Threat Database Adware Adware.Baidu

Adware.Baidu

By GoldSparrow in Adware
Translate To:

Threat Scorecard

Popularity Rank: 2,880
Threat Level: 20 % (Normal)
Infected Computers: 15,108
First Seen: July 24, 2009
Last Seen: January 31, 2026
OS(es) Affected: Windows

Adware.Baidu is an adware application created to deliver popup advertisements. Adware.Baidu is reported to be installed via Trojan downloaders and through Javascript drive-by downloads. Baidu is related to a search engine of Chinese origin. Adware.Baidu is also capable to collect and send information on your browsing patterns.

SpyHunter Detects & Remove Adware.Baidu

File System Details

Adware.Baidu may create the following file(s):
# File Name MD5 Detections
1. TheMatrix.scr 0697fed1e358d6fd1c97e9d9db40ebdb 3,864
2. bdupdate.exe 21e3ebc9aec62a5d2e1033594d6f13ab 3,705
3. A0109889.exe 08e09fb31437955849034d16a4594cc7 563
4. TTPlayer.exe 74fa381b42e80712e8907740cfa1ef4f 90
5. TTPlayer.lnk 989275d50b9121699067c065f098f1a7 84
6. winsys32_071106.dll 1285cdd314e057f7c758bbbd372bd563 0
7. scrsys16_071012.dll fc97129c51349a568da1bed8d0b9b42a 0
8. winsys16_071106.dll, scrsys16_071106.dll 918a8d845cd3f72c66e9452395fda517 0
More files

Analysis Report

General information

Family Name: Adware.Baidu
Signature status: No Signature

Known Samples

MD5: b5d8b339f9fdd3c3b6200d3f4306e920
SHA1: a024030dc357bec0362e817ab0ac50e876f3edc0
File Size: 4.45 MB, 4447763 bytes
MD5: 09affa706c6d509a59f29e5fe0022027
SHA1: 3f6ab836a20b7e3336330017ab7a24dd5470f317
SHA256: 23ACFC0C1371C75A8FFD0CDCB142634750E469B986463C542D42B3B73823CC08
File Size: 212.68 KB, 212684 bytes
MD5: df27b0974d3b01f8bf5e0d4b34d5353b
SHA1: 530f7c20168f2fdafe58a64f9faadb9eedbcff36
SHA256: 14EB3AD6D359EC012F2AE0E8C58E83DB5EE5689BEA6F945D5166894F1B1F0B4E
File Size: 3.66 MB, 3659399 bytes
MD5: 86d942bf0577f24016a22c2995207f9c
SHA1: 5cc346c2bc7174195c60271f57008aea269e21c8
SHA256: A3AE019F3932E4FEFC6065AFC90BDC6DA0FFD85A222B4FDA9A98C5223DC9B10A
File Size: 562.17 KB, 562167 bytes
MD5: 4941b0f8ef6609f06bef23e8d95962a8
SHA1: 44df2a7fe3e0359af3a6e9374f2d0cb3bbd19b0b
SHA256: DF6AB41C130C846B9A91D2FAB0388BF48674DF057EFCE525DAB3FC67127E1AC4
File Size: 770.05 KB, 770048 bytes
Show More
MD5: 9fa77f83659dd190594eb3fcae48be3f
SHA1: d0165a9c9aa36818930f7ceda1a70f37f4ea9d66
SHA256: C731E37A2B626EA57005607C1CF8F0F692F8D1C81DC66E8178322169A6EC38ED
File Size: 589.82 KB, 589824 bytes
MD5: b061634fa8c0c97d8849859007151b26
SHA1: 8f010cf8f1dd4b7c920616b7727c687055bac0db
SHA256: C6589774311A25E2C556DE2DB03B48D2D54CCC6F477AD95518B313EBF8F54136
File Size: 1.03 MB, 1030184 bytes
MD5: d1cd9c5a6ef0484655850ca88ac968ba
SHA1: da37d117eac37e59039471c8303b871e161fb75b
SHA256: 1BA5E81577EF022D5937DDDC5E19264D270434CCA8F98818DCD5E39C4A8A2A73
File Size: 1.05 MB, 1048576 bytes
MD5: 7f4cd3deadfd29e2642e7b0d8016c8dd
SHA1: 64e2da9ad744861d4d1d652cdaa9f268e57989c9
SHA256: 9842EACD107740C2749FB16D2F4D343E35764335220EB8D340C05E3763FDB88D
File Size: 531.91 KB, 531912 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Channel Name {ChannelName need to be replaced!}
Comments
  • BaiduYunguanjia Installer
  • Format Factory Media Tools
Company Name
  • Baidu
  • Baidu, Inc.
  • Free Time
File Description
  • Baidu Antivirus Uninstall
  • BaiduPlayer Setup
  • BaiduYunguanjia Installer
  • Format Factory Video/Audio/Picture Converter
File Version
  • 2008.3.11
  • 7.61.0.105
  • 7.60.5.106
  • 7.57.0.102
  • 4.4.4.78690
  • 3.6.0.0
  • 1.0.25.66
Legal Copyright
  • Baidu. All rights reserved.
  • Copyright (C) 2013 Baidu, Inc. All Rights Reserved.
  • Copyright (c) Baidu Company
  • Format Factory
Legal Trademarks Format Factory Application is a trademark of FreeTime
Product Name
  • Baidu Antivirus
  • BaiduPlayer Setup
  • BaiduYunguanjia Installer Application
  • Format Factory
  • normal
Product Version
  • 4.4.4.78690
  • 3.6.0.0
  • 1.0.25.66

Digital Signatures

Signer Root Status
Baidu Online Network Technology (Beijing) Co., Ltd. VeriSign Class 3 Code Signing 2009-2 CA Root Not Trusted
Baidu Online Network Technology (Beijing)Co., Ltd VeriSign Class 3 Code Signing 2010 CA Self Signed

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\program files (x86)\common files\installshield\professional\runtime\10\00\intel32\cto6339.tmp Generic Write,Read Attributes
c:\program files (x86)\common files\installshield\professional\runtime\10\00\intel32\cto6339.tmp Synchronize,Write Attributes
c:\program files (x86)\common files\installshield\professional\runtime\10\00\intel32\ctor.dll Synchronize,Write Data
c:\program files (x86)\common files\installshield\professional\runtime\10\00\intel32\dot62cb.tmp Generic Write,Read Attributes
c:\program files (x86)\common files\installshield\professional\runtime\10\00\intel32\dot62cb.tmp Synchronize,Write Attributes
c:\program files (x86)\common files\installshield\professional\runtime\10\00\intel32\dotnetinstaller.exe Synchronize,Write Data
c:\program files (x86)\common files\installshield\professional\runtime\10\00\intel32\igdi.dll Synchronize,Write Data
c:\program files (x86)\common files\installshield\professional\runtime\10\00\intel32\ike623d.tmp Generic Write,Read Attributes
c:\program files (x86)\common files\installshield\professional\runtime\10\00\intel32\ike623d.tmp Synchronize,Write Attributes
Show More
c:\program files (x86)\common files\installshield\professional\runtime\10\00\intel32\ikernel.dll Synchronize,Write Data
c:\program files (x86)\common files\installshield\professional\runtime\10\00\intel32\isc6398.tmp Generic Write,Read Attributes
c:\program files (x86)\common files\installshield\professional\runtime\10\00\intel32\isc6398.tmp Synchronize,Write Attributes
c:\program files (x86)\common files\installshield\professional\runtime\10\00\intel32\iscript.dll Synchronize,Write Data
c:\program files (x86)\common files\installshield\professional\runtime\10\00\intel32\isp5e5f.tmp\setup.dll Synchronize,Write Data
c:\program files (x86)\common files\installshield\professional\runtime\10\00\intel32\isp5e5f.tmp\temp.000 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files (x86)\common files\installshield\professional\runtime\10\00\intel32\isp6027.tmp\igdi.dll Synchronize,Write Attributes
c:\program files (x86)\common files\installshield\professional\runtime\10\00\intel32\isp6027.tmp\igdi.dll Synchronize,Write Data
c:\program files (x86)\common files\installshield\professional\runtime\10\00\intel32\isp6027.tmp\temp.000 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\program files (x86)\common files\installshield\professional\runtime\10\00\intel32\ius63f7.tmp Generic Write,Read Attributes
c:\program files (x86)\common files\installshield\professional\runtime\10\00\intel32\ius63f7.tmp Synchronize,Write Attributes
c:\program files (x86)\common files\installshield\professional\runtime\10\00\intel32\iuser.dll Synchronize,Write Data
c:\program files (x86)\common files\installshield\professional\runtime\10\00\intel32\set5e6f.tmp Generic Write,Read Attributes
c:\program files (x86)\common files\installshield\professional\runtime\10\00\intel32\setup.dll Synchronize,Write Data
c:\program files (x86)\common files\installshield\professional\runtime\ikernel.rgs Generic Write,Read Attributes
c:\program files (x86)\common files\installshield\professional\runtime\ikernel.rgs Synchronize,Write Attributes
c:\program files (x86)\common files\installshield\professional\runtime\isp6446.tmp Generic Write,Read Attributes
c:\program files (x86)\common files\installshield\professional\runtime\isp6446.tmp Synchronize,Write Attributes
c:\program files (x86)\common files\installshield\professional\runtime\isprobe.tlb Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\program files (x86)\common files\installshield\professional\runtime\obj64a5.tmp Generic Write,Read Attributes
c:\program files (x86)\common files\installshield\professional\runtime\obj64a5.tmp Synchronize,Write Attributes
c:\program files (x86)\common files\installshield\professional\runtime\objectps.dll Synchronize,Write Data
c:\users\user\appdata\local\temp\6793.rra Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\_se6096.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\bye5b6f.tmp\disk1\data1.cab Generic Write,Read Attributes
c:\users\user\appdata\local\temp\bye5b6f.tmp\disk1\data1.hdr Generic Write,Read Attributes
c:\users\user\appdata\local\temp\bye5b6f.tmp\disk1\engine32.cab Generic Write,Read Attributes
c:\users\user\appdata\local\temp\bye5b6f.tmp\disk1\layout.bin Generic Write,Read Attributes
c:\users\user\appdata\local\temp\bye5b6f.tmp\disk1\setup.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\bye5b6f.tmp\disk1\setup.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\bye5b6f.tmp\disk1\setup.ibt Generic Write,Read Attributes
c:\users\user\appdata\local\temp\bye5b6f.tmp\disk1\setup.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\bye5b6f.tmp\disk1\setup.inx Generic Write,Read Attributes
c:\users\user\appdata\local\temp\igd6047.tmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\isp6016.tmp\_setup.dll Synchronize,Write Data
c:\users\user\appdata\local\temp\isp6016.tmp\temp.000 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\ispackfiles.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\iss5d54.tmp\setup.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsa61b2.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\nsabb38.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\nsgbd7a.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\nsp60d7.tmp Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete
c:\users\user\appdata\local\temp\nsq61c3.tmp Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsq61c3.tmp\system.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsq61c3.tmp\system.dll Synchronize,Write Attributes
c:\users\user\appdata\local\temp\nsu56ec.tmp\drwsetup.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsvbd8a.tmp\installoptions.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsvbd8a.tmp\iospecial.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\nsvbd8a.tmp\iospecial.ini Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsvbd8a.tmp\modern-header.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsvbd8a.tmp\modern-wizard.bmp Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsvbd8a.tmp\nsskinengine.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\nsvbd8a.tmp\system.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\~nsu.tmp\au_.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3119368278-1123331430-659265220-1001\05142823b0f8a9b87ae059162bfb4b1b_bfeb5820-9643-42ad-a79f-071dff4d8e64 Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\classes\wow6432node\clsid\{f4817e4b-04b6-11d3-8862-00c04f72f303}\inprocserver32:: C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\Objectps.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{f4817e4b-04b6-11d3-8862-00c04f72f303}\inprocserver32::threadingmodel Both RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{f4817e4b-04b6-11d3-8862-00c04f72f303}:: PSFactoryBuffer RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{f4817e4b-04b6-11d3-8862-00c04f72f303}\proxystubclsid32:: {F4817E4B-04B6-11D3-8862-00C04F72F303} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{f4817e4b-04b6-11d3-8862-00c04f72f303}:: ISetupServiceProvider RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{f4817e4b-04b6-11d3-8862-00c04f72f303}\nummethods:: 6 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{9b697780-dbbc-11d2-80c7-00104b1f6cea}\proxystubclsid32:: {F4817E4B-04B6-11D3-8862-00C04F72F303} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{9b697780-dbbc-11d2-80c7-00104b1f6cea}:: ISetupObjectClass RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{9b697780-dbbc-11d2-80c7-00104b1f6cea}\nummethods:: 5 RegNtPreCreateKey
HKLM\software\classes\typelib\{94636247-bc39-4b8b-a728-2d1fbebfa76a}\1.0:: InstallShield DevStudio Setup Kernel RegNtPreCreateKey
Show More
HKLM\software\classes\typelib\{94636247-bc39-4b8b-a728-2d1fbebfa76a}\1.0\flags:: 0 RegNtPreCreateKey
HKLM\software\classes\typelib\{94636247-bc39-4b8b-a728-2d1fbebfa76a}\1.0\0\win32:: C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime\IsProBE.tlb RegNtPreCreateKey
HKLM\software\classes\typelib\{94636247-bc39-4b8b-a728-2d1fbebfa76a}\1.0\helpdir:: C:\Program Files (x86)\Common Files\InstallShield\Professional\RunTime RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2068-cb55-11d2-8094-00104b1f9838}:: ISetupTransferEvents RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2068-cb55-11d2-8094-00104b1f9838}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2068-cb55-11d2-8094-00104b1f9838}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2068-cb55-11d2-8094-00104b1f9838}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2068-cb55-11d2-8094-00104b1f9838}:: ISetupTransferEvents RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2068-cb55-11d2-8094-00104b1f9838}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2068-cb55-11d2-8094-00104b1f9838}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2068-cb55-11d2-8094-00104b1f9838}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2066-cb55-11d2-8094-00104b1f9838}:: ISetupFeature RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2066-cb55-11d2-8094-00104b1f9838}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2066-cb55-11d2-8094-00104b1f9838}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2066-cb55-11d2-8094-00104b1f9838}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2066-cb55-11d2-8094-00104b1f9838}:: ISetupFeature RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2066-cb55-11d2-8094-00104b1f9838}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2066-cb55-11d2-8094-00104b1f9838}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2066-cb55-11d2-8094-00104b1f9838}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{cc096170-e2cb-11d2-80c8-00104b1f6cea}:: ISetupBasicFeature RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{cc096170-e2cb-11d2-80c8-00104b1f6cea}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{cc096170-e2cb-11d2-80c8-00104b1f6cea}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{cc096170-e2cb-11d2-80c8-00104b1f6cea}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{cc096170-e2cb-11d2-80c8-00104b1f6cea}:: ISetupBasicFeature RegNtPreCreateKey
HKLM\software\classes\interface\{cc096170-e2cb-11d2-80c8-00104b1f6cea}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{cc096170-e2cb-11d2-80c8-00104b1f6cea}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{cc096170-e2cb-11d2-80c8-00104b1f6cea}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b11-e59d-11d2-b40b-00a024b9dddd}:: ISetupFeatureLog RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b11-e59d-11d2-b40b-00a024b9dddd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b11-e59d-11d2-b40b-00a024b9dddd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b11-e59d-11d2-b40b-00a024b9dddd}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b11-e59d-11d2-b40b-00a024b9dddd}:: ISetupFeatureLog RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b11-e59d-11d2-b40b-00a024b9dddd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b11-e59d-11d2-b40b-00a024b9dddd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b11-e59d-11d2-b40b-00a024b9dddd}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b13-e59d-11d2-b40b-00a024b9dddd}:: ISetupFeatureLogs RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b13-e59d-11d2-b40b-00a024b9dddd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b13-e59d-11d2-b40b-00a024b9dddd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b13-e59d-11d2-b40b-00a024b9dddd}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b13-e59d-11d2-b40b-00a024b9dddd}:: ISetupFeatureLogs RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b13-e59d-11d2-b40b-00a024b9dddd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b13-e59d-11d2-b40b-00a024b9dddd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b13-e59d-11d2-b40b-00a024b9dddd}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b12-e59d-11d2-b40b-00a024b9dddd}:: ISetupOpSequence RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b12-e59d-11d2-b40b-00a024b9dddd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b12-e59d-11d2-b40b-00a024b9dddd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b12-e59d-11d2-b40b-00a024b9dddd}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b12-e59d-11d2-b40b-00a024b9dddd}:: ISetupOpSequence RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b12-e59d-11d2-b40b-00a024b9dddd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b12-e59d-11d2-b40b-00a024b9dddd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b12-e59d-11d2-b40b-00a024b9dddd}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b10-e59d-11d2-b40b-00a024b9dddd}:: ISetupLogDB RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b10-e59d-11d2-b40b-00a024b9dddd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b10-e59d-11d2-b40b-00a024b9dddd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b10-e59d-11d2-b40b-00a024b9dddd}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b10-e59d-11d2-b40b-00a024b9dddd}:: ISetupLogDB RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b10-e59d-11d2-b40b-00a024b9dddd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b10-e59d-11d2-b40b-00a024b9dddd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b10-e59d-11d2-b40b-00a024b9dddd}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b16-e59d-11d2-b40b-00a024b9dddd}:: ISetupOpTypes RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b16-e59d-11d2-b40b-00a024b9dddd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b16-e59d-11d2-b40b-00a024b9dddd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b16-e59d-11d2-b40b-00a024b9dddd}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b16-e59d-11d2-b40b-00a024b9dddd}:: ISetupOpTypes RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b16-e59d-11d2-b40b-00a024b9dddd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b16-e59d-11d2-b40b-00a024b9dddd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b16-e59d-11d2-b40b-00a024b9dddd}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b15-e59d-11d2-b40b-00a024b9dddd}:: ISetupOpType RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b15-e59d-11d2-b40b-00a024b9dddd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b15-e59d-11d2-b40b-00a024b9dddd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{8c3c1b15-e59d-11d2-b40b-00a024b9dddd}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b15-e59d-11d2-b40b-00a024b9dddd}:: ISetupOpType RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b15-e59d-11d2-b40b-00a024b9dddd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b15-e59d-11d2-b40b-00a024b9dddd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{8c3c1b15-e59d-11d2-b40b-00a024b9dddd}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{2583251f-0a04-11d3-886b-00c04f72f303}:: ISetupBasicFeatureStateEvents RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{2583251f-0a04-11d3-886b-00c04f72f303}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{2583251f-0a04-11d3-886b-00c04f72f303}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{2583251f-0a04-11d3-886b-00c04f72f303}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{2583251f-0a04-11d3-886b-00c04f72f303}:: ISetupBasicFeatureStateEvents RegNtPreCreateKey
HKLM\software\classes\interface\{2583251f-0a04-11d3-886b-00c04f72f303}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{2583251f-0a04-11d3-886b-00c04f72f303}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{2583251f-0a04-11d3-886b-00c04f72f303}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2065-cb55-11d2-8094-00104b1f9838}:: ISetupFeatures RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2065-cb55-11d2-8094-00104b1f9838}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2065-cb55-11d2-8094-00104b1f9838}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{aa7e2065-cb55-11d2-8094-00104b1f9838}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2065-cb55-11d2-8094-00104b1f9838}:: ISetupFeatures RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2065-cb55-11d2-8094-00104b1f9838}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2065-cb55-11d2-8094-00104b1f9838}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{aa7e2065-cb55-11d2-8094-00104b1f9838}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{be6115a1-7de5-48dc-ad2a-25060e00fce2}:: ISetupTransferEvents2 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{be6115a1-7de5-48dc-ad2a-25060e00fce2}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{be6115a1-7de5-48dc-ad2a-25060e00fce2}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{be6115a1-7de5-48dc-ad2a-25060e00fce2}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{be6115a1-7de5-48dc-ad2a-25060e00fce2}:: ISetupTransferEvents2 RegNtPreCreateKey
HKLM\software\classes\interface\{be6115a1-7de5-48dc-ad2a-25060e00fce2}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{be6115a1-7de5-48dc-ad2a-25060e00fce2}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{be6115a1-7de5-48dc-ad2a-25060e00fce2}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{ba24e1da-9e87-4502-9af0-b5ddfa6d6b23}:: ISetupTransferEvents3 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{ba24e1da-9e87-4502-9af0-b5ddfa6d6b23}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{ba24e1da-9e87-4502-9af0-b5ddfa6d6b23}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{ba24e1da-9e87-4502-9af0-b5ddfa6d6b23}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{ba24e1da-9e87-4502-9af0-b5ddfa6d6b23}:: ISetupTransferEvents3 RegNtPreCreateKey
HKLM\software\classes\interface\{ba24e1da-9e87-4502-9af0-b5ddfa6d6b23}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{ba24e1da-9e87-4502-9af0-b5ddfa6d6b23}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{ba24e1da-9e87-4502-9af0-b5ddfa6d6b23}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{6b15a454-9067-4878-b10e-b9dffe03049d}:: ISetupLogDB2 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{6b15a454-9067-4878-b10e-b9dffe03049d}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{6b15a454-9067-4878-b10e-b9dffe03049d}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{6b15a454-9067-4878-b10e-b9dffe03049d}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{6b15a454-9067-4878-b10e-b9dffe03049d}:: ISetupLogDB2 RegNtPreCreateKey
HKLM\software\classes\interface\{6b15a454-9067-4878-b10e-b9dffe03049d}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{6b15a454-9067-4878-b10e-b9dffe03049d}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{6b15a454-9067-4878-b10e-b9dffe03049d}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{a36ecfbe-faaa-417d-9d41-7fef98fde554}:: ISetupOpSequence2 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{a36ecfbe-faaa-417d-9d41-7fef98fde554}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{a36ecfbe-faaa-417d-9d41-7fef98fde554}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{a36ecfbe-faaa-417d-9d41-7fef98fde554}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{a36ecfbe-faaa-417d-9d41-7fef98fde554}:: ISetupOpSequence2 RegNtPreCreateKey
HKLM\software\classes\interface\{a36ecfbe-faaa-417d-9d41-7fef98fde554}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{a36ecfbe-faaa-417d-9d41-7fef98fde554}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{a36ecfbe-faaa-417d-9d41-7fef98fde554}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{4d08a70c-42e4-4238-af79-7a7485c66ee2}:: ISetupScriptDebugEngineOld_2 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{4d08a70c-42e4-4238-af79-7a7485c66ee2}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{4d08a70c-42e4-4238-af79-7a7485c66ee2}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{4d08a70c-42e4-4238-af79-7a7485c66ee2}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{4d08a70c-42e4-4238-af79-7a7485c66ee2}:: ISetupScriptDebugEngineOld_2 RegNtPreCreateKey
HKLM\software\classes\interface\{4d08a70c-42e4-4238-af79-7a7485c66ee2}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{4d08a70c-42e4-4238-af79-7a7485c66ee2}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{4d08a70c-42e4-4238-af79-7a7485c66ee2}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{b310295d-e006-4e5a-9cbe-fa7c092f2fc3}:: ISetupScriptStackFrameOld_2 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{b310295d-e006-4e5a-9cbe-fa7c092f2fc3}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{b310295d-e006-4e5a-9cbe-fa7c092f2fc3}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{b310295d-e006-4e5a-9cbe-fa7c092f2fc3}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{b310295d-e006-4e5a-9cbe-fa7c092f2fc3}:: ISetupScriptStackFrameOld_2 RegNtPreCreateKey
HKLM\software\classes\interface\{b310295d-e006-4e5a-9cbe-fa7c092f2fc3}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{b310295d-e006-4e5a-9cbe-fa7c092f2fc3}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{b310295d-e006-4e5a-9cbe-fa7c092f2fc3}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{9e274dca-9b35-4b99-904f-76f2c5b59f76}:: ISetupScriptErrorOld_2 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{9e274dca-9b35-4b99-904f-76f2c5b59f76}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{9e274dca-9b35-4b99-904f-76f2c5b59f76}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{9e274dca-9b35-4b99-904f-76f2c5b59f76}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{9e274dca-9b35-4b99-904f-76f2c5b59f76}:: ISetupScriptErrorOld_2 RegNtPreCreateKey
HKLM\software\classes\interface\{9e274dca-9b35-4b99-904f-76f2c5b59f76}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{9e274dca-9b35-4b99-904f-76f2c5b59f76}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{9e274dca-9b35-4b99-904f-76f2c5b59f76}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{7fa3f3d3-7b9e-4f51-9448-3642b544cebd}:: ISetupScriptDebuggerOld_2 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{7fa3f3d3-7b9e-4f51-9448-3642b544cebd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{7fa3f3d3-7b9e-4f51-9448-3642b544cebd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{7fa3f3d3-7b9e-4f51-9448-3642b544cebd}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{7fa3f3d3-7b9e-4f51-9448-3642b544cebd}:: ISetupScriptDebuggerOld_2 RegNtPreCreateKey
HKLM\software\classes\interface\{7fa3f3d3-7b9e-4f51-9448-3642b544cebd}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{7fa3f3d3-7b9e-4f51-9448-3642b544cebd}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{7fa3f3d3-7b9e-4f51-9448-3642b544cebd}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{3dfe4f8f-a5a1-4eca-9a50-e5cf9ba836e9}:: ISetupScriptDebuggerOld2_2 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{3dfe4f8f-a5a1-4eca-9a50-e5cf9ba836e9}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{3dfe4f8f-a5a1-4eca-9a50-e5cf9ba836e9}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{3dfe4f8f-a5a1-4eca-9a50-e5cf9ba836e9}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{3dfe4f8f-a5a1-4eca-9a50-e5cf9ba836e9}:: ISetupScriptDebuggerOld2_2 RegNtPreCreateKey
HKLM\software\classes\interface\{3dfe4f8f-a5a1-4eca-9a50-e5cf9ba836e9}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{3dfe4f8f-a5a1-4eca-9a50-e5cf9ba836e9}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{3dfe4f8f-a5a1-4eca-9a50-e5cf9ba836e9}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{084a0737-26b9-4433-8007-a9161333b5fc}:: ISetupScriptDebugEngineOld RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{084a0737-26b9-4433-8007-a9161333b5fc}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{084a0737-26b9-4433-8007-a9161333b5fc}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{084a0737-26b9-4433-8007-a9161333b5fc}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{084a0737-26b9-4433-8007-a9161333b5fc}:: ISetupScriptDebugEngineOld RegNtPreCreateKey
HKLM\software\classes\interface\{084a0737-26b9-4433-8007-a9161333b5fc}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{084a0737-26b9-4433-8007-a9161333b5fc}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{084a0737-26b9-4433-8007-a9161333b5fc}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{9aee3f7a-a79f-4b41-bc48-e7946ffeab35}:: ISetupScriptStackFrameOld RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{9aee3f7a-a79f-4b41-bc48-e7946ffeab35}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{9aee3f7a-a79f-4b41-bc48-e7946ffeab35}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{9aee3f7a-a79f-4b41-bc48-e7946ffeab35}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{9aee3f7a-a79f-4b41-bc48-e7946ffeab35}:: ISetupScriptStackFrameOld RegNtPreCreateKey
HKLM\software\classes\interface\{9aee3f7a-a79f-4b41-bc48-e7946ffeab35}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{9aee3f7a-a79f-4b41-bc48-e7946ffeab35}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{9aee3f7a-a79f-4b41-bc48-e7946ffeab35}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{1ed19966-1493-4539-b9f5-97a6556ce8f8}:: ISetupScriptErrorOld RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{1ed19966-1493-4539-b9f5-97a6556ce8f8}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{1ed19966-1493-4539-b9f5-97a6556ce8f8}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{1ed19966-1493-4539-b9f5-97a6556ce8f8}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\interface\{1ed19966-1493-4539-b9f5-97a6556ce8f8}:: ISetupScriptErrorOld RegNtPreCreateKey
HKLM\software\classes\interface\{1ed19966-1493-4539-b9f5-97a6556ce8f8}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\interface\{1ed19966-1493-4539-b9f5-97a6556ce8f8}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey
HKLM\software\classes\interface\{1ed19966-1493-4539-b9f5-97a6556ce8f8}\typelib::version 1.0 RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{17773851-7ff4-44c1-b084-1e1edb2bfd4d}:: ISetupScriptDebuggerOld RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{17773851-7ff4-44c1-b084-1e1edb2bfd4d}\proxystubclsid32:: {00020424-0000-0000-C000-000000000046} RegNtPreCreateKey
HKLM\software\classes\wow6432node\interface\{17773851-7ff4-44c1-b084-1e1edb2bfd4d}\typelib:: {94636247-BC39-4B8B-A728-2D1FBEBFA76A} RegNtPreCreateKey

703 additional registry modifications are not displayed above.

Windows API Usage

Category API
Anti Debug
  • IsDebuggerPresent
User Data Access
  • GetUserObjectInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Process Shell Execute
  • CreateProcess
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Other Suspicious
  • AdjustTokenPrivileges

Shell Command Execution

C:\Users\Wqihzbpg\AppData\Local\Temp\nsu56EC.tmp\drwsetup.exe
C:\Users\Wqihzbpg\AppData\Local\Temp\nsu56EC.tmp\drwsetup.exe -deleter
"C:\Users\Kfayuxji\AppData\Local\Temp\~nsu.tmp\Au_.exe" _?=c:\users\user\downloads\
"c:\users\user\downloads\uninstall.exe" /KEEPINSTDIR _?=c:\users\user\downloads
"C:\Users\Icirxgde\AppData\Local\Temp\~nsu.tmp\Au_.exe" _?=c:\users\user\downloads\

Trending

Most Viewed

Loading...