage",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Url History",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SUBDOWNLOAD_LOCKDOWN",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_IGNORE_LEADING_FILE_SEPARATOR_IN_URI_KB933105",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\International\\Scripts",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Accepted Documents",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{BCD1DE7E-2DB1-418B-B047-4A74E101F8C1}\\ProxyStubClsid32",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Ranges\\",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_RESTRICTED_ZONE_WHEN_FILE_NOT_FOUND",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer\\Restrictions",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\TravelLog",
"HKEY_LOCAL_MACHINE\\Software\\Policies",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer\\Control Panel",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_RESTRICT_FILEDOWNLOAD",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html\\(Default)",
"HKEY_CURRENT_USER\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\OleAut",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Rpc",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProtocolDefaults\\",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer\\Infodelivery\\Restrictions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MIME_HANDLING",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\3",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\2",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{8A40A45D-055C-4B62-ABD7-6D613E2CEAEC}\\ProxyStubClsid32",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\0",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\4",
"HKEY_CLASSES_ROOT\\CLSID\\{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}\\ShellFolder",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Internet Explorer\\Main",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Internet Explorer\\BrowserEmulation",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_BROWSER_EMULATION",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Ratings",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_DOCUMENT_COMPATIBLE_MODE",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\1",
"HKEY_CLASSES_ROOT\\.html\\OpenWithProgids",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_WEBOC_DOCUMENT_ZOOM",
"HKEY_CLASSES_ROOT\\FirefoxHTML-E7CF176E110C211B",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{26656EAA-54EB-4E6F-8F85-4F0EF901A406}\\ProxyStubClsid32",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Internet Explorer",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_UNC_SAVEDFILECHECK",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\Clsid",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html\\OpenWithProgids",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\ShellEx\\IconHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_SSLUX",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\MenuExt\\%s",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Domains\\",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_BLOCK_LMZ_IMG",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Scripts\\3",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Internet Explorer\\Zoom",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_CUSTOM_IMAGE_MIME_TYPES_KB910561",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Security",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Associations\\UrlAssociations\\Directory",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.html\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\DxTrans",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_XSSFILTER",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Zoom",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_UNC_SAVEDFILECHECK",
"HKEY_CURRENT_USER\\Software\\Microsoft\\windows\\CurrentVersion\\Internet Settings\\Wpad",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B}\\1.1",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer\\Main\\FeatureControl",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\System\\DNSClient",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Security\\Adv AddrBar Spoof Detection",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4",
"HKEY_CURRENT_USER\\Interface\\{8A40A45D-055C-4B62-ABD7-6D613E2CEAEC}",
"HKEY_CURRENT_USER\\Interface\\{55272A00-42CB-11CE-8135-00AA004BB851}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\TreatAs",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Services",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap",
"HKEY_CLASSES_ROOT\\Folder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CLASSES_ROOT\\.gif",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\Progid",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Security\\Adv AddrBar Spoof Detection",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_SAFE_BINDTOOBJECT",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/x-jg\\Bits",
"HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\LDAP",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Associations\\UrlAssociations\\http\\UserChoice",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Internet Explorer\\Main\\FeatureControl",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{3050f819-98b5-11cf-bb82-00aa00bdce0b}",
"HKEY_CURRENT_USER\\Software",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.html\\ShellEx\\IconHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\Compatibility\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\MAIN",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\COM3",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\PROTOCOLS\\Filter\\text\/html",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\ShellEx\\IconHandler",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\iexplore.exe",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Scripts",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_USE_IETLDLIST_FOR_DOMAIN_DETERMINATION",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_LEGACY_DLCONTROL_BEHAVIORS",
"HKEY_CLASSES_ROOT\\AllFilesystemObjects",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\DocObject",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{3050f4e1-98b5-11cf-bb82-00aa00bdce0b}",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MIME_SNIFFING",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Zoom",
"HKEY_CURRENT_USER\\TypeLib",
"HKEY_CURRENT_USER\\SOFTWARE\\Classes\\PROTOCOLS\\Handler\\about",
"HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\CurVer",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Domains\\",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_SSLUX",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}",
"HKEY_CLASSES_ROOT\\.html",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\",
"HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\DocObject",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Security\\Floppy Access",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/x-icon\\Bits",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\Clsid",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MANAGE_SCRIPT_CIRCULAR_REFS",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Internet Explorer\\Infodelivery\\Restrictions",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing\\RASMANCS",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Domains\\",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\Explorer",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{3050f4f5-98B5-11CF-BB82-00AA00BDCE0B}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/x-wmf\\Bits",
"HKEY_CURRENT_USER\\Software\\Microsoft\\windows\\CurrentVersion\\Internet Settings\\Connections",
"HKEY_CLASSES_ROOT\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.html\\DocObject",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ShellCompatibility\\Applications\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\CurVer",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\4",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\0",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\1",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\2",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\3",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_ZONES_DEFAULT_DRIVE_INTRANET_KB941000",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{3697C5FA-60DD-4B56-92D4-74A569205C16}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ShellCompatibility\\Objects\\{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/x-png\\Bits",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\DocObject",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Url History",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Low Rights",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\Shell\\RegisteredApplications\\UrlAssociations\\Directory\\OpenWithProgids",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\ActiveX Compatibility\\{F414C260-6AC0-11CF-B6D1-00AA00BBBB58}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_Cross_Domain_Redirect_Mitigation",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\Progid",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/bmp\\Bits",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Blocked",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/gif\\Bits",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap",
"HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\Clsid",
"HKEY_CURRENT_USER\\Interface\\{26656EAA-54EB-4E6F-8F85-4F0EF901A406}",
"HKEY_CLASSES_ROOT\\htmlfile",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Activities",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Activities",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Url History",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Ranges\\",
"HKEY_LOCAL_MACHINE\\Software\\Borland\\Locales",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\crypt32",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MSHTML_AUTOLOAD_IEFRAME",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B}",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Internet Explorer\\Restrictions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Version Vector",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_RESPECT_OBJECTSAFETY_POLICY_KB905547",
"HKEY_CLASSES_ROOT\\PROTOCOLS\\Name-Space Handler\\file\\",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_ZONE_ELEVATION",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\BrowseInPlace",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_BROWSER_EMULATION",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_MIME_HANDLING"
],
"resolves_host": [
"wpad",
"cuckpc"
],
"file_written": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A8B9.log",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\ProgressBar.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_tb.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\ie6_main.css",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\sponsored.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Resume_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_wi.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close_Hover.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\BG.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Quick_Specs.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Loader.gif",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Pause_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\button-bg.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\main.css",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg2.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Icon_Generic.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\progress-bar.css",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\bootstrap_37556.html",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\checkbox.css",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg-corner.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\form.bmp.Mask",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\csshover3.htc",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\TR.locale",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button_Hover.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button_Hover.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\button.css",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\browse.css",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Progress.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\EN.locale",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A82C.log"
],
"regkey_deleted": [
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName"
],
"file_deleted": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A8B9.log",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\bootstrap_37556.html",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A82C.log"
],
"file_exists": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\",
"C:\\",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\ProgressBar.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_tb.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Microsoft",
"C:\\Users\\cuck\\",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\sponsored.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\main.css:Zone.Identifier",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Resume_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_wi.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\",
"C:\\Users\\",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\BG.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Quick_Specs.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Loader.gif",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Pause_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\main.css",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\progress-bar.css",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\bootstrap_37556.html",
"C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Internet Explorer",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\progress-bar.css:Zone.Identifier",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\bootstrap_37556.html:Zone.Identifier",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Progress.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\",
"C:\\Users\\cuck\\AppData\\"
],
"mutex": [
"MSIMGSIZECacheMutex",
"Local\\ZonesCounterMutex",
"Local\\ZonesLockedCacheCounterMutex",
"Local\\ZoneAttributeCacheCounterMutex",
"IESQMMUTEX_0_208",
"Local\\ZonesCacheCounterMutex"
],
"file_failed": [
"\\\\?\\pipe\\0K1C1T1I1E1C1F1N1C1T1H",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\bootstrap_37556.html"
],
"guid": [
"{275c23e2-3747-11d0-9fea-00aa003f8646}",
"{6a01fda0-30df-11d0-b724-00aa006c1a01}",
"{30c3b080-30fb-11d0-b724-00aa006c1a01}",
"{dccfc164-2b38-11d2-b7ec-00c04f8f5d9a}",
"{25336920-03f9-11cf-8fd0-00aa00686f13}",
"{a3ccedf7-2de2-11d0-86f4-00a0c913f750}",
"{dcb00c01-570f-4a9b-8d69-199fdba5723b}",
"{5762f2a7-4658-4c7a-a4ac-bdabfe154e0d}",
"{4ef17940-30e0-11d0-b724-00aa006c1a01}",
"{6e89f8e2-9a2a-4797-9b91-41146bdf0e7b}",
"{00000146-0000-0000-c000-000000000046}",
"{6c736dc1-ab0d-11d0-a2ad-00a0c90f27e8}",
"{d0074ffd-570f-4a9b-8d69-199fdba5723b}",
"{a3ccedf3-2de2-11d0-86f4-00a0c913f750}",
"{f414c260-6ac0-11cf-b6d1-00aa00bbbb58}",
"{000214e6-0000-0000-c000-000000000046}",
"{00000001-0000-0000-c000-000000000046}",
"{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}",
"{d9e89500-30fa-11d0-b724-00aa006c1a01}",
"{00000323-0000-0000-c000-000000000046}",
"{e7e4bc40-e76a-11ce-a9bb-00aa004ae837}",
"{8856f961-340a-11d0-a96b-00c04fd705a2}",
"{dcb00000-570f-4a9b-8d69-199fdba5723b}",
"{50d5107a-d278-4871-8989-f4ceaaf59cfc}",
"{bb1a2ae1-a4f9-11cf-8f20-00805f2cd064}",
"{a47979d2-c419-11d9-a5b4-001185ad2b89}",
"{00000112-0000-0000-c000-000000000046}",
"{6c736db1-bd94-11d0-8a23-00aa00b58e10}",
"{3050f406-98b5-11cf-bb82-00aa00bdce0b}",
"{08c0e040-62d1-11d1-9326-0060b067b86e}",
"{e569bde7-a8dc-47f3-893f-fd2b31b3eefd}"
],
"file_read": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\ProgressBar.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_tb.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\sponsored.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Resume_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_wi.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\bootstrap_37556.html",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\BG.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Quick_Specs.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Loader.gif",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Pause_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\main.css",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\progress-bar.css",
"C:\\Windows\\SysWOW64\\ieframe.dll",
"C:\\Users\\desktop.ini",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A8B9.log",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Progress.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\EN.locale",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A82C.log"
],
"regkey_read": [
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\EnableLUA",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Rpc\\MaxRpcSize",
"HKEY_CURRENT_USER\\.html\\Content Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Version Vector\\VML",
"HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001\\ProfileImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoSetFolders",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoFileUrl",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Scripts\\3\\IEFontSize",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SUBDOWNLOAD_LOCKDOWN\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASAPI32\\FileDirectory",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\AutoProxyDetectType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Domain",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\DisableImprovedZoneCheck",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CreateUriCacheSize",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideIcons",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\RecommendedLevel",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\AutoCheckSelect",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\MinLevel",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\Attributes",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyEnable",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\Icon",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\UrlEncoding",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.gif\\Content Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\EnableConsoleTracing",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\DisableCachingOfSSLPages",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\XDomainRequest",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsAliasedNotifications",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Display Inline Images",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\MinLevel",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Zoom\\ZoomDisabled",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\Flags",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\PROTOCOLS\\Handler\\about\\CLSID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\DocObject",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CoInternetCombineIUriCacheSize",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASAPI32\\EnableFileTracing",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\IsTextPlainHonored",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/x-png\\Image Filter CLSID",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Scripts\\3\\IEFixedFontName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\Show image placeholders",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}\\InProcServer32\\LoadWithoutCOM",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\DontPrettyPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\AllowFileCLSIDJunctions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}\\InProcServer32\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_ZONE_ELEVATION\\*",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Low Rights\\ProtectedModeOffForAllZones",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.html\\AlwaysShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_LEGACY_DLCONTROL_BEHAVIORS\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{2A1C9EB2-DF62-4154-B800-63278FCB8037}\\ProxyStubClsid32\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\FileTracingMask",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\SmoothScroll",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Use Stylesheets",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\Flags",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CodePage\\950",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CoInternetCombineIUriCacheSize",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\2106",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\1201",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\TabProcGrowth",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\IETld\\IETldDllVersionLow",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\DevicePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\SpecialFoldersCacheSize",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowTypeOverlay",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Always Use My Font Size",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Data",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideFileExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocServer32\\InprocServer32",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/jpeg\\Bits\\0",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Enable AutoImageResize",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\IETld\\IETldDllVersionHigh",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\2500",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\CurrentLevel",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.html\\NeverShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{8A40A45D-055C-4B62-ABD7-6D613E2CEAEC}\\ProxyStubClsid32\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoWebView",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.css\\Content Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\2000",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}\\Enable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_UNC_SAVEDFILECHECK\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\AcceptLanguage",
"HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SystemSetupInProgress",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FrameTabWindow",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\RecommendedLevel",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SourcePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/pjpeg\\Bits\\0",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\RestrictedAttributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseOldHostResolutionOrder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\2700",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\ProgramData",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\NeverShowExt",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowInfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_LEGACY_DLCONTROL_BEHAVIORS\\*",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Move System Caret",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B}\\1.1\\0\\win32\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\AdminTabProcs",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\(Default)",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\SessionMerging",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/x-wmf\\Bits\\0",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\RecommendedLevel",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocServer32\\ThreadingModel",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Anchor Color Visited",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\AlwaysShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SSLUX\\*",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\SeparateProcess",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\SecuritySafe",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Locale\\00000409",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MIME_SNIFFING\\*",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\SpecialFoldersCacheSize",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.html\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoCommonGroups",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\IETld\\IETldVersionHigh",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\PinToNameSpaceTree",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\COM3\\COM+Enabled",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsFORPARSING",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\DisableCachingOfSSLPages",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\DOMStorage",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\2500",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\2000",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\UrlEncoding",
"HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\AlwaysShowExt",
"HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\\*",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Hostname",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowCompColor",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\IEXPLORE.EXE\\(Default)",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\MiscFlags",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Services\\SelectionActivityButtonDisable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoPropertiesRecycleBin",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\QueryForInfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\AccessProviders\\MartaExtension",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoPropertiesMyComputer",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\UseHR",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\DOMStorage",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\SmartDithering",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\SessionMerging",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\2500",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\Print_Background",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellState",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Force Offscreen Composition",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_BLOCK_LMZ_IMG\\*",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CoInternetCombineIUriCacheSize",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\UrlEncoding",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\Icon",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Disable Script Debugger",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\1400",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\XMLHTTP",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\CurrentLevel",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\NeverShowExt",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\DriveMask",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Generation",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\CurrentLevel",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SAFE_BINDTOOBJECT\\*",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\RtfConverterFlags",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\FileDirectory",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoControlPanel",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_ZONE_ELEVATION\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\UseClearType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SSLUX\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\2500",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\Flags",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Play_Animations",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_BROWSER_EMULATION\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Associations\\UrlAssociations\\http\\UserChoice\\Progid",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FrameTabWindow",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Use Anchor Hover Color",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Default_CodePage",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\IETld\\IETldVersionLow",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Scripts\\Default_IEFontSizePrivate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASAPI32\\EnableConsoleTracing",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MIME_SNIFFING\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html\\UserChoice\\Progid",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_RESTRICT_FILEDOWNLOAD\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Scripts\\3\\IEFontSizePrivate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\SpecialFoldersCacheSize",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Filter",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Anchor Color",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/x-png\\Bits\\0",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsFORDISPLAY",
"HKEY_CURRENT_USER\\.html\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\CTF\\EnableAnchorContext",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Generation",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoInternetIcon",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Data",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\No3DBorder",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Print_Background",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Url History\\DaysToKeep",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\MapNetDriveVerbs",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} {000214E6-0000-0000-C000-000000000046} 0xFFFF",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\DefaultConnectionSettings",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\2106",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\XDomainRequest",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crypt32\\DebugHeapFlags",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\MaxFileSize",
"HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Layout Hotkey",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\CurrentLevel",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Disable Visited Hyperlinks",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_PROTOCOL_LOCKDOWN\\*",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\MinLevel",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\MinLevel",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\DontShowSuperHidden",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Version Vector\\WindowsEdition",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.html\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASAPI32\\MaxFileSize",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Expand Alt Text",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Play_Background_Sounds",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Display Inline Videos",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_XSSFILTER\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASAPI32\\ConsoleTracingMask",
"HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\NeverShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\DisableCachingOfSSLPages",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\EnableFileTracing",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideFolderVerbs",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_RESTRICT_FILEDOWNLOAD\\*",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoNetCrawling",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Q300829",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\TabProcGrowth",
"HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\OOBEInProgress",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CreateUriCacheSize",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideInWebView",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\Display Inline Videos",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\NoProtectedModeBanner",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\CallForAttributes",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AutoRecover",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\ConsoleTracingMask",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\No3DBorder",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\WpadLastNetwork",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragDelay",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\AdminTabProcs",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CreateUriCacheSize",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Always Use My Font Face",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\EnablePunycode",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.png\\Content Type",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\2106",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\NavigationDelay",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Cryptography\\MachineGuid",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HasNavigationEnum",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\2500",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\DocObject",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\2500",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\RecommendedLevel",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowSuperHidden",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\AppData",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\EnablePunycode",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MSHTML_AUTOLOAD_IEFRAME\\*",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoFileMenu",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\CurrentLevel",
"HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Language Hotkey",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\SmartDithering",
"HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Hotkey",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SAFE_BINDTOOBJECT\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseHostnameAsAlias",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\NoNetCrawling",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_XSSFILTER\\*",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\AutoDetect",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Anchor Underline",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASAPI32\\FileTracingMask",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MIME_HANDLING\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Page_Transitions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{26656EAA-54EB-4E6F-8F85-4F0EF901A406}\\ProxyStubClsid32\\(Default)",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\WarnOnIntranet",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Language Groups\\1",
"HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\DocObject",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Use_DlgBox_Colors",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MIME_HANDLING\\*",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Version Vector\\IE",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsUniversalDelegate",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\SpecialFoldersCacheSize",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\QueryForOverlay",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CoInternetCombineIUriCacheSize",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Hidden",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\ClassicShell",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_PROTOCOL_LOCKDOWN\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsParseDisplayName",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\WebView",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{55272A00-42CB-11CE-8135-00AA004BB851}\\ProxyStubClsid32\\(Default)",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\EnablePunycode",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Allow Programmatic Cut_Copy_Paste",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\2700",
"HKEY_CURRENT_USER\\Software\\Microsoft\\FTP\\Use Web Based FTP",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\2500",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{BCD1DE7E-2DB1-418B-B047-4A74E101F8C1}\\ProxyStubClsid32\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\MachineGuid",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\Page_Transitions",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\IconsOnly",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\160A",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.html\\DocObject",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\2500",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\DisableScriptDebuggerIE",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FrameMerging",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\Flags",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\LdapClientIntegrity",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Security\\DisableSecuritySettingsCheck",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Always Use My Colors",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Anchor Color Hover",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragScrollInterval",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\SeparateProcess",
"HKEY_CURRENT_USER\\FirefoxURL-E7CF176E110C211B\\shell\\open\\command\\(Default)",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragScrollInset",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\RecommendedLevel",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\DocObject",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Cleanup HTCs",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SUBDOWNLOAD_LOCKDOWN\\*",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_UNC_SAVEDFILECHECK\\*",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragScrollDelay",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/bmp\\Bits\\0",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\WarnOnIntranet",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocServer32\\(Default)",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CreateUriCacheSize",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\WarnOnIntranet",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\ComputerName\\ActiveComputerName\\ComputerName",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\SmoothScroll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_BROWSER_EMULATION\\*",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\UseDropHandler",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Show image placeholders",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\1201",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\NoFileFolderJunction",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MSHTML_AUTOLOAD_IEFRAME\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Security\\DisableSecuritySettingsCheck",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\MinLevel",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/png\\Bits\\0",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FrameMerging",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Security_HKLM_only",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_BLOCK_LMZ_IMG\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/gif\\Bits\\0",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\EnablePunycode",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\PageSetup\\Print_Background",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\MapNetDrvBtn",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\Flags",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\UseThemes",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Scripts\\3\\IEPropFontName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideOnDesktopPerUser",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\NeverShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\CEIPEnable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoSimpleStartMenu",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\Enable AutoImageResize",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\BrowseInPlace",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\CSS_Compat",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\160A"
],
"directory_enumerated": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Quick_Specs.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\system.js",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_tb.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Network\\Connections\\Pbk\\rasphone.pbk",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Resume_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\compatibility.js",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\wizard.js",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\i18n.js",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\package.js",
"C:\\Windows\\System32\\ras\\*.pbk",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\tray.js",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\script\\main.js",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_wi.png",
"C:\\Users\\cuck\\AppData",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\BG.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\form.js",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\installer.js",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Loader.gif",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\logicBox.js",
"C:\\Users",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\menu.js",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\webBrowser.js",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\main.css",
"C:\\ProgramData\\Microsoft\\Network\\Connections\\Pbk\\rasphone.pbk",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\progress-bar.css",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\bootstrap_37556.html",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\libs\\idp.js",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\utils.js",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\ProgressBar.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\ui\\progressBar.js",
"C:\\Users\\cuck\\AppData\\Local",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\sponsored.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Pause_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\debug.js",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Network\\Connections\\Pbk\\*.pbk",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\script\\flow.js",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\libs\\json2.js",
"C:\\Users\\cuck",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\eventListener.js",
"C:\\ProgramData\\Microsoft\\Network\\Connections\\Pbk\\*.pbk",
"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Progress.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\adManager.js",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\application.js"
],
"regkey_written": [
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\EnableConsoleTracing",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadDecisionReason",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadDecision",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadNetworkName",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} {000214E6-0000-0000-C000-000000000046} 0xFFFF",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\EnableFileTracing",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\DefaultConnectionSettings",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\MaxFileSize",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\FileTracingMask",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadDecisionTime",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\WpadLastNetwork",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\FileDirectory",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\ConsoleTracingMask"
]
}[
{
"yara": [],
"sha1": "51eac62cf77a0b88a3e9cb9ee6f85def21fd4bcf",
"name": "14e064857751b23d_progress.png",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Progress.png",
"type": "PNG image data, 4 x 10, 8-bit\/color RGB, non-interlaced",
"sha256": "14e064857751b23da7bbe40861ef4caf99b2496227507b8e3108fbac6d901f75",
"urls": [],
"crc32": "E727EE98",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/14e064857751b23d_progress.png",
"ssdeep": null,
"size": 104,
"sha512": "046ec179571d239bfb2d51be9837f96d9afebf2e5db77bba0f4a25ce8716d37581a3f9753bd2dbb04c47711699a9d93987bceb71df0b8becf8c577d660320069",
"pids": [
2436
],
"md5": "35a600a752d3074501de31a516860499"
},
{
"yara": [],
"sha1": "489ec909c854bc2944413509a930986f1cc0b330",
"name": "34225cce5a307b69_0294A8B9.log",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A8B9.log",
"type": "ASCII text, with no line terminators",
"sha256": "34225cce5a307b690e9499ac20e6f2b621a8a95276a89692ccb3bb792970cc3d",
"urls": [],
"crc32": "3C5D5EB3",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/34225cce5a307b69_0294A8B9.log",
"ssdeep": null,
"size": 8,
"sha512": "264194d460f12ff484b3296b77e43d60669cd82418d83187cfd74e8e36fc2a839d466613ca4d968de31913c30b130e1b4d8fce55868a8690230d16966c7a2890",
"pids": [
2436
],
"md5": "0fbe6ac9c58283dad6a51aa9d21f3c02"
},
{
"yara": [],
"sha1": "d73b3bc67c9fe124768697cee7eec84c2b1eee4f",
"name": "b28db98f2a6b06b6_close_hover.png",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close_Hover.png",
"type": "PNG image data, 17 x 16, 8-bit\/color RGBA, non-interlaced",
"sha256": "b28db98f2a6b06b6783b8fca6aabdcb89234d5bd4306fa71711988dba1fc71ea",
"urls": [],
"crc32": "4F170BAB",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/b28db98f2a6b06b6_close_hover.png",
"ssdeep": null,
"size": 207,
"sha512": "511de8d97853457a37f89550f4b283ed69c05efdb7ce63657bc53b4e37ddf357577738be92da4bcd736d9c3c181c5ffc50b890c8cd5aa27099a87acf2c600fad",
"pids": [
2436
],
"md5": "f5bdb3cabdc15580d97fa94aa3397c08"
},
{
"yara": [],
"sha1": "8652c46e2c3b32be118f3d9bcf30c3f000e11f0c",
"name": "a0ff54eac40a24b1_0294A82C.log",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A82C.log",
"type": "ASCII text, with no line terminators",
"sha256": "a0ff54eac40a24b1731bac4bb9678725115435c605d40047454009d1dd1d88bd",
"urls": [],
"crc32": "A3B2BF67",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/a0ff54eac40a24b1_0294A82C.log",
"ssdeep": null,
"size": 8,
"sha512": "bc263e0be2364d275f815c858ffcc75ccc1f4ca8eae6f27b98b6a26bd339a93b05e4325393a07268b1017485bf2bd2541f0ffd610b5ff4ae32909c004879e9d8",
"pids": [
2436
],
"md5": "58b3f2790b9c6c88146492066bf49431"
},
{
"yara": [],
"sha1": "7563da7fa8845e65111e092fbc49be2c93a9f781",
"name": "cf67489e041886a0_bg.png",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\BG.png",
"type": "PNG image data, 646 x 504, 8-bit\/color RGB, non-interlaced",
"sha256": "cf67489e041886a05568013927922bbae7e93f69a3597b92888ac4fadf8b8c7c",
"urls": [],
"crc32": "0B310A6D",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/cf67489e041886a0_bg.png",
"ssdeep": null,
"size": 3207,
"sha512": "9bd1bada0549e10b8afa1bc4aa6218e3c10fdac7063d9ad4fc4e6ca70f9e842533e27697522ae0d1d848d2903c5ab2265d22f7685e612c7c425393dbf24e31c0",
"pids": [
2436
],
"md5": "17285e115a289af21e95910c957bbabc"
},
{
"yara": [],
"sha1": "d141a79feb407506709f051e55c55438a12fd3b4",
"name": "7bf800336671204d_pause_button.png",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Pause_Button.png",
"type": "PNG image data, 21 x 21, 8-bit\/color RGBA, non-interlaced",
"sha256": "7bf800336671204de36b7d1f6ceffdff830040f51d21bc44f220f68d72cf492b",
"urls": [],
"crc32": "AC31F777",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/7bf800336671204d_pause_button.png",
"ssdeep": null,
"size": 577,
"sha512": "3222cb5772a4e9b20de253914c0856c7e6383567df68fcf287801f6f79248f65957515e7ec4a44db1fbe910afeae8ca3349295c4bdf03df6aabde36f2aaa6b5e",
"pids": [
2436
],
"md5": "84b37cb510f50c8fea812eb308d3f03f"
},
{
"yara": [],
"sha1": "13807a10369f7ff9ab3f9aba18135bccb98bec2d",
"name": "974cd89e64bdaa85_progress-bar.css",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\progress-bar.css",
"type": "ASCII text, with CRLF line terminators",
"sha256": "974cd89e64bdaa85bf36ed2a50af266d245d781a8139f5b45d7c55a0b0841dda",
"urls": [],
"crc32": "AF154B27",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/974cd89e64bdaa85_progress-bar.css",
"ssdeep": null,
"size": 506,
"sha512": "0d4e54d2ffe96ccf548097f7812e3608537b4dae9687816983fddfb73223c196159cc6a39fcdc000784c79b2ced878efbc7a5b5f6e057973bf25b128124510df",
"pids": [
2436
],
"md5": "5335f1c12201b5f7cf5f8b4f5692e3d1"
},
{
"yara": [],
"sha1": "347f69357e225ab59d41a8dafe0732663a7e8c7e",
"name": "ab4eeb3ea1eef4e8_progress-bg2.png",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg2.png",
"type": "PNG image data, 20 x 26, 8-bit colormap, non-interlaced",
"sha256": "ab4eeb3ea1eef4e84cb61eccb0ba0998b32108d70b3902df3619f4d9393f74c3",
"urls": [],
"crc32": "80C216FB",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/ab4eeb3ea1eef4e8_progress-bg2.png",
"ssdeep": null,
"size": 978,
"sha512": "187b2103e7cf438840aa9bcbfde0800b1e8592eb6abf1d70367334a1969d21986154f34472f302512bf4971b29ed55500b2ad9d6d1ced3ae23ddacc5b7c61a00",
"pids": [
2436
],
"md5": "b582d9a67bfe77d523ba825fd0b9dae3"
},
{
"yara": [],
"sha1": "1fb34409373b6ce2abee20d60947f1357f30e248",
"name": "c1cf449536bc2778_progress-bg.png",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg.png",
"type": "PNG image data, 19 x 22, 8-bit colormap, non-interlaced",
"sha256": "c1cf449536bc2778e27348e45f0f53d04c284109199fb7a9af7a61016b91f8bc",
"urls": [],
"crc32": "81EF803E",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/c1cf449536bc2778_progress-bg.png",
"ssdeep": null,
"size": 1105,
"sha512": "1b213f089da5502986da85f21673a522b36ceb4aec26bb1dffa809c58511056602cc0b99ab21ab206e2466928be0cdee7c7a95b39dc1183d8cfb529a22fe07c8",
"pids": [
2436
],
"md5": "e9f12f92a9eeb8ebe911080721446687"
},
{
"yara": [],
"sha1": "a4bd01f828454f3619a815dbe5423b181ec4051c",
"name": "f076773a6e3ae0f1_bootstrap_37556.html",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\bootstrap_37556.html",
"type": "HTML document, ASCII text, with no line terminators",
"sha256": "f076773a6e3ae0f1cee3c69232779a1aaaf05202db472040c0c8ea4a70af173a",
"urls": [],
"crc32": "CB024DFD",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/f076773a6e3ae0f1_bootstrap_37556.html",
"ssdeep": null,
"size": 156,
"sha512": "965c10d2aa5312602153338da873e8866d2782e0cf633befe5a552b770e08abf47a4d2e007cdef7010c212ebcb9fefea5610c41c7ed1553440eaeab7ddd72daa",
"pids": [
2436
],
"md5": "1ea9e5b417811379e874ad4870d5c51a"
},
{
"yara": [],
"sha1": "4b6876c6655cb3732a2218f89c9f170a32a820e7",
"name": "83f15163a379cb5f_en.locale",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\EN.locale",
"type": "HTML document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators",
"sha256": "83f15163a379cb5f085e514406d4a40590a90594daf9d980d9ef455537f252b6",
"urls": [],
"crc32": "F035B9A2",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/83f15163a379cb5f_en.locale",
"ssdeep": null,
"size": 4038,
"sha512": "e8cac92ababf18f9e3bcb329d6c4f57f28ebb5bbb808de43c3145b5366a1d3ce9543db7c1dacbea5abcadbbe21d108435004b316b32903712fc540ac7895f48f",
"pids": [
2436
],
"md5": "5e2dde2c7d9c154bd3b1f6fd019e0ded"
},
{
"yara": [],
"sha1": "1d7757aebc836cf75b00c106741eb58a4f14fed5",
"name": "86f2539351f57318_grey_button_hover.png",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button_Hover.png",
"type": "PNG image data, 162 x 39, 8-bit\/color RGBA, non-interlaced",
"sha256": "86f2539351f57318c65dc9936f49dee19a261540095e045b9c4c95be76cae143",
"urls": [],
"crc32": "1219B740",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/86f2539351f57318_grey_button_hover.png",
"ssdeep": null,
"size": 947,
"sha512": "5d36e234672c61bd34809f105e05e95a4b13e3cda199884fb59c8bb629c80c0fb7b3f5b99df6df7dc310d48a87d39a6612e0ac3de79cd466eca5b423b75d3d8e",
"pids": [
2436
],
"md5": "c92d77a8e40e884934d5e1ef355a3b82"
},
{
"yara": [],
"sha1": "787aeda3eee8053705fb208a6b399b8340820b82",
"name": "6e6b964fd79b4a34_quick_specs.png",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Quick_Specs.png",
"type": "PNG image data, 588 x 121, 2-bit colormap, non-interlaced",
"sha256": "6e6b964fd79b4a3461f128e2ed145b9b641d108b8616695f36387661cae995bb",
"urls": [],
"crc32": "1DB62899",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/6e6b964fd79b4a34_quick_specs.png",
"ssdeep": null,
"size": 221,
"sha512": "0159aca0c2a49393fd91acd4b6819217e67f8fd01e220297eb3e0fdd8132fad794fc317f5cc5e2b761d4123da71478b97df776908de6740eb6d54187c6c00754",
"pids": [
2436
],
"md5": "07cd59b954e8495ad6cd6a7c11d2de86"
},
{
"yara": [],
"sha1": "8bd2699352da87d4d7c5d5c4698a0f90b2b6408d",
"name": "63d6bd8e3e52c266_color_button_hover.png",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button_Hover.png",
"type": "PNG image data, 162 x 39, 8-bit\/color RGBA, non-interlaced",
"sha256": "63d6bd8e3e52c2665fbc1480eb2b27630b3c144e190d8cd5b094fc715d140e37",
"urls": [],
"crc32": "86342109",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/63d6bd8e3e52c266_color_button_hover.png",
"ssdeep": null,
"size": 1642,
"sha512": "f1d59b28f11a24d8587cd2b0b0b09493e27d145aecfc6bef44adf0a7e453603e55c92f7ad41ec9208cb559a481eefa75814eca9052fadec9e4cae77bb2d4822a",
"pids": [
2436
],
"md5": "507eb0a50680b1f332858f8547b8bf6e"
},
{
"yara": [],
"sha1": "233d056e36c35e752e8f7a4f5492e012ac7f5d58",
"name": "5ef48a8c8c3771b4_browse.css",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\browse.css",
"type": "ASCII text, with CRLF line terminators",
"sha256": "5ef48a8c8c3771b4f233314d50dd3b5afdcd99dd4b74a9745c8fe7b22207056d",
"urls": [],
"crc32": "49459553",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/5ef48a8c8c3771b4_browse.css",
"ssdeep": null,
"size": 337,
"sha512": "a62f805768d8aab4a773a2d5b480ad71e5b88b94af9eed8a7855caee0bfbcfce8a0bbad5de07a3b918f1da18f8e67ff961be575c000b64ce7ef5bee9292d2407",
"pids": [
2436
],
"md5": "6009d6e864f60aea980a9df94c1f7e1c"
},
{
"yara": [],
"sha1": "bf228a3af2fd2e1c90eb9fa28c305ec2e94c837b",
"name": "98def3a2f0343a87_tr.locale",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\TR.locale",
"type": "HTML document, UTF-8 Unicode text, with very long lines, with CRLF line terminators",
"sha256": "98def3a2f0343a87af3fa60b54476ebdec5ef805d4250c1df263604baf076d80",
"urls": [],
"crc32": "FEA8DEA5",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/98def3a2f0343a87_tr.locale",
"ssdeep": null,
"size": 4351,
"sha512": "6b020c74b238433a6fb5034353f69a3a8ee04f96367f83eba0835c5936830b3a73e1c402468bb9145e3489bc35f1617c48bd2f05d6a07559320bc3274270861b",
"pids": [
2436
],
"md5": "a9d0bfabe018ced0aaa315dcaeb68ff7"
},
{
"yara": [],
"sha1": "2075181a18827b789a9e85b116b192250e72b991",
"name": "ffe7f4a3405c31af_color_button.png",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button.png",
"type": "PNG image data, 162 x 39, 8-bit\/color RGBA, non-interlaced",
"sha256": "ffe7f4a3405c31afecb32c66609bcab022d6ddf7ff6de3c6560166cc42037943",
"urls": [],
"crc32": "D1E263C0",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/ffe7f4a3405c31af_color_button.png",
"ssdeep": null,
"size": 1157,
"sha512": "03e785062c31a5aa8570a8d210be2d47c396b4a067a869a3dd876b147a0cf499bbc6c3a8b1424937cec693707fdfa543965bb5500e44284b6a5000470bc4342f",
"pids": [
2436
],
"md5": "c706108c7982dc4bad4accd00dbd4743"
},
{
"yara": [],
"sha1": "3a9a1ba234e613e5f808c3ffeda05a10a5dafe00",
"name": "8d46eb0c60043dcb_sponsored.png",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\sponsored.png",
"type": "PNG image data, 137 x 40, 8-bit\/color RGBA, non-interlaced",
"sha256": "8d46eb0c60043dcb7d79ab3d0525148fc901764620c02e4b9c5dd8b0e9026303",
"urls": [
"http:\/\/ns.adobe.com\/xap\/1.0\/mm\/",
"http:\/\/ns.adobe.com\/xap\/1.0\/",
"http:\/\/ns.adobe.com\/xap\/1.0\/sType\/ResourceRef"
],
"crc32": "40BB3269",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/8d46eb0c60043dcb_sponsored.png",
"ssdeep": null,
"size": 2082,
"sha512": "e891552bee3aa10247cad1fcc510331077016a6e71d46827be2dd46017f943c5acc2c1506b41217880d35d52a94989923ad0a345f8791da4bb379eceefe3c407",
"pids": [
2436
],
"md5": "e3758d529f93fee4807f5ea95fbc1a6c"
},
{
"yara": [],
"sha1": "2974f4bf37231205a256f2648189a461e74869c0",
"name": "476a7b1085cc64de_loader.gif",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Loader.gif",
"type": "GIF image data, version 89a, 220 x 19",
"sha256": "476a7b1085cc64de1c0eb74a6776fa8385d57eb18774f199df83fc4d7bbcc24e",
"urls": [],
"crc32": "2F7B5638",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/476a7b1085cc64de_loader.gif",
"ssdeep": null,
"size": 10819,
"sha512": "2d50b9095d06ffd15eeeccf0eb438026ca8d09ba57141fed87a60edd2384e2139320fb5539144a2f16de885c49b0919a93690974f32b73654debca01d9d7d55c",
"pids": [
2436
],
"md5": "57ca1a2085d82f0574e3ef740b9a5ead"
},
{
"yara": [],
"sha1": "91642b0d16021c0e2082b74f712a6cb4803ef4d7",
"name": "e10d3217a8827abb_grey_button.png",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button.png",
"type": "PNG image data, 162 x 39, 8-bit\/color RGBA, non-interlaced",
"sha256": "e10d3217a8827abbd8d80b67fb34e31ca23be889a3628f8444a12e28e89ff916",
"urls": [],
"crc32": "3ADCA336",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/e10d3217a8827abb_grey_button.png",
"ssdeep": null,
"size": 478,
"sha512": "bfccdf014c35aec8164cb4e098762531e51ce7c9313bc4adf086b888c744e09e8d40407102b4e642dcf2feceec6405abd60eea1034120ff19b7c7f4b231a24ea",
"pids": [
2436
],
"md5": "c6664fd9c243aa6e40ea1aa8a9deccf9"
},
{
"yara": [],
"sha1": "2931e65dc245e567dd3c50f8a02ab419ddb4795c",
"name": "03acfb58c4b49bfa_main.css",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\main.css",
"type": "ASCII text, with CRLF line terminators",
"sha256": "03acfb58c4b49bfa4116897754b2e0a763005dce24a36fd377dd79303dd6bb95",
"urls": [],
"crc32": "C59A87F1",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/03acfb58c4b49bfa_main.css",
"ssdeep": null,
"size": 8288,
"sha512": "02fdc8837217b3ea43fe64a0dbfb0743386ee66467fe746d46ae3a133e70863e54144ed8c3603e8545464138aff1079b3156b29c7c060a9e7fca9b4032df5b26",
"pids": [
2436
],
"md5": "3008e794273b2875b13521c7e495fcbc"
},
{
"yara": [],
"sha1": "cdee967961a3ea87565ae7ca287be8ed20496160",
"name": "f638cc042b7ade6f_close.png",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close.png",
"type": "PNG image data, 17 x 16, 8-bit\/color RGBA, non-interlaced",
"sha256": "f638cc042b7ade6f43f2faf0077e020137562e559178396b7e975db39ac13df6",
"urls": [],
"crc32": "6408D24F",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/f638cc042b7ade6f_close.png",
"ssdeep": null,
"size": 207,
"sha512": "db52224964ffd03fa65fddabea29d4f7c23840a18d1ad1028f228589c8c642280a762d2f4250159106f911455b8f0706a3b204dcbbb0484638d4f41f4f54a836",
"pids": [
2436
],
"md5": "c222a4f3d309721c0898606960120266"
},
{
"yara": [],
"sha1": "4ec405f2668d5d93260525ad916abafa2414cb72",
"name": "8e806f5b94fc294e_button.css",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\button.css",
"type": "ASCII text, with CRLF line terminators",
"sha256": "8e806f5b94fc294e918503c8053ef1284e4f4b1e02c7da4f4635e33ec33e0534",
"urls": [],
"crc32": "7DF9208E",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/8e806f5b94fc294e_button.css",
"ssdeep": null,
"size": 417,
"sha512": "1a8a27a92abe35edaa2c950b130579c92f0d0d87b09971843c39569cf06d407b8e896751e73452676bfad45a363f0b6dd00cb6c5faf33966880539e106b19f94",
"pids": [
2436
],
"md5": "37e1ff96e084ec201f0d95feef4d5e94"
},
{
"yara": [],
"sha1": "0b2769433e73e3c6c677a5c7294a9a2f45cb8a64",
"name": "e37e99ddfc73ac7b_csshover3.htc",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\csshover3.htc",
"type": "HTML document, ASCII text, with very long lines, with CRLF line terminators",
"sha256": "e37e99ddfc73ac7ba774e23736b2ef429d9a0cb8c906453c75b14c029bdd5493",
"urls": [
"http:\/\/www.xs4all.nl\/",
"http:\/\/creativecommons.org\/licenses\/LGPL\/2.1"
],
"crc32": "3030E7E7",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/e37e99ddfc73ac7b_csshover3.htc",
"ssdeep": null,
"size": 2893,
"sha512": "fff97c9f5954dac6477d619382fe30a4d625027a709b9d8b30e6524d31df35d9bd3c122cd501f785a18a65e998a2afb5220d5fe482a27d0b81a40baa6c9565da",
"pids": [
2436
],
"md5": "52fa0da50bf4b27ee625c80d36c67941"
},
{
"yara": [],
"sha1": "a1615c118fbfa49253d98185eae283f26ea392d7",
"name": "2693930c474fe640_button-bg.png",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\button-bg.png",
"type": "PNG image data, 5 x 22, 8-bit\/color RGB, non-interlaced",
"sha256": "2693930c474fe640e2fe8d6ef98abe2ecd303d2392c3d8b2e006e8942ba8f534",
"urls": [],
"crc32": "55349B32",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/2693930c474fe640_button-bg.png",
"ssdeep": null,
"size": 131,
"sha512": "6529c2602a88139f44534c70bc41f02a3a99cda666cd9d2be5e3f1fb45bb2c9b288cf7eb4636070713787017e108b7c353983c7a7f5ff213a8dcfc5d780df945",
"pids": [
2436
],
"md5": "98b1de48dfa64dc2aa1e52facfbee3b0"
},
{
"yara": [],
"sha1": "2dab653eb20be72b034a38dc1fcebbd18f079c86",
"name": "9216d98a6574dfad_default_wi.png",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_wi.png",
"type": "PNG image data, 629 x 142, 8-bit colormap, non-interlaced",
"sha256": "9216d98a6574dfadacdc8321dc435454cb72c589b3ee8326a9b946966f756d7f",
"urls": [
"http:\/\/ns.adobe.com\/xap\/1.0\/mm\/",
"http:\/\/ns.adobe.com\/xap\/1.0\/",
"http:\/\/ns.adobe.com\/xap\/1.0\/sType\/ResourceRef"
],
"crc32": "59778B45",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/9216d98a6574dfad_default_wi.png",
"ssdeep": null,
"size": 28178,
"sha512": "25575fea9abb1491b5a5853244a9b655ce05f64d98f4b79134674f2d9a560a5af405c1783c9da4a07cfb38b51d060c7a70890c70df6c1c8f4b01e041aa4f649f",
"pids": [
2436
],
"md5": "1cc2677e3e29e45e538985839cff2b42"
},
{
"yara": [],
"sha1": "adc23b97959b979927f5c7646ca407292566f2a5",
"name": "27dd029405cbfb0c_form.bmp.mask",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\form.bmp.Mask",
"type": "SysEx File -",
"sha256": "27dd029405cbfb0c3bf8bac517be5db9aa83e981b1dc2bd5c5d6c549fa514101",
"urls": [],
"crc32": "DEC035D1",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/27dd029405cbfb0c_form.bmp.mask",
"ssdeep": null,
"size": 244,
"sha512": "50ec40ef5795f57a8356e657aaa1708acb93354b6d6ef0319805cea5facf397f45d4e9896942bc49cb0a9a86dd6772a9dd3c27cce50a184e7e6559bf05a44274",
"pids": [
2436
],
"md5": "d2fc989f9c2043cd32332ec0fad69c70"
},
{
"yara": [],
"sha1": "a5ee1d55de2cc60966039120c830fc19cefb0351",
"name": "717f3f02f5d5fd14_progressbar.png",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\ProgressBar.png",
"type": "PNG image data, 525 x 21, 8-bit\/color RGBA, non-interlaced",
"sha256": "717f3f02f5d5fd1478b6d2ec44acef6e70bb8f1adcf2dc030c08b92e851737e1",
"urls": [],
"crc32": "55C9D5EA",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/717f3f02f5d5fd14_progressbar.png",
"ssdeep": null,
"size": 812,
"sha512": "d232072c9540bf0e2fd56f353c2cc83518eabf8282cc02d9f8bec81c0341287ada29ba79f2a515d68722658686b6cce97be138a48f44409562d9a567af200bd6",
"pids": [
2436
],
"md5": "eabb61abba55f80af418fa1128d1548d"
},
{
"yara": [],
"sha1": "98f4c693af708e02201de2aee31fe094dc3b0a9c",
"name": "e466a2db2f755d9e_resume_button.png",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Resume_Button.png",
"type": "PNG image data, 21 x 21, 8-bit\/color RGBA, non-interlaced",
"sha256": "e466a2db2f755d9eb68619439af37ff4e45559b7a3f476e226ab2a11aeadae1a",
"urls": [],
"crc32": "8B8EE214",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/e466a2db2f755d9e_resume_button.png",
"ssdeep": null,
"size": 718,
"sha512": "9ddaaad53375f4d2874fe5c98b6782202d2bd975cdd9363796986dc7567368b94d9ec1aa3e839194097838b787bbd71d574540cf5b04fd04f10fa80d6a89e695",
"pids": [
2436
],
"md5": "9d31583bcfad58a6b9ddeaf44549a5e6"
},
{
"yara": [
{
"meta": {
"description": "Matched shellcode byte patterns",
"author": "nex"
},
"name": "shellcode",
"offsets": {
"shell2": [
[
16100,
0
]
]
},
"strings": [
"ZKEw"
]
}
],
"sha1": "6e3a721aef65625bf99b639800476150d262dd4b",
"name": "87af4027e8f89459_default_tb.png",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_tb.png",
"type": "PNG image data, 630 x 117, 8-bit colormap, non-interlaced",
"sha256": "87af4027e8f89459463bdd73df7b928b883eefb20514159d3a1a4be0d39e00c0",
"urls": [
"http:\/\/ns.adobe.com\/xap\/1.0\/mm\/",
"http:\/\/ns.adobe.com\/xap\/1.0\/",
"http:\/\/ns.adobe.com\/xap\/1.0\/sType\/ResourceRef"
],
"crc32": "366777FA",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/87af4027e8f89459_default_tb.png",
"ssdeep": null,
"size": 19494,
"sha512": "1efcf8af09cf857b3850cec43a88fc8c0992e3b04f78ad2c71b84c2ac7775e745df211582694588b29217aefb1ae02b29b94c2cfe52b5d32bdafb9dce73b9920",
"pids": [
2436
],
"md5": "70e70599d4b853df0f12f6cb0e04695f"
},
{
"yara": [],
"sha1": "50f84ef8331341b48981af82313b146863eba526",
"name": "b09504c1bf0486d3_checkbox.css",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\checkbox.css",
"type": "ASCII text, with CRLF line terminators",
"sha256": "b09504c1bf0486d3ec46500592b178a3a6c39284672af8815c3687cc3d29560d",
"urls": [],
"crc32": "19F79D2C",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/b09504c1bf0486d3_checkbox.css",
"ssdeep": null,
"size": 190,
"sha512": "03e96bef74c0b3a31124c3d3c1bb78af1053a8719ca373c6b9316d63bac9545c1f4ecc2d747eb64341d8da31bc0f23da094e19c3e07ed46f65c28dc88e13bd3a",
"pids": [
2436
],
"md5": "64773c6b0e3413c81aebc46cce8c9318"
},
{
"yara": [],
"sha1": "a00692b5a73c035da31aa5a285202cd117118290",
"name": "dccfb478e6097086_icon_generic.png",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Icon_Generic.png",
"type": "PNG image data, 34 x 32, 8-bit\/color RGBA, non-interlaced",
"sha256": "dccfb478e6097086d886b5a01d120bf511b381982b0975e0c65eab3846e4234d",
"urls": [],
"crc32": "376898B4",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/dccfb478e6097086_icon_generic.png",
"ssdeep": null,
"size": 1906,
"sha512": "1bd9612dc93217f1341764d1a4f917da8af338649772a41ae89798b5db7cc9bd9c6ec78b7a34945d3d0885b929bf7ae696a865dd50e4fb332ff3ca77bd84d629",
"pids": [
2436
],
"md5": "a35aeb077ffa7ffb4382c639743d29cc"
},
{
"yara": [],
"sha1": "e792ed3676746fe81b1b93ec6c11c7b27a121c96",
"name": "378c6b06f8c9a905_ie6_main.css",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\ie6_main.css",
"type": "ASCII text, with CRLF line terminators",
"sha256": "378c6b06f8c9a90540c61383b7250bc4df34f5547af4d96ddce717c3683c62d8",
"urls": [],
"crc32": "1DA8CD56",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/378c6b06f8c9a905_ie6_main.css",
"ssdeep": null,
"size": 1934,
"sha512": "44556be46e32f9db923861f75309ea0cba579478524fa43b8eb4b9426b8a36a743ac62f671a1e9694a94ab27006f5e472b9367b47aaf88e2d87709fd4b243b7a",
"pids": [
2436
],
"md5": "5fa9587859aea5525ad5461d188c169a"
},
{
"yara": [],
"sha1": "3bf74d0ac61083e97cf3ebd07d86a8f4fed1885b",
"name": "86b6e6826bcde295_progress-bg-corner.png",
"filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg-corner.png",
"type": "PNG image data, 22 x 26, 8-bit\/color RGB, non-interlaced",
"sha256": "86b6e6826bcde2955d64d4600a4e01693522c1fddf156ce31c4ba45b3653a7bd",
"urls": [],
"crc32": "F0FDCDCB",
"path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/881\/files\/86b6e6826bcde295_progress-bg-corner.png",
"ssdeep": null,
"size": 1636,
"sha512": "4ca9b7c5d3a2a87d3ec7e24c96e5a06e0c1390e993d51e8509f6dbcbd709064e476196c6ed5059e7fafa10ad258071e769feed91b890a010c9662804efd15787",
"pids": [
2436
],
"md5": "608f1f20cd6ca9936eaa7e8c14f366be"
}
][
{
"process_path": "C:\\Users\\cuck\\AppData\\Local\\Temp\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"process_name": "a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"pid": 816,
"summary": {
"file_opened": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"C:\\Windows\\Globalization\\Sorting\\sortdefault.nls"
],
"regkey_opened": [
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\Compatibility\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\KnownClasses",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\crypt32",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\DirectSwitchHotkeys",
"HKEY_CURRENT_USER\\Software\\Borland\\Delphi\\Locales",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{3697C5FA-60DD-4B56-92D4-74A569205C16}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CURRENT_USER\\Software\\Borland\\Locales",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\",
"HKEY_LOCAL_MACHINE\\Software\\Borland\\Locales",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CURRENT_USER\\Keyboard Layout\\Toggle",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}"
],
"file_read": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin"
],
"regkey_read": [
"HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Language Hotkey",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\CTF\\EnableAnchorContext",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crypt32\\DebugHeapFlags",
"HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Hotkey",
"HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Layout Hotkey",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}\\Enable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\DisableImprovedZoneCheck",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Security_HKLM_only"
],
"dll_loaded": [
"gdi32.dll",
"kernel32.dll",
"UxTheme.dll",
"oleaut32.dll",
"C:\\Windows\\system32\\ole32.dll",
"dwmapi.dll",
"URLMON.DLL",
"C:\\Windows\\syswow64\\MSCTF.dll",
"KERNEL32.DLL",
"OLEAUT32.DLL",
"advapi32.dll",
"comctl32",
"ole32.dll",
"comdlg32.dll",
"olepro32.dll",
"version.dll",
"wininet.dll",
"comctl32.dll",
"Kernel32",
"Kernel32.dll",
"shell32.dll",
"user32.dll"
]
},
"first_seen": 1562575988.0619,
"ppid": 2436
},
{
"process_path": "C:\\Windows\\System32\\lsass.exe",
"process_name": "lsass.exe",
"pid": 476,
"summary": {},
"first_seen": 1562575985.3438,
"ppid": 376
},
{
"process_path": "C:\\Users\\cuck\\AppData\\Local\\Temp\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"process_name": "a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"pid": 2436,
"summary": {
"file_created": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A8B9.log",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\ProgressBar.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_tb.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\ie6_main.css",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\sponsored.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Resume_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_wi.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close_Hover.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\BG.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Quick_Specs.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Loader.gif",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Pause_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\button-bg.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\main.css",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg2.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Icon_Generic.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\progress-bar.css",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\bootstrap_37556.html",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\checkbox.css",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg-corner.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\form.bmp.Mask",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\csshover3.htc",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\TR.locale",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button_Hover.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button_Hover.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\button.css",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\browse.css",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Progress.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\EN.locale",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A82C.log"
],
"directory_created": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\",
"C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\"
],
"dll_loaded": [
"IEFRAME.dll",
"C:\\Windows\\System32\\mswsock.dll",
"urlmon.dll",
"mshtml.dll",
"apphelp.dll",
"gdi32.dll",
"DNSAPI.dll",
"SHELL32.dll",
"kernel32.dll",
"UxTheme.dll",
"oleaut32.dll",
"C:\\Windows\\system32\\ole32.dll",
"dwmapi.dll",
"C:\\Windows\\system32\\napinsp.dll",
"ImgUtil.dll",
"ntmarta.dll",
"URLMON.DLL",
"C:\\Windows\\system32\\Msimtf.dll",
"API-MS-WIN-Service-Management-L1-1-0.dll",
"VERSION.dll",
"C:\\Windows\\syswow64\\MSCTF.dll",
"KERNEL32.DLL",
"API-MS-Win-Core-LocalRegistry-L1-1-0.dll",
"OLEAUT32.DLL",
"RASMAN.DLL",
"IPHLPAPI.DLL",
"advapi32.dll",
"comctl32",
"ole32.dll",
"comdlg32.dll",
"API-MS-WIN-Service-winsvc-L1-1-0.dll",
"olepro32.dll",
"rtutils.dll",
"version.dll",
"C:\\Windows\\SysWOW64\\oleaut32.dll",
"wininet.dll",
"ADVAPI32.dll",
"OLEAUT32.dll",
"C:\\Windows\\system32\\pnrpnsp.dll",
"DHCPCSVC.DLL",
"C:\\Windows\\System32\\winrnr.dll",
"API-MS-Win-Security-SDDL-L1-1-0.dll",
"comctl32.dll",
"WININET.dll",
"Kernel32",
"SXS.DLL",
"MLANG.dll",
"Kernel32.dll",
"powrprof.dll",
"shell32.dll",
"rpcrt4.dll",
"SETUPAPI.dll",
"WS2_32.dll",
"user32.dll"
],
"file_opened": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A8B9.log",
"C:\\",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\ProgressBar.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_tb.png",
"C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Internet Explorer\\MSIMGSIZ.DAT",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\ie6_main.css",
"C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches\\cversions.1.db",
"C:\\Users\\cuck\\AppData\\Local\\Temp",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\sponsored.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Resume_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_wi.png",
"C:\\Users\\cuck\\AppData",
"C:\\Windows\\SysWOW64\\ieframe.dll",
"C:\\Users\\cuck\\AppData\\Local",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close_Hover.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\BG.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Quick_Specs.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Loader.gif",
"C:\\Users",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Pause_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\button-bg.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\main.css",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg2.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Icon_Generic.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\progress-bar.css",
"\\\\?\\pipe\\0K1C1T1I1E1C1F1N1C1T1H_TEST",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\checkbox.css",
"C:\\Users\\desktop.ini",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg-corner.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\form.bmp.Mask",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\csshover3.htc",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\TR.locale",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button_Hover.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\bootstrap_37556.html",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button_Hover.png",
"C:\\Windows\\Globalization\\Sorting\\sortdefault.nls",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\button.css",
"C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Windows\\Caches\\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000004.db",
"C:\\Users\\cuck",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\browse.css",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Progress.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\EN.locale",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A82C.log"
],
"command_line": [
"\"C:\\Users\\cuck\\AppData\\Local\\Temp\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin\" \/_ShowProgress \/PrTxt:TG9hZGluZy4uLg=="
],
"connects_host": [
"rp.kralprogramcdn.com",
"info.kralprogramcdn.com"
],
"regkey_opened": [
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/pjpeg\\Bits",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows NT\\DnsClient",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/tiff\\Bits",
"HKEY_CLASSES_ROOT\\Directory",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer\\Main",
"HKEY_CLASSES_ROOT\\PROTOCOLS\\Name-Space Handler\\about\\",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{E429B25A-E5D3-4D1F-9BE3-0C608477E3A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_PROTOCOL_LOCKDOWN",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_IEDDE_REGISTER_URLECHO",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Settings",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\DxTrans",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Blocked",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_BROWSER_EMULATION",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\PROTOCOLS\\Handler\\about",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced",
"HKEY_CURRENT_USER\\SOFTWARE\\Classes\\PROTOCOLS\\Filter\\text\/html",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_IPERSISTMONIKER_LOAD_REDIRECTED_URL_KB976425",
"HKEY_CURRENT_USER\\Software\\Policies",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{DCBD6FA8-032F-11D3-B5B1-00C04FC324A1}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\DocObject",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder",
"HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\LayoutIcon\\0409\\0000041d",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\KnownClasses",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\PageSetup",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows NT\\Rpc",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_IGNORE_POLICIES_ZONEMAP_IF_ESC_ENABLED_KB918915",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Styles",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\ShellEx\\IconHandler",
"HKEY_CLASSES_ROOT\\MIME\\Database\\Content Type",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_ZONES_CHECK_ZONEMAP_POLICY_KB941001",
"HKEY_CURRENT_USER\\Interface\\{2A1C9EB2-DF62-4154-B800-63278FCB8037}",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\Clsid",
"HKEY_CURRENT_USER\\Keyboard Layout\\Toggle",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocHandler",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\TravelLog",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{531FDEBF-9B4C-4A43-A2AA-960E8FCDC732}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{55272A00-42CB-11CE-8135-00AA004BB851}\\ProxyStubClsid32",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Ftp",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\",
"HKEY_CLASSES_ROOT\\Drive\\shellex\\FolderExtensions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_IEDDE_REGISTER_PROTOCOL",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_PROTOCOL_LOCKDOWN",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Ftp",
"HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\LSA\\AccessProviders",
"HKEY_CLASSES_ROOT\\.png",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/jpeg\\Bits",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/x-png",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer",
"HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\(Default)",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_ZONE_ELEVATION",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International",
"HKEY_CURRENT_USER\\Software\\Borland\\Delphi\\Locales",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Low Rights",
"HKEY_CLASSES_ROOT\\.css",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Services",
"HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\Tcpip\\Parameters",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\MediaTypeClass",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_ACTIVEX_INACTIVATE_MODE_REMOVAL_REVERT",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{81D4E9C9-1D3B-41BC-9E6C-4B40BF79E35E}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Services",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer\\Zoom",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_MIME_SNIFFING",
"HKEY_CURRENT_USER\\Software\\Microsoft\\windows\\CurrentVersion\\Internet Settings\\Zones",
"HKEY_CURRENT_USER\\Software\\Borland\\Locales",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\MenuExt",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\ActiveDesktop",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Recovery",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Domains\\",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer",
"HKEY_LOCAL_MACHINE\\Software",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B}\\1.1\\0",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Url History",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.html\\Clsid",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html\\UserChoice",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SAFE_BINDTOOBJECT",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\ActiveX Compatibility",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B}\\1.1\\0\\win32",
"HKEY_CLASSES_ROOT\\PROTOCOLS\\Name-Space Handler\\",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{03B5835F-F03C-411B-9CE2-AA23E1171E36}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\(Default)",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\Explorer",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SCRIPTURL_MITIGATION",
"HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\DnsCache\\Parameters",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_BINARY_CALLER_SERVICE_PROVIDER",
"HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\ShellEx\\IconHandler",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Ranges\\",
"HKEY_CLASSES_ROOT\\CLSID\\{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}\\InProcServer32",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/png\\Bits",
"HKEY_CURRENT_USER\\Software\\Microsoft\\CTF\\DirectSwitchHotkeys",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\IETld",
"HKEY_LOCAL_MACHINE\\System\\Setup",
"HKEY_CLASSES_ROOT\\SystemFileAssociations\\.html",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SHOW_FAILED_CONNECT_CONTENT_KB942615",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_READ_ZONE_STRINGS_FROM_REGISTRY",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\4",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\3",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\2",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\1",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\0",
"HKEY_CLASSES_ROOT\\FirefoxURL-E7CF176E110C211B\\shell\\open\\command",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_ADDITIONAL_IE8_MEMORY_CLEANUP",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\BrowseInPlace",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer\\BrowserEmulation",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\Feature_Enable_Compat_Logging",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{2A1C9EB2-DF62-4154-B800-63278FCB8037}\\ProxyStubClsid32",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Activities",
"HKEY_CURRENT_USER\\Interface\\{BCD1DE7E-2DB1-418B-B047-4A74E101F8C1}",
"HKEY_CLASSES_ROOT\\SystemFileAssociations\\document",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Setup",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_RESTRICT_FILEDOWNLOAD",
"HKEY_CLASSES_ROOT\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}",
"HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocServer32",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocHandler32",
"HKEY_CLASSES_ROOT\\PROTOCOLS\\Name-Space Handler\\*\\",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Nls\\CodePage",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Url History",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SUBDOWNLOAD_LOCKDOWN",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_IGNORE_LEADING_FILE_SEPARATOR_IN_URI_KB933105",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\International\\Scripts",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Accepted Documents",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{BCD1DE7E-2DB1-418B-B047-4A74E101F8C1}\\ProxyStubClsid32",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Ranges\\",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_RESTRICTED_ZONE_WHEN_FILE_NOT_FOUND",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{78CB5B0E-26ED-4FCC-854C-77E8F3D1AA80}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer\\Restrictions",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\TravelLog",
"HKEY_LOCAL_MACHINE\\Software\\Policies",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer\\Control Panel",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_RESTRICT_FILEDOWNLOAD",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html\\(Default)",
"HKEY_CURRENT_USER\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\OleAut",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Rpc",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProtocolDefaults\\",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer\\Infodelivery\\Restrictions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MIME_HANDLING",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\3",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\2",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{8A40A45D-055C-4B62-ABD7-6D613E2CEAEC}\\ProxyStubClsid32",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\0",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\4",
"HKEY_CLASSES_ROOT\\CLSID\\{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}\\ShellFolder",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Internet Explorer\\Main",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Internet Explorer\\BrowserEmulation",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_BROWSER_EMULATION",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Ratings",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_DOCUMENT_COMPATIBLE_MODE",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\1",
"HKEY_CLASSES_ROOT\\.html\\OpenWithProgids",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_WEBOC_DOCUMENT_ZOOM",
"HKEY_CLASSES_ROOT\\FirefoxHTML-E7CF176E110C211B",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{26656EAA-54EB-4E6F-8F85-4F0EF901A406}\\ProxyStubClsid32",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Internet Explorer",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_UNC_SAVEDFILECHECK",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{C1EE01F2-B3B6-4A6A-9DDD-E988C088EC82}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\Clsid",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html\\OpenWithProgids",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\ShellEx\\IconHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_SSLUX",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\MenuExt\\%s",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Domains\\",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_BLOCK_LMZ_IMG",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Scripts\\3",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Internet Explorer\\Zoom",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_CUSTOM_IMAGE_MIME_TYPES_KB910561",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Security",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Associations\\UrlAssociations\\Directory",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.html\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\DxTrans",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_XSSFILTER",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Zoom",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_UNC_SAVEDFILECHECK",
"HKEY_CURRENT_USER\\Software\\Microsoft\\windows\\CurrentVersion\\Internet Settings\\Wpad",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B}\\1.1",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Internet Explorer\\Main\\FeatureControl",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\System\\DNSClient",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Security\\Adv AddrBar Spoof Detection",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4",
"HKEY_CURRENT_USER\\Interface\\{8A40A45D-055C-4B62-ABD7-6D613E2CEAEC}",
"HKEY_CURRENT_USER\\Interface\\{55272A00-42CB-11CE-8135-00AA004BB851}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\TreatAs",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Services",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap",
"HKEY_CLASSES_ROOT\\Folder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{AE6BE008-07FB-400D-8BEB-337A64F7051F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CLASSES_ROOT\\.gif",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\Progid",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Security\\Adv AddrBar Spoof Detection",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_SAFE_BINDTOOBJECT",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/x-jg\\Bits",
"HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Services\\LDAP",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Associations\\UrlAssociations\\http\\UserChoice",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Internet Explorer\\Main\\FeatureControl",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{3050f819-98b5-11cf-bb82-00aa00bdce0b}",
"HKEY_CURRENT_USER\\Software",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.html\\ShellEx\\IconHandler",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\Compatibility\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\MAIN",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\COM3",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\PROTOCOLS\\Filter\\text\/html",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\ShellEx\\IconHandler",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{07EB03D6-B001-41DF-9192-BF9B841EE71F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\iexplore.exe",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Scripts",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_USE_IETLDLIST_FOR_DOMAIN_DETERMINATION",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_LEGACY_DLCONTROL_BEHAVIORS",
"HKEY_CLASSES_ROOT\\AllFilesystemObjects",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\DocObject",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{3050f4e1-98b5-11cf-bb82-00aa00bdce0b}",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{A028AE76-01B1-46C2-99C4-ACD9858AE02F}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MIME_SNIFFING",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Zoom",
"HKEY_CURRENT_USER\\TypeLib",
"HKEY_CURRENT_USER\\SOFTWARE\\Classes\\PROTOCOLS\\Handler\\about",
"HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\CurVer",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Domains\\",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{8613E14C-D0C0-4161-AC0F-1DD2563286BC}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_SSLUX",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}",
"HKEY_CLASSES_ROOT\\.html",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\",
"HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\DocObject",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Security\\Floppy Access",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/x-icon\\Bits",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Security",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\Clsid",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MANAGE_SCRIPT_CIRCULAR_REFS",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Internet Explorer\\Infodelivery\\Restrictions",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing\\RASMANCS",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Domains\\",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\Explorer",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F25E9F57-2FC8-4EB3-A41A-CCE5F08541E6}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\CLSID\\{3050f4f5-98B5-11CF-BB82-00AA00BDCE0B}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/x-wmf\\Bits",
"HKEY_CURRENT_USER\\Software\\Microsoft\\windows\\CurrentVersion\\Internet Settings\\Connections",
"HKEY_CLASSES_ROOT\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.html\\DocObject",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ShellCompatibility\\Applications\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\CurVer",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\4",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\0",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\1",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\2",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Lockdown_Zones\\3",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_ZONES_DEFAULT_DRIVE_INTRANET_KB941000",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{3697C5FA-60DD-4B56-92D4-74A569205C16}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\ShellCompatibility\\Objects\\{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/x-png\\Bits",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\DocObject",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Url History",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Low Rights",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\Shell\\RegisteredApplications\\UrlAssociations\\Directory\\OpenWithProgids",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\ActiveX Compatibility\\{F414C260-6AC0-11CF-B6D1-00AA00BBBB58}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_Cross_Domain_Redirect_Mitigation",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\Progid",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/bmp\\Bits",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Blocked",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{F89E9E58-BD2F-4008-9AC2-0F816C09F4EE}\\Category\\Category\\{534C48C1-0607-4098-A521-4FC899C73E90}",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/gif\\Bits",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap",
"HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\Clsid",
"HKEY_CURRENT_USER\\Interface\\{26656EAA-54EB-4E6F-8F85-4F0EF901A406}",
"HKEY_CLASSES_ROOT\\htmlfile",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Activities",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Activities",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Url History",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\Ranges\\",
"HKEY_LOCAL_MACHINE\\Software\\Borland\\Locales",
"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\crypt32",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Cryptography",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MSHTML_AUTOLOAD_IEFRAME",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B}",
"HKEY_LOCAL_MACHINE\\Software\\Policies\\Microsoft\\Internet Explorer\\Restrictions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Version Vector",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_RESPECT_OBJECTSAFETY_POLICY_KB905547",
"HKEY_CLASSES_ROOT\\PROTOCOLS\\Name-Space Handler\\file\\",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_ZONE_ELEVATION",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\BrowseInPlace",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies",
"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_BROWSER_EMULATION",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_MIME_HANDLING"
],
"resolves_host": [
"wpad",
"cuckpc"
],
"file_written": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A8B9.log",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\ProgressBar.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_tb.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\ie6_main.css",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\sponsored.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Resume_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_wi.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close_Hover.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\BG.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Quick_Specs.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Loader.gif",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Pause_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\button-bg.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\main.css",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg2.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Icon_Generic.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\progress-bar.css",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\bootstrap_37556.html",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\checkbox.css",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\progress-bg-corner.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\form.bmp.Mask",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\csshover3.htc",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\TR.locale",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button_Hover.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button_Hover.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\button.css",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\browse.css",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Progress.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\EN.locale",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A82C.log"
],
"regkey_deleted": [
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName"
],
"file_deleted": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A8B9.log",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\bootstrap_37556.html",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A82C.log"
],
"file_exists": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\",
"C:\\",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\ProgressBar.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_tb.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Microsoft",
"C:\\Users\\cuck\\",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\sponsored.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\main.css:Zone.Identifier",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Resume_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_wi.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\",
"C:\\Users\\",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\BG.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Quick_Specs.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\images\\",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Loader.gif",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Pause_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\main.css",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\progress-bar.css",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\bootstrap_37556.html",
"C:\\Users\\cuck\\AppData\\Local\\Microsoft\\Internet Explorer",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\progress-bar.css:Zone.Identifier",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\bootstrap_37556.html:Zone.Identifier",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Progress.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\",
"C:\\Users\\cuck\\AppData\\"
],
"mutex": [
"MSIMGSIZECacheMutex",
"Local\\ZonesCounterMutex",
"Local\\ZonesLockedCacheCounterMutex",
"Local\\ZoneAttributeCacheCounterMutex",
"IESQMMUTEX_0_208",
"Local\\ZonesCacheCounterMutex"
],
"file_failed": [
"\\\\?\\pipe\\0K1C1T1I1E1C1F1N1C1T1H",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\bootstrap_37556.html"
],
"guid": [
"{275c23e2-3747-11d0-9fea-00aa003f8646}",
"{6a01fda0-30df-11d0-b724-00aa006c1a01}",
"{30c3b080-30fb-11d0-b724-00aa006c1a01}",
"{dccfc164-2b38-11d2-b7ec-00c04f8f5d9a}",
"{25336920-03f9-11cf-8fd0-00aa00686f13}",
"{a3ccedf7-2de2-11d0-86f4-00a0c913f750}",
"{dcb00c01-570f-4a9b-8d69-199fdba5723b}",
"{5762f2a7-4658-4c7a-a4ac-bdabfe154e0d}",
"{4ef17940-30e0-11d0-b724-00aa006c1a01}",
"{6e89f8e2-9a2a-4797-9b91-41146bdf0e7b}",
"{00000146-0000-0000-c000-000000000046}",
"{6c736dc1-ab0d-11d0-a2ad-00a0c90f27e8}",
"{d0074ffd-570f-4a9b-8d69-199fdba5723b}",
"{a3ccedf3-2de2-11d0-86f4-00a0c913f750}",
"{f414c260-6ac0-11cf-b6d1-00aa00bbbb58}",
"{000214e6-0000-0000-c000-000000000046}",
"{00000001-0000-0000-c000-000000000046}",
"{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}",
"{d9e89500-30fa-11d0-b724-00aa006c1a01}",
"{00000323-0000-0000-c000-000000000046}",
"{e7e4bc40-e76a-11ce-a9bb-00aa004ae837}",
"{8856f961-340a-11d0-a96b-00c04fd705a2}",
"{dcb00000-570f-4a9b-8d69-199fdba5723b}",
"{50d5107a-d278-4871-8989-f4ceaaf59cfc}",
"{bb1a2ae1-a4f9-11cf-8f20-00805f2cd064}",
"{a47979d2-c419-11d9-a5b4-001185ad2b89}",
"{00000112-0000-0000-c000-000000000046}",
"{6c736db1-bd94-11d0-8a23-00aa00b58e10}",
"{3050f406-98b5-11cf-bb82-00aa00bdce0b}",
"{08c0e040-62d1-11d1-9326-0060b067b86e}",
"{e569bde7-a8dc-47f3-893f-fd2b31b3eefd}"
],
"file_read": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\ProgressBar.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_tb.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\sponsored.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Resume_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_wi.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\bootstrap_37556.html",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\BG.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Quick_Specs.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Loader.gif",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Pause_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\main.css",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\progress-bar.css",
"C:\\Windows\\SysWOW64\\ieframe.dll",
"C:\\Users\\desktop.ini",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A8B9.log",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Progress.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\locale\\EN.locale",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\0294A82C.log"
],
"regkey_read": [
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\EnableLUA",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Rpc\\MaxRpcSize",
"HKEY_CURRENT_USER\\.html\\Content Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Version Vector\\VML",
"HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-699399860-4089948139-3198924279-1001\\ProfileImagePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoSetFolders",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoFileUrl",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Scripts\\3\\IEFontSize",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SUBDOWNLOAD_LOCKDOWN\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASAPI32\\FileDirectory",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\AutoProxyDetectType",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Domain",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\DisableImprovedZoneCheck",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CreateUriCacheSize",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideIcons",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\RecommendedLevel",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\AutoCheckSelect",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\MinLevel",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\Attributes",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyEnable",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\Icon",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\UrlEncoding",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.gif\\Content Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\EnableConsoleTracing",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\DisableCachingOfSSLPages",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\XDomainRequest",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsAliasedNotifications",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Display Inline Images",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\MinLevel",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Zoom\\ZoomDisabled",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\Flags",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\PROTOCOLS\\Handler\\about\\CLSID",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\DocObject",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CoInternetCombineIUriCacheSize",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASAPI32\\EnableFileTracing",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\IsTextPlainHonored",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/x-png\\Image Filter CLSID",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Scripts\\3\\IEFixedFontName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\Show image placeholders",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}\\InProcServer32\\LoadWithoutCOM",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\DontPrettyPath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\AllowFileCLSIDJunctions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}\\InProcServer32\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_ZONE_ELEVATION\\*",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Low Rights\\ProtectedModeOffForAllZones",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.html\\AlwaysShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_LEGACY_DLCONTROL_BEHAVIORS\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{2A1C9EB2-DF62-4154-B800-63278FCB8037}\\ProxyStubClsid32\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\FileTracingMask",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\SmoothScroll",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Use Stylesheets",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\ExtendedLocale\\en-US",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\Flags",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CodePage\\950",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CoInternetCombineIUriCacheSize",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\2106",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\1201",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\TabProcGrowth",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\IETld\\IETldDllVersionLow",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\DevicePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\SpecialFoldersCacheSize",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowTypeOverlay",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Always Use My Font Size",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Data",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\HideFileExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocServer32\\InprocServer32",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/jpeg\\Bits\\0",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Enable AutoImageResize",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\IETld\\IETldDllVersionHigh",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\2500",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\CurrentLevel",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.html\\NeverShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{8A40A45D-055C-4B62-ABD7-6D613E2CEAEC}\\ProxyStubClsid32\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoWebView",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.css\\Content Type",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\2000",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\CTF\\TIP\\{0000897b-83df-4b96-be07-0fb58b01c4a4}\\LanguageProfile\\0x00000000\\{0001bea3-ed56-483d-a2e2-aeae25577436}\\Enable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_UNC_SAVEDFILECHECK\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\AcceptLanguage",
"HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SystemSetupInProgress",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FrameTabWindow",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\RecommendedLevel",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Setup\\SourcePath",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/pjpeg\\Bits\\0",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\RestrictedAttributes",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseOldHostResolutionOrder",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\2700",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\ProgramData",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\NeverShowExt",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowInfoTip",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_LEGACY_DLCONTROL_BEHAVIORS\\*",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Move System Caret",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\TypeLib\\{EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B}\\1.1\\0\\win32\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\AdminTabProcs",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\(Default)",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\SessionMerging",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/x-wmf\\Bits\\0",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\RecommendedLevel",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocServer32\\ThreadingModel",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\NonEnum\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Anchor Color Visited",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\AlwaysShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SSLUX\\*",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\SeparateProcess",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\SecuritySafe",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Locale\\00000409",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MIME_SNIFFING\\*",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\SpecialFoldersCacheSize",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.html\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoCommonGroups",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\IETld\\IETldVersionHigh",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\PinToNameSpaceTree",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\COM3\\COM+Enabled",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsFORPARSING",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\DisableCachingOfSSLPages",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\DOMStorage",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\2500",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\2000",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\UrlEncoding",
"HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\AlwaysShowExt",
"HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\\*",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Tcpip\\Parameters\\Hostname",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowCompColor",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\App Paths\\IEXPLORE.EXE\\(Default)",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\MiscFlags",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Services\\SelectionActivityButtonDisable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoPropertiesRecycleBin",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\QueryForInfoTip",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\AccessProviders\\MartaExtension",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoPropertiesMyComputer",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\UseHR",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\DOMStorage",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\SmartDithering",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\SessionMerging",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\2500",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\Print_Background",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\ShellState",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Force Offscreen Composition",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_BLOCK_LMZ_IMG\\*",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CoInternetCombineIUriCacheSize",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\UrlEncoding",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\Icon",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Disable Script Debugger",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\1400",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\XMLHTTP",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\CurrentLevel",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\NeverShowExt",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Drive\\shellex\\FolderExtensions\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\DriveMask",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Generation",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\CurrentLevel",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SAFE_BINDTOOBJECT\\*",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\RtfConverterFlags",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\FileDirectory",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoControlPanel",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_ZONE_ELEVATION\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\UseClearType",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SSLUX\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\2500",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\Flags",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Play_Animations",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_BROWSER_EMULATION\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Shell\\Associations\\UrlAssociations\\http\\UserChoice\\Progid",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FrameTabWindow",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Use Anchor Hover Color",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Default_CodePage",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\IETld\\IETldVersionLow",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Scripts\\Default_IEFontSizePrivate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASAPI32\\EnableConsoleTracing",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MIME_SNIFFING\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html\\UserChoice\\Progid",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_RESTRICT_FILEDOWNLOAD\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Scripts\\3\\IEFontSizePrivate",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\SpecialFoldersCacheSize",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Filter",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Anchor Color",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/x-png\\Bits\\0",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsFORDISPLAY",
"HKEY_CURRENT_USER\\.html\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\CTF\\EnableAnchorContext",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b5-70f9-11e8-b07b-806e6f6e6963}\\Generation",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoInternetIcon",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\MountPoints2\\CPC\\Volume\\{3f5cc1b6-70f9-11e8-b07b-806e6f6e6963}\\Data",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\No3DBorder",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Print_Background",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Url History\\DaysToKeep",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\MapNetDriveVerbs",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} {000214E6-0000-0000-C000-000000000046} 0xFFFF",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\DefaultConnectionSettings",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\2106",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\XDomainRequest",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\crypt32\\DebugHeapFlags",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\MaxFileSize",
"HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Layout Hotkey",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\CurrentLevel",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Disable Visited Hyperlinks",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_PROTOCOL_LOCKDOWN\\*",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\MinLevel",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\MinLevel",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\DontShowSuperHidden",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Version Vector\\WindowsEdition",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.html\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASAPI32\\MaxFileSize",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Expand Alt Text",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Play_Background_Sounds",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Display Inline Videos",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_XSSFILTER\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASAPI32\\ConsoleTracingMask",
"HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\NeverShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\DisableCachingOfSSLPages",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\EnableFileTracing",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideFolderVerbs",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_RESTRICT_FILEDOWNLOAD\\*",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoNetCrawling",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Q300829",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\TabProcGrowth",
"HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\OOBEInProgress",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CreateUriCacheSize",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideInWebView",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\Display Inline Videos",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\NoProtectedModeBanner",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\CallForAttributes",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Recovery\\AutoRecover",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\ConsoleTracingMask",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\No3DBorder",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\WpadLastNetwork",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragDelay",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\AdminTabProcs",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CreateUriCacheSize",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Always Use My Font Face",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\EnablePunycode",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\.png\\Content Type",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\2106",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\NavigationDelay",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\CustomLocale\\en-US",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Cryptography\\MachineGuid",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HasNavigationEnum",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\2500",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Directory\\DocObject",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\2500",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\RecommendedLevel",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\ShowSuperHidden",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\AppData",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\EnablePunycode",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MSHTML_AUTOLOAD_IEFRAME\\*",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoFileMenu",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\CurrentLevel",
"HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Language Hotkey",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\SmartDithering",
"HKEY_CURRENT_USER\\Keyboard Layout\\Toggle\\Hotkey",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SAFE_BINDTOOBJECT\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\UseHostnameAsAlias",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\NoNetCrawling",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_XSSFILTER\\*",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\AutoDetect",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Anchor Underline",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASAPI32\\FileTracingMask",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MIME_HANDLING\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Page_Transitions",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{26656EAA-54EB-4E6F-8F85-4F0EF901A406}\\ProxyStubClsid32\\(Default)",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\WarnOnIntranet",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Nls\\Language Groups\\1",
"HKEY_CURRENT_USER\\FirefoxHTML-E7CF176E110C211B\\DocObject",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Use_DlgBox_Colors",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MIME_HANDLING\\*",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Version Vector\\IE",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsUniversalDelegate",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\SpecialFoldersCacheSize",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\QueryForOverlay",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CoInternetCombineIUriCacheSize",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\Hidden",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\ClassicShell",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_PROTOCOL_LOCKDOWN\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\WantsParseDisplayName",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\WebView",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{55272A00-42CB-11CE-8135-00AA004BB851}\\ProxyStubClsid32\\(Default)",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\EnablePunycode",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Allow Programmatic Cut_Copy_Paste",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\2700",
"HKEY_CURRENT_USER\\Software\\Microsoft\\FTP\\Use Web Based FTP",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\2500",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\Interface\\{BCD1DE7E-2DB1-418B-B047-4A74E101F8C1}\\ProxyStubClsid32\\(Default)",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\MachineGuid",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\BrowseInPlace",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\Page_Transitions",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\IconsOnly",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\160A",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\SystemFileAssociations\\.html\\DocObject",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2\\2500",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\DisableScriptDebuggerIE",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FrameMerging",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3\\Flags",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LDAP\\LdapClientIntegrity",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\Security\\DisableSecuritySettingsCheck",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Always Use My Colors",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Settings\\Anchor Color Hover",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragScrollInterval",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\SeparateProcess",
"HKEY_CURRENT_USER\\FirefoxURL-E7CF176E110C211B\\shell\\open\\command\\(Default)",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragScrollInset",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\Icon",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\RecommendedLevel",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\DocObject",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Cleanup HTCs",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_SUBDOWNLOAD_LOCKDOWN\\*",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_UNC_SAVEDFILECHECK\\*",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\DragScrollDelay",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/bmp\\Bits\\0",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\WarnOnIntranet",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{B196B286-BAB4-101A-B69C-00AA00341D07}\\InprocServer32\\(Default)",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\CreateUriCacheSize",
"HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\WarnOnIntranet",
"HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\ComputerName\\ActiveComputerName\\ComputerName",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\SmoothScroll",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_BROWSER_EMULATION\\*",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\UseDropHandler",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\Show image placeholders",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\1201",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\NoFileFolderJunction",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_MSHTML_AUTOLOAD_IEFRAME\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Security\\DisableSecuritySettingsCheck",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1\\MinLevel",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/png\\Bits\\0",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FrameMerging",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Security_HKLM_only",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\FeatureControl\\FEATURE_BLOCK_LMZ_IMG\\a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\MIME\\Database\\Content Type\\image\/gif\\Bits\\0",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\EnablePunycode",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\PageSetup\\Print_Background",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\MapNetDrvBtn",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\4\\Flags",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\UseThemes",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\International\\Scripts\\3\\IEPropFontName",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Wow6432Node\\CLSID\\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\\ShellFolder\\HideOnDesktopPerUser",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\AllFilesystemObjects\\NeverShowExt",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\IsShortcut",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SQMClient\\Windows\\CEIPEnable",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoSimpleStartMenu",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Internet Explorer\\MAIN\\Enable AutoImageResize",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\Folder\\BrowseInPlace",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\CSS_Compat",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0\\160A"
],
"directory_enumerated": [
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Quick_Specs.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\system.js",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_tb.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Grey_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Network\\Connections\\Pbk\\rasphone.pbk",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Resume_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\compatibility.js",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\wizard.js",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\i18n.js",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\package.js",
"C:\\Windows\\System32\\ras\\*.pbk",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\tray.js",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\script\\main.js",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\default_wi.png",
"C:\\Users\\cuck\\AppData",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\BG.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\form.js",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\installer.js",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Loader.gif",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\logicBox.js",
"C:\\Users",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\menu.js",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\webBrowser.js",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\main.css",
"C:\\ProgramData\\Microsoft\\Network\\Connections\\Pbk\\rasphone.pbk",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css\\sdk-ui\\progress-bar.css",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\bootstrap_37556.html",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Color_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\libs\\idp.js",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\utils.js",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\ProgressBar.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\ui\\progressBar.js",
"C:\\Users\\cuck\\AppData\\Local",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\css",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\sponsored.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Pause_Button.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\debug.js",
"C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Network\\Connections\\Pbk\\*.pbk",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\script\\flow.js",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\libs\\json2.js",
"C:\\Users\\cuck",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\eventListener.js",
"C:\\ProgramData\\Microsoft\\Network\\Connections\\Pbk\\*.pbk",
"C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Progress.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\images\\Close.png",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\adManager.js",
"C:\\Users\\cuck\\AppData\\Local\\Temp\\ish43296828\\sdk\\application.js"
],
"regkey_written": [
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\EnableConsoleTracing",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadDecisionReason",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadDecision",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadNetworkName",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Cached\\{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} {000214E6-0000-0000-C000-000000000046} 0xFFFF",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\EnableFileTracing",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\DefaultConnectionSettings",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\MaxFileSize",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\FileTracingMask",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadDecisionTime",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\WpadLastNetwork",
"HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\FileDirectory",
"HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\RASMANCS\\ConsoleTracingMask"
]
},
"first_seen": 1562575985.5781,
"ppid": 2660
}
][
{
"markcount": 2,
"families": [],
"description": "Collects information to fingerprint the system (MachineGuid, DigitalProductId, SystemBiosDate)",
"severity": 1,
"marks": [
{
"category": "registry",
"ioc": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\MachineGuid",
"type": "ioc",
"description": null
},
{
"category": "registry",
"ioc": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Cryptography\\MachineGuid",
"type": "ioc",
"description": null
}
],
"references": [],
"name": "recon_fingerprint"
},
{
"markcount": 1,
"families": [],
"description": "Checks amount of memory in system, this can be used to detect virtual machines that have a low amount of memory available",
"severity": 1,
"marks": [
{
"call": {
"category": "system",
"status": 1,
"stacktrace": [],
"api": "GlobalMemoryStatusEx",
"return_value": 1,
"arguments": {},
"time": 1562575985.9371,
"tid": 2124,
"flags": {}
},
"pid": 2436,
"type": "call",
"cid": 1543
}
],
"references": [],
"name": "antivm_memory_available"
},
{
"markcount": 3,
"families": [],
"description": "The executable contains unknown PE section names indicative of a packer (could be a false positive)",
"severity": 1,
"marks": [
{
"category": "section",
"ioc": "CODE",
"type": "ioc",
"description": null
},
{
"category": "section",
"ioc": "DATA",
"type": "ioc",
"description": null
},
{
"category": "section",
"ioc": "BSS",
"type": "ioc",
"description": null
}
],
"references": [],
"name": "pe_features"
},
{
"markcount": 10,
"families": [],
"description": "Allocates read-write-execute memory (usually to unpack itself)",
"severity": 2,
"marks": [
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2436,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 40960,
"protection": 64,
"process_handle": "0xffffffff",
"base_address": "0x00401000"
},
"time": 1562575985.7181,
"tid": 2124,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2436,
"type": "call",
"cid": 0
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtAllocateVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2436,
"region_size": 720896,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"protection": 64,
"process_handle": "0xffffffff",
"allocation_type": 4096,
"base_address": "0x00730000"
},
"time": 1562575985.7181,
"tid": 2124,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE",
"allocation_type": "MEM_COMMIT"
}
},
"pid": 2436,
"type": "call",
"cid": 12
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2436,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 1,
"length": 819200,
"protection": 64,
"process_handle": "0xffffffff",
"base_address": "0x00901000"
},
"time": 1562575985.7501,
"tid": 2124,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2436,
"type": "call",
"cid": 159
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2436,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 1,
"length": 643072,
"protection": 64,
"process_handle": "0xffffffff",
"base_address": "0x009c9000"
},
"time": 1562575985.7501,
"tid": 2124,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 2436,
"type": "call",
"cid": 160
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtAllocateVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 2436,
"region_size": 4096,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"protection": 64,
"process_handle": "0xffffffff",
"allocation_type": 4096,
"base_address": "0x007f0000"
},
"time": 1562575985.7961,
"tid": 2124,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE",
"allocation_type": "MEM_COMMIT"
}
},
"pid": 2436,
"type": "call",
"cid": 852
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 816,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"length": 40960,
"protection": 64,
"process_handle": "0xffffffff",
"base_address": "0x00401000"
},
"time": 1562575988.1869,
"tid": 2256,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 816,
"type": "call",
"cid": 0
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtAllocateVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 816,
"region_size": 720896,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"protection": 64,
"process_handle": "0xffffffff",
"allocation_type": 4096,
"base_address": "0x00420000"
},
"time": 1562575988.1869,
"tid": 2256,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE",
"allocation_type": "MEM_COMMIT"
}
},
"pid": 816,
"type": "call",
"cid": 12
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 816,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 1,
"length": 819200,
"protection": 64,
"process_handle": "0xffffffff",
"base_address": "0x01dd1000"
},
"time": 1562575988.2029,
"tid": 2256,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 816,
"type": "call",
"cid": 159
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtProtectVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 816,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 1,
"length": 643072,
"protection": 64,
"process_handle": "0xffffffff",
"base_address": "0x01e99000"
},
"time": 1562575988.2029,
"tid": 2256,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE"
}
},
"pid": 816,
"type": "call",
"cid": 160
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtAllocateVirtualMemory",
"return_value": 0,
"arguments": {
"process_identifier": 816,
"region_size": 4096,
"stack_dep_bypass": 0,
"stack_pivoted": 0,
"heap_dep_bypass": 0,
"protection": 64,
"process_handle": "0xffffffff",
"allocation_type": 4096,
"base_address": "0x004d0000"
},
"time": 1562575988.2499,
"tid": 2256,
"flags": {
"protection": "PAGE_EXECUTE_READWRITE",
"allocation_type": "MEM_COMMIT"
}
},
"pid": 816,
"type": "call",
"cid": 852
}
],
"references": [],
"name": "allocates_rwx"
},
{
"markcount": 1,
"families": [],
"description": "A process attempted to delay the analysis task.",
"severity": 2,
"marks": [
{
"type": "generic",
"description": "a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin tried to sleep 170 seconds, actually delayed analysis time by 170 seconds"
}
],
"references": [],
"name": "antisandbox_sleep"
},
{
"markcount": 1,
"families": [],
"description": "Checks adapter addresses which can be used to detect virtual network interfaces",
"severity": 2,
"marks": [
{
"call": {
"category": "network",
"status": 0,
"stacktrace": [],
"last_error": 0,
"nt_status": -1073741772,
"api": "GetAdaptersAddresses",
"return_value": 111,
"arguments": {
"flags": 0,
"family": 0
},
"time": 1562575986.0621,
"tid": 2820,
"flags": {}
},
"pid": 2436,
"type": "call",
"cid": 2834
}
],
"references": [],
"name": "antivm_network_adapters"
},
{
"markcount": 1,
"families": [],
"description": "Expresses interest in specific running processes",
"severity": 2,
"marks": [
{
"category": "process",
"ioc": "a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880.bin",
"type": "ioc",
"description": null
}
],
"references": [],
"name": "process_interest"
},
{
"markcount": 2,
"families": [],
"description": "Terminates another process",
"severity": 2,
"marks": [
{
"call": {
"category": "process",
"status": 0,
"stacktrace": [],
"last_error": 0,
"nt_status": 0,
"api": "NtTerminateProcess",
"return_value": 0,
"arguments": {
"status_code": "0x00000103",
"process_identifier": 816,
"process_handle": "0x00000214"
},
"time": 1562575999.2811,
"tid": 2124,
"flags": {}
},
"pid": 2436,
"type": "call",
"cid": 6677
},
{
"call": {
"category": "process",
"status": 1,
"stacktrace": [],
"api": "NtTerminateProcess",
"return_value": 0,
"arguments": {
"status_code": "0x00000103",
"process_identifier": 816,
"process_handle": "0x00000214"
},
"time": 1562575999.2811,
"tid": 2124,
"flags": {}
},
"pid": 2436,
"type": "call",
"cid": 6678
}
],
"references": [],
"name": "terminates_remote_process"
},
{
"markcount": 5,
"families": [],
"description": "Sets or modifies WPAD proxy autoconfiguration file for traffic interception",
"severity": 3,
"marks": [
{
"call": {
"category": "registry",
"status": 1,
"stacktrace": [],
"api": "RegSetValueExA",
"return_value": 0,
"arguments": {
"key_handle": "0x000004d0",
"value": 1,
"regkey_r": "WpadDecisionReason",
"reg_type": 4,
"regkey": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadDecisionReason"
},
"time": 1562575986.7341,
"tid": 2820,
"flags": {
"reg_type": "REG_DWORD"
}
},
"pid": 2436,
"type": "call",
"cid": 4055
},
{
"call": {
"category": "registry",
"status": 1,
"stacktrace": [],
"api": "RegSetValueExA",
"return_value": 0,
"arguments": {
"key_handle": "0x000004d0",
"value": "\u00e0\u00c4\u009e\u009d\u00ad5\u00d5\u0001",
"regkey_r": "WpadDecisionTime",
"reg_type": 3,
"regkey": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadDecisionTime"
},
"time": 1562575986.7341,
"tid": 2820,
"flags": {
"reg_type": "REG_BINARY"
}
},
"pid": 2436,
"type": "call",
"cid": 4056
},
{
"call": {
"category": "registry",
"status": 1,
"stacktrace": [],
"api": "RegSetValueExA",
"return_value": 0,
"arguments": {
"key_handle": "0x000004d0",
"value": 3,
"regkey_r": "WpadDecision",
"reg_type": 4,
"regkey": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadDecision"
},
"time": 1562575986.7341,
"tid": 2820,
"flags": {
"reg_type": "REG_DWORD"
}
},
"pid": 2436,
"type": "call",
"cid": 4057
},
{
"call": {
"category": "registry",
"status": 1,
"stacktrace": [],
"api": "RegSetValueExW",
"return_value": 0,
"arguments": {
"key_handle": "0x000004d0",
"value": "Unidentified network",
"regkey_r": "WpadNetworkName",
"reg_type": 1,
"regkey": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}\\WpadNetworkName"
},
"time": 1562575986.7341,
"tid": 2820,
"flags": {
"reg_type": "REG_SZ"
}
},
"pid": 2436,
"type": "call",
"cid": 4058
},
{
"call": {
"category": "registry",
"status": 1,
"stacktrace": [],
"api": "RegSetValueExW",
"return_value": 0,
"arguments": {
"key_handle": "0x00000418",
"value": "{E34DF837-3A38-4E8C-83F4-ABF8AB3FB4A6}",
"regkey_r": "WpadLastNetwork",
"reg_type": 1,
"regkey": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad\\WpadLastNetwork"
},
"time": 1562575986.7341,
"tid": 2820,
"flags": {
"reg_type": "REG_SZ"
}
},
"pid": 2436,
"type": "call",
"cid": 4126
}
],
"references": [],
"name": "modifies_proxy_wpad"
}
]The Yara rules did not detect anything in the file.
{
"tls": [],
"udp": [
{
"src": "192.168.56.101",
"dst": "192.168.56.255",
"offset": 662,
"time": 6.2578480243683,
"dport": 137,
"sport": 137
},
{
"src": "192.168.56.101",
"dst": "192.168.56.255",
"offset": 5342,
"time": 12.396643161774,
"dport": 138,
"sport": 138
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 7186,
"time": 5.389858007431,
"dport": 5355,
"sport": 51001
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 7506,
"time": 4.1576540470123,
"dport": 5355,
"sport": 53595
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 7834,
"time": 6.278126001358,
"dport": 5355,
"sport": 53848
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 8162,
"time": 4.6621291637421,
"dport": 5355,
"sport": 54255
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 8490,
"time": 3.0445830821991,
"dport": 5355,
"sport": 55314
},
{
"src": "192.168.56.101",
"dst": "224.0.0.252",
"offset": 8818,
"time": 6.4014711380005,
"dport": 5355,
"sport": 55880
},
{
"src": "192.168.56.101",
"dst": "239.255.255.250",
"offset": 9146,
"time": 4.6740159988403,
"dport": 1900,
"sport": 1900
},
{
"src": "192.168.56.101",
"dst": "239.255.255.250",
"offset": 28556,
"time": 4.1755800247192,
"dport": 3702,
"sport": 49152
},
{
"src": "192.168.56.101",
"dst": "239.255.255.250",
"offset": 36940,
"time": 6.4004640579224,
"dport": 1900,
"sport": 53598
}
],
"dns_servers": [],
"http": [],
"icmp": [],
"smtp": [],
"tcp": [],
"smtp_ex": [],
"mitm": [],
"hosts": [],
"pcap_sha256": "f1316b1036a6aa0f430067c2ee4e1b86d50c7f3b4ba257f2e6841c52541a6f54",
"dns": [],
"http_ex": [],
"domains": [],
"dead_hosts": [],
"sorted_pcap_sha256": "9cc0c7a18cc1a577847e6c2cdfced92df4be355de5672019d139d8b0574d3bba",
"irc": [],
"https_ex": []
}









The instructions below shows how to remove iron25072014.exe with help from the FreeFixer removal tool. Basically, you install FreeFixer, scan your computer, check the iron25072014.exe file for removal, restart your computer and scan it again to verify that iron25072014.exe has been successfully removed. Here are the removal instructions in more detail:
| Property | Value |
|---|---|
| MD5 | 8a8092df66056fb72ae7ce95fe38d43e |
| SHA256 | a5d46f660bf8e154b44830e063b2df2280945d714b3b355c5e48761fd1d00880 |
These are some of the error messages that can appear related to iron25072014.exe:
iron25072014.exe has encountered a problem and needs to close. We are sorry for the inconvenience.
iron25072014.exe - Application Error. The instruction at "0xXXXXXXXX" referenced memory at "0xXXXXXXXX". The memory could not be "read/written". Click on OK to terminate the program.
has stopped working.
End Program - iron25072014.exe. This program is not responding.
iron25072014.exe is not a valid Win32 application.
iron25072014.exe - Application Error. The application failed to initialize properly (0xXXXXXXXX). Click OK to terminate the application.
To help other users, please let us know what you will do with the file:
Please share with the other users what you think about this file. What does this file do? Is it legitimate or something that your computer is better without? Do you know how it was installed on your system? Did you install it yourself or did it come bundled with some other software? Is it running smoothly or do you get some error message? Any information that will help to document this file is welcome. Thank you for your contributions.
I'm reading all new comments so don't hesitate to post a question about the file. If I don't have the answer perhaps another user can help you.
No comments posted yet.