IOC Report
plotdemo.exe

loading gif

Files

File Path
Type
Category
Malicious
plotdemo.exe
PE32 executable (GUI) Intel 80386, for MS Windows
initial sample
C:\Program Files (x86)\PSI\PSIPLOT\PSIPLOT.EXE
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Windows\Installer\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}\NewShortcut3_B94EC0BE542B4F308679E8D52BAD769F.htm
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
malicious
C:\Config.Msi\5ee892.rbs
data
modified
C:\Program Files (x86)\PSI\PSIPLOT\$LASTTSM.TSM
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\$PSFIT.EQN
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\BLUE.CLR
Generic INItialization configuration [LINE_COLOR_RGB]
dropped
C:\Program Files (x86)\PSI\PSIPLOT\BLUE_INV.CLR
Generic INItialization configuration [LINE_COLOR_RGB]
dropped
C:\Program Files (x86)\PSI\PSIPLOT\CHEMSTIF.ODE
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\DEFAULT.CLR
Generic INItialization configuration [LINE_COLOR_RGB]
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\A010013L.PFB
PostScript Type 1 font program data (URWGothicL-Book 1.05)
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\A010015L.PFB
PostScript Type 1 font program data (URWGothicL-Demi 1.05)
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\A010033L.PFB
PostScript Type 1 font program data (URWGothicL-BookObli 1.05)
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\A010035L.PFB
PostScript Type 1 font program data (URWGothicL-DemiObli 1.05)
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\ACCTEST.PS
PostScript document text
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\ADDXCHAR.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\ALIGN.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\Agrement.rtf
Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\B018012L.PFB
PostScript Type 1 font program data (URWBookmanL-Ligh 1.05)
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\B018015L.PFB
PostScript Type 1 font program data (URWBookmanL-DemiBold 1.05)
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\B018032L.PFB
PostScript Type 1 font program data (URWBookmanL-LighItal 1.05)
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\B018035L.PFB
PostScript Type 1 font program data (URWBookmanL-DemiBoldItal 1.05)
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\BDFTOPS.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\C059013L.PFB
PostScript Type 1 font program data (CenturySchL-Roma 1.05)
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\C059016L.PFB
PostScript Type 1 font program data (CenturySchL-Bold 1.05)
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\C059033L.PFB
PostScript Type 1 font program data (CenturySchL-Ital 1.05)
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\C059036L.PFB
PostScript Type 1 font program data (CenturySchL-BoldItal 1.05)
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\CAPTION.PS
PostScript document text
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\CID2CODE.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\COPYING
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\D050000L.PFB
PostScript Type 1 font program data (Dingbats 001.005)
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\DECRYPT.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\DOCIE.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\ERRPAGE.PS
PostScript document text
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\FONT2C.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\FONT2PCL.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\Fontmap
PostScript document text
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\Fontmap.GS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GSDLL32.DLL
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GSLP.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GSNUP.PS
PostScript document text
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GSWIN32C.EXE
PE32 executable (console) Intel 80386, for MS Windows
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_AGL.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_BTOKN.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_CCFNT.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_CE_E.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_CFF.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_CIDCM.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_CIDFN.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_CMAP.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_CMDL.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_CSS_E.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_DBT_E.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_DISKF.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_DPNXT.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_DPS.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_DPS1.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_DPS2.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_DSCP.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_EPSF.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_FFORM.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_FONTS.PS
assembler source, ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_FRSD.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_ICC.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_IL1_E.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_IL2_E.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_INIT.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_KANJI.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_KSB_E.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_L2IMG.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_LEV2.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_LGO_E.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_LGX_E.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_LL3.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_MEX_E.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_MGL_E.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_MRO_E.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_PDF_E.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_PFILE.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_RDLIN.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_RES.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_SETPD.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_STATD.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_STD_E.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_SYM_E.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_TRAP.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_TTF.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_TYP32.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_TYP42.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_TYPE1.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_WAN_E.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_WL1_E.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_WL2_E.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GS_WL5_E.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\Gs_pdfwr.ps
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\HT_CCSTO.PS
PostScript document text
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\IMAGE-QA.PS
PostScript document text
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\IMPATH.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\JISPAPER.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\LANDSCAP.PS
PostScript document text
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\LEVEL1.PS
PostScript document text
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\LINES.PS
PostScript document text
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\MARKHINT.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\MARKPATH.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\N019003L.PFB
PostScript Type 1 font program data (NimbusSanL-Regu 1.05)
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\N019004L.PFB
PostScript Type 1 font program data (NimbusSanL-Bold 1.05)
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\N019023L.PFB
PostScript Type 1 font program data (NimbusSanL-ReguItal 1.05)
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\N019024L.PFB
PostScript Type 1 font program data (NimbusSanL-BoldItal 1.05)
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\N019043L.PFB
PostScript Type 1 font program data (NimbusSanL-ReguCond 1.05)
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\N019044L.PFB
PostScript Type 1 font program data (NimbusSanL-BoldCond 1.05)
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\N019063L.PFB
PostScript Type 1 font program data (NimbusSanL-ReguCondItal 1.05)
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\N019064L.PFB
PostScript Type 1 font program data (NimbusSanL-BoldCondItal 1.05)
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\N021003L.PFB
PostScript Type 1 font program data (NimbusRomNo9L-Regu 1.05)
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\N021004L.PFB
PostScript Type 1 font program data (NimbusRomNo9L-Medi 1.05)
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\N021023L.PFB
PostScript Type 1 font program data (NimbusRomNo9L-ReguItal 1.05)
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\N021024L.PFB
PostScript Type 1 font program data (NimbusRomNo9L-MediItal 1.05)
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\N022003L.PFB
PostScript Type 1 font program data (NimbusMonL-Regu 1.05)
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\N022004L.PFB
PostScript Type 1 font program data (NimbusMonL-Bold 1.05)
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\N022023L.PFB
PostScript Type 1 font program data (NimbusMonL-ReguObli 1.05)
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\N022024L.PFB
PostScript Type 1 font program data (NimbusMonL-BoldObli 1.05)
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\P052003L.PFB
PostScript Type 1 font program data (URWPalladioL-Roma 1.05)
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\P052004L.PFB
PostScript Type 1 font program data (URWPalladioL-Bold 1.05)
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\P052023L.PFB
PostScript Type 1 font program data (URWPalladioL-Ital 1.05)
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\P052024L.PFB
PostScript Type 1 font program data (URWPalladioL-BoldItal 1.05)
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\PACKFILE.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\PCHARSTR.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\PDF2DSC.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\PDFOPT.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\PDFWRITE.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\PDF_BASE.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\PDF_DRAW.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\PDF_FONT.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\PDF_MAIN.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\PDF_OPS.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\PDF_SEC.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\PF2AFM.PS
PostScript document text
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\PFBTOPFA.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\PPATH.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\PPHS.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\PRFONT.PS
PostScript document text
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\PRINTAFM.PS
PostScript document text
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\QUIT.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\ROLLCONV.PS
PostScript document text
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\S050000L.PFB
PostScript Type 1 font program data (StandardSymL 001.005)
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\SHOWCHAR.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\SHOWPAGE.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\STCINFO.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\STCOLOR.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\STOCHT.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\TRACEIMG.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\TRACEOP.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\TYPE1ENC.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\TYPE1OPS.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\UNINFO.PS
PostScript document text
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\UNPROT.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\VIEWCMYK.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\VIEWGIF.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\VIEWJPEG.PS
PostScript document text
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\VIEWMIFF.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\VIEWPBM.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\VIEWPCX.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\VIEWPS2A.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\WFTOPFA.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\WINMAPS.PS
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\WRFONT.PS
assembler source, ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\Z003034L.PFB
PostScript Type 1 font program data (URWChanceryL-MediItal 1.05)
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\ZEROLINE.PS
PostScript document text
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\readme.rtf
Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GRAY.CLR
Generic INItialization configuration [LINE_COLOR_RGB]
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GRAY_INV.CLR
Generic INItialization configuration [LINE_COLOR_RGB]
dropped
C:\Program Files (x86)\PSI\PSIPLOT\GdiPlus.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
C:\Program Files (x86)\PSI\PSIPLOT\HALFSPCT.CLR
Generic INItialization configuration [LINE_COLOR_RGB]
dropped
C:\Program Files (x86)\PSI\PSIPLOT\HALF_INV.CLR
Generic INItialization configuration [LINE_COLOR_RGB]
dropped
C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files (x86)\PSI\PSIPLOT\LESSN10A.EQN
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\LESSN10A.PDW
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\LESSN10B.EQN
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\LESSN10B.PDW
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\LESSN10C.EQN
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\LESSN10D.EQN
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\LESSN14A.PDW
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\LESSON1.PDW
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\LESSON10.EQN
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\LESSON10.PDW
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\LESSON14.PDW
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\LESSON2.PDW
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\LESSON3.PDW
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\LESSON4.PDW
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\LESSON6.XLS
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\LESSON7.PDW
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\LESSON7B.PDW
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\LESSON8.PDW
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\LESSON9.PDW
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\LNSPEC.CLR
Generic INItialization configuration [LINE_COLOR_RGB]
dropped
C:\Program Files (x86)\PSI\PSIPLOT\LNSPEC1.CLR
Generic INItialization configuration [LINE_COLOR_RGB]
dropped
C:\Program Files (x86)\PSI\PSIPLOT\LORENZ.ODE
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\Macro\lesson18.pmw
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\PLT8HKEY.DAT
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\POSTSCRP\ICONLIB.DLL
MS-DOS executable, NE for MS Windows 3.x (DLL or font)
dropped
C:\Program Files (x86)\PSI\PSIPLOT\POSTSCRP\PS5UI.DLL
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
C:\Program Files (x86)\PSI\PSIPLOT\POSTSCRP\PSCRIPT.DRV
MS-DOS executable, NE for MS Windows 3.x (DLL or font)
dropped
C:\Program Files (x86)\PSI\PSIPLOT\POSTSCRP\PSCRIPT.HLP
MS Windows 3.1 help, Tue Apr 17 13:11:49 2001, 26038 bytes
dropped
C:\Program Files (x86)\PSI\PSIPLOT\POSTSCRP\PSCRIPT.NTF
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\POSTSCRP\PSCRIPT.SPD
PPD file, version "4.3"
dropped
C:\Program Files (x86)\PSI\PSIPLOT\POSTSCRP\PSCRIPT1.SPD
PPD file, version "4.0"
dropped
C:\Program Files (x86)\PSI\PSIPLOT\POSTSCRP\PSCRIPT5.DLL
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
C:\Program Files (x86)\PSI\PSIPLOT\POSTSCRP\PSIPSCRP.PPD
PPD file, version "4.3"
dropped
C:\Program Files (x86)\PSI\PSIPLOT\POSTSCRP\PSMON.DLL
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Program Files (x86)\PSI\PSIPLOT\POSTSCRP\TMFONTS.MFM
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\POSTSCRP\WIN95HLP.HLP
MS Windows 3.1 help, Fri Nov 7 22:55:00 1997, 21066 bytes
dropped
C:\Program Files (x86)\PSI\PSIPLOT\POSTSCRP\WinEx\PS5UI.DLL
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Program Files (x86)\PSI\PSIPLOT\POSTSCRP\WinEx\PSCRIPT.HLP
MS Windows 3.1 help, Tue Apr 17 13:11:49 2001, 26038 bytes
dropped
C:\Program Files (x86)\PSI\PSIPLOT\POSTSCRP\WinEx\PSCRIPT.NTF
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\POSTSCRP\WinEx\PSCRIPT5.DLL
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Program Files (x86)\PSI\PSIPLOT\POSTSCRP\WinEx\PSIPSCRP.PPD
PPD file, version "4.3"
dropped
C:\Program Files (x86)\PSI\PSIPLOT\PSIGRAPH.ICO
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\PSIPLOT.CHM
MS Windows HtmlHelp Data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\PSIPLOT.INI
Generic INItialization configuration [CreateColumn]
dropped
C:\Program Files (x86)\PSI\PSIPLOT\PSIProject.ico
MS Windows icon resource - 5 icons, 32x32, 8 bits/pixel, 48x48, 8 bits/pixel
dropped
C:\Program Files (x86)\PSI\PSIPLOT\PSIREPORT.ICO
MS Windows icon resource - 2 icons, 32x32, 48x48
dropped
C:\Program Files (x86)\PSI\PSIPLOT\PSISHEET.ICO
MS Windows icon resource - 1 icon, 32x32, 16 colors
dropped
C:\Program Files (x86)\PSI\PSIPLOT\README.TXT
Non-ISO extended-ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\README.rtf
Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
dropped
C:\Program Files (x86)\PSI\PSIPLOT\RED.CLR
Generic INItialization configuration [LINE_COLOR_RGB]
dropped
C:\Program Files (x86)\PSI\PSIPLOT\RED1.CLR
Generic INItialization configuration [LINE_COLOR_RGB]
dropped
C:\Program Files (x86)\PSI\PSIPLOT\RED2.CLR
Generic INItialization configuration [LINE_COLOR_RGB]
dropped
C:\Program Files (x86)\PSI\PSIPLOT\RED_INV.CLR
Generic INItialization configuration [LINE_COLOR_RGB]
dropped
C:\Program Files (x86)\PSI\PSIPLOT\RED_LITE.CLR
Generic INItialization configuration [LINE_COLOR_RGB]
dropped
C:\Program Files (x86)\PSI\PSIPLOT\ROSSLER.ODE
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SPECTRUM.CLR
Generic INItialization configuration [LINE_COLOR_RGB]
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SPEC_INV.CLR
Generic INItialization configuration [LINE_COLOR_RGB]
dropped
C:\Program Files (x86)\PSI\PSIPLOT\STIFF.ODE
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SampleData\GLMBinomial.pdw
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SampleData\GLMNormal.pdw
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SampleData\GMLPoisson.pdw
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SampleData\MLINEAR.PDW
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SampleData\cdlstick.PDW
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SampleData\comp2lns.PDW
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SampleData\ec50.PDW
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SampleData\floatcolumn.pdw
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SampleData\kaplan_meier.pdw
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SampleData\ld50.pdw
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SampleData\logistic.PDW
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SampleData\nichols.pdw
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SampleData\ssa.pdw
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SampleData\weibull.pdw
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SamplePlot\GrafPaper\ber.pgw
Composite Document File V2 Document, Cannot read section info
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SamplePlot\GrafPaper\decibel.pgw
Composite Document File V2 Document, Cannot read section info
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SamplePlot\GrafPaper\logit.pgw
Composite Document File V2 Document, Cannot read section info
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SamplePlot\GrafPaper\loglog.pgw
Composite Document File V2 Document, Cannot read section info
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SamplePlot\GrafPaper\probability.pgw
Composite Document File V2 Document, Cannot read section info
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SamplePlot\GrafPaper\reciprocal.pgw
Composite Document File V2 Document, Cannot read section info
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SamplePlot\GrafPaper\regular.pgw
Composite Document File V2 Document, Cannot read section info
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SamplePlot\GrafPaper\semilog.pgw
Composite Document File V2 Document, Cannot read section info
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SamplePlot\area.PGW
Composite Document File V2 Document, Cannot read section info
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SamplePlot\axis_sample.PGW
Composite Document File V2 Document, Cannot read section info
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SamplePlot\axisattr.PGW
Composite Document File V2 Document, Cannot read section info
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SamplePlot\axismode.PGW
Composite Document File V2 Document, Cannot read section info
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SamplePlot\boxplot.PGW
Composite Document File V2 Document, Cannot read section info
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SamplePlot\butterworth.PGW
Composite Document File V2 Document, Cannot read section info
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SamplePlot\cluster_area.PGW
Composite Document File V2 Document, Cannot read section info
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SamplePlot\cylindricsurface.PGW
Composite Document File V2 Document, Cannot read section info
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SamplePlot\errbar.PGW
Composite Document File V2 Document, Cannot read section info
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SamplePlot\maze.PGW
Composite Document File V2 Document, Cannot read section info
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SamplePlot\qcchart.PGW
Composite Document File V2 Document, Cannot read section info
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SamplePlot\reciprocal.pgw
Composite Document File V2 Document, Cannot read section info
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SamplePlot\stock.pgw
Composite Document File V2 Document, Cannot read section info
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SamplePlot\surface.PGW
Composite Document File V2 Document, Cannot read section info
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SamplePlot\symbolID.PGW
Composite Document File V2 Document, Cannot read section info
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SamplePlot\text.PGW
Composite Document File V2 Document, Cannot read section info
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SamplePlot\userdef.PGW
Composite Document File V2 Document, Cannot read section info
dropped
C:\Program Files (x86)\PSI\PSIPLOT\SamplePlot\vector.PGW
Composite Document File V2 Document, Cannot read section info
dropped
C:\Program Files (x86)\PSI\PSIPLOT\TEMPLET.ODE
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\TEMPLET.TSM
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\TUTORIAL.PDF
PDF document, version 1.1
dropped
C:\Program Files (x86)\PSI\PSIPLOT\control2.gif
GIF image data, version 89a, 760 x 560
dropped
C:\Program Files (x86)\PSI\PSIPLOT\lessn10c.PDW
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\lessn16a.pdw
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\lessn16b.pdw
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\lessn18.pdw
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\lessn18a.pdw
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\lesson16.pdw
data
dropped
C:\Program Files (x86)\PSI\PSIPLOT\lesson17.txt
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\readme.htm
HTML document, ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\templet.FPL
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\templet1.FPL
ASCII text, with CRLF line terminators
dropped
C:\Program Files (x86)\PSI\PSIPLOT\templet2.FPL
ASCII text, with CRLF line terminators
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PSI-Plot\Readme.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Has Working directory, Icon number=0, Archive, ctime=Thu May 3 18:20:52 2012, mtime=Thu Oct 10 17:18:30 2024, atime=Thu May 3 18:20:52 2012, length=3951, window=hide
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PSI-Plot\TUTORIAL.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Has Working directory, Icon number=0, Archive, ctime=Sun Apr 15 14:44:10 2012, mtime=Thu Oct 10 17:18:27 2024, atime=Sun Apr 15 14:44:10 2012, length=2103361, window=hide
dropped
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PSI-Plot\psiplot.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Has Working directory, Icon number=0, Archive, ctime=Thu May 3 17:52:22 2012, mtime=Thu Oct 10 17:18:27 2024, atime=Thu May 3 17:52:22 2012, length=9342976, window=hide
dropped
C:\Users\Public\Desktop\PSI-Plot Working Demo.lnk
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Icon number=0, Archive, ctime=Thu May 3 17:52:22 2012, mtime=Thu Oct 10 17:18:32 2024, atime=Thu May 3 17:52:22 2012, length=9342976, window=hide
dropped
C:\Users\user\AppData\Local\Temp\MSIA4B2.tmp
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\_is8C78\0x0409.ini
Generic INItialization configuration [Languages]
dropped
C:\Users\user\AppData\Local\Temp\_is8C78\PSI-Plot Ver 10.5 Working Demo.msi
Composite Document File V2 Document, Little Endian, Os: Windows, Version 5.1, MSI Installer, Last Saved By: InstallShield , Number of Characters: 0, Security: 1, Number of Words: 0, Title: Installation Database, Comments: Contact: Your local administrator, Keywords: Installer,MSI,Database, Subject: Welcome to PSI-Plot Version 10.5 Working Demo, Author: InstallShield Software Corporation, Number of Pages: 200, Name of Creating Application: InstallShield X - Express Edition 10.0, Last Saved Time/Date: Thu May 3 16:22:06 2012, Create Time/Date: Thu May 3 16:22:06 2012, Last Printed: Thu May 3 16:22:06 2012, Revision Number: {96644CA9-8EA3-446B-8568-6E1624759883}, Code page: 1252, Template: Intel;1033
dropped
C:\Users\user\AppData\Local\Temp\_is8C78\Setup.INI
Generic INItialization configuration [Startup]
dropped
C:\Users\user\AppData\Local\Temp\_is8C78\_ISMSIDEL.INI
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\~8C68.tmp
Generic INItialization configuration [Startup]
dropped
C:\Windows\Downloaded Installations\{96644CA9-8EA3-446B-8568-6E1624759883}\PSI-Plot Ver 10.5 Working Demo.msi
Composite Document File V2 Document, Little Endian, Os: Windows, Version 5.1, MSI Installer, Last Saved By: InstallShield , Number of Characters: 0, Security: 1, Number of Words: 0, Title: Installation Database, Comments: Contact: Your local administrator, Keywords: Installer,MSI,Database, Subject: Welcome to PSI-Plot Version 10.5 Working Demo, Author: InstallShield Software Corporation, Number of Pages: 200, Name of Creating Application: InstallShield X - Express Edition 10.0, Last Saved Time/Date: Thu May 3 16:22:06 2012, Create Time/Date: Thu May 3 16:22:06 2012, Last Printed: Thu May 3 16:22:06 2012, Revision Number: {96644CA9-8EA3-446B-8568-6E1624759883}, Code page: 1252, Template: Intel;1033
dropped
C:\Windows\Installer\5ee891.msi
Composite Document File V2 Document, Little Endian, Os: Windows, Version 5.1, MSI Installer, Last Saved By: InstallShield , Number of Characters: 0, Security: 1, Number of Words: 0, Title: Installation Database, Comments: Contact: Your local administrator, Keywords: Installer,MSI,Database, Subject: Welcome to PSI-Plot Version 10.5 Working Demo, Author: InstallShield Software Corporation, Number of Pages: 200, Name of Creating Application: InstallShield X - Express Edition 10.0, Last Saved Time/Date: Thu May 3 16:22:06 2012, Create Time/Date: Thu May 3 16:22:06 2012, Last Printed: Thu May 3 16:22:06 2012, Revision Number: {96644CA9-8EA3-446B-8568-6E1624759883}, Code page: 1252, Template: Intel;1033
dropped
C:\Windows\Installer\5ee893.msi
Composite Document File V2 Document, Little Endian, Os: Windows, Version 5.1, MSI Installer, Last Saved By: InstallShield , Number of Characters: 0, Security: 1, Number of Words: 0, Title: Installation Database, Comments: Contact: Your local administrator, Keywords: Installer,MSI,Database, Subject: Welcome to PSI-Plot Version 10.5 Working Demo, Author: InstallShield Software Corporation, Number of Pages: 200, Name of Creating Application: InstallShield X - Express Edition 10.0, Last Saved Time/Date: Thu May 3 16:22:06 2012, Create Time/Date: Thu May 3 16:22:06 2012, Last Printed: Thu May 3 16:22:06 2012, Revision Number: {96644CA9-8EA3-446B-8568-6E1624759883}, Code page: 1252, Template: Intel;1033
dropped
C:\Windows\Installer\MSIED35.tmp
data
dropped
C:\Windows\Installer\SourceHash{CF7D8275-38F3-42CF-AF3D-29B1BF918926}
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Installer\inprogressinstallinfo.ipi
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Installer\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}\ARPPRODUCTICON.exe
MS Windows icon resource - 5 icons, 32x32, 8 bits/pixel, 48x48, 8 bits/pixel
dropped
C:\Windows\Installer\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}\NewShortcut1_E57AF06D4375496697A2B3227B8F52A3.EXE
MS Windows icon resource - 5 icons, 32x32, 8 bits/pixel, 48x48, 8 bits/pixel
dropped
C:\Windows\Installer\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}\NewShortcut6_B94EC0BE542B4F308679E8D52BAD769F.exe
MS Windows icon resource - 5 icons, 32x32, 8 bits/pixel, 48x48, 8 bits/pixel
dropped
C:\Windows\Installer\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}\NewShortcut7_B94EC0BE542B4F308679E8D52BAD769F.PDF
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.log
Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
C:\Windows\PSIPLOT.INI
Generic INItialization configuration [CreateColumn]
dropped
C:\Windows\System32\spool\drivers\x64\3\PSIPSCRP.PPD
PPD file, version "4.3"
dropped
C:\Windows\System32\spool\drivers\x64\PS5UI.DLL
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Windows\System32\spool\drivers\x64\PSCRIPT.HLP
MS Windows 3.1 help, Tue Apr 17 13:11:49 2001, 26038 bytes
dropped
C:\Windows\System32\spool\drivers\x64\PSCRIPT.NTF
data
dropped
C:\Windows\System32\spool\drivers\x64\PSCRIPT5.DLL
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\Windows\System32\spool\drivers\x64\PSIPSCRP.PPD
PPD file, version "4.3"
dropped
C:\Windows\Temp\~DF236A664A65A73CE7.TMP
data
dropped
C:\Windows\Temp\~DF2475FED551644849.TMP
data
dropped
C:\Windows\Temp\~DF26CD9645139C62E1.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF2931FAC31C296BB1.TMP
data
dropped
C:\Windows\Temp\~DF2A6266BC8FED5E8A.TMP
data
dropped
C:\Windows\Temp\~DF2BB1FF67CCB2BA08.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF733BBCDF67162C3E.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DF8FDFF2A96AE69220.TMP
data
dropped
C:\Windows\Temp\~DFA870BB9D712FD90A.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\Windows\Temp\~DFBCCBE9E0F6F29FA5.TMP
data
dropped
C:\Windows\Temp\~DFC634E747B8F69118.TMP
data
dropped
C:\Windows\Temp\~DFCD410FC2588C4F64.TMP
Composite Document File V2 Document, Cannot read section info
dropped
C:\gdiplus.dll
PE32 executable (DLL) (console) Intel 80386, for MS Windows
dropped
There are 318 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
C:\Windows\System32\msiexec.exe
C:\Windows\system32\msiexec.exe /V
malicious
C:\Users\user\Desktop\plotdemo.exe
"C:\Users\user\Desktop\plotdemo.exe"
C:\Windows\SysWOW64\msiexec.exe
MSIEXEC.EXE /i "C:\Windows\Downloaded Installations\{96644CA9-8EA3-446B-8568-6E1624759883}\PSI-Plot Ver 10.5 Working Demo.msi" SETUPEXEDIR="C:\Users\user\Desktop"
C:\Windows\SysWOW64\msiexec.exe
C:\Windows\syswow64\MsiExec.exe -Embedding 8C8A1754951F47B4EB3715E07FE2E622 C
C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe
"C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe"

URLs

Name
IP
Malicious
http://www.ozemail.com.au/%7Egeoffk/pdfencrypt/
unknown
http://www.ghostscript.com/licensing/.
unknown
http://www.artifex.com/licensing/
unknown

Registry

Path
Value
Malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PSIGraph.PSIPlot.8
NULL
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PSIData\shell\open\command
NULL
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PSIData\shell\open
NULL
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PSIData\shell
NULL
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PSIGraph.PSIPlot.8\shell\open\command
NULL
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PSIReport\shell\open
NULL
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PSIReport\shell\open\command
NULL
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PSIProject\shell\open\command
NULL
malicious
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Owner
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
SessionHash
HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000
Sequence
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Config.Msi\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\5ee892.rbs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\5ee892.rbsLow
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\74F94B9BBF2724C40A9FE944297AF10E
5728D7FC3F83FC24FAD3921BFB199862
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8FB42BAB6F4D0304A931CD8983C3B652
5728D7FC3F83FC24FAD3921BFB199862
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7D55E54B964674A47BA400302A2516CE
5728D7FC3F83FC24FAD3921BFB199862
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\077DF42C38936C845BEEBA3075F7A53A
5728D7FC3F83FC24FAD3921BFB199862
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\378FC22BA8FF69C41BEF77567175CBC4
5728D7FC3F83FC24FAD3921BFB199862
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\96893B08A846510449B9BFAB4626D324
5728D7FC3F83FC24FAD3921BFB199862
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ECBF4C7116FD5A440A9EBF33D6629986
5728D7FC3F83FC24FAD3921BFB199862
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB5371275E6E4D947B053F285F8F8BDA
5728D7FC3F83FC24FAD3921BFB199862
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A6725C03AF8F73B4D93E547C95761A13
5728D7FC3F83FC24FAD3921BFB199862
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8B13DCA805BDAE94DB8E6E3CFE444F75
5728D7FC3F83FC24FAD3921BFB199862
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DC0511D57D8BE964AA86276A30170D04
5728D7FC3F83FC24FAD3921BFB199862
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2F91004E07F800748A1B2DD0E7B8EC97
5728D7FC3F83FC24FAD3921BFB199862
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB60EDC172A93DF4FA262C9CC66B2490
5728D7FC3F83FC24FAD3921BFB199862
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AD0FFFC51CBB16447954BA95BA19B646
5728D7FC3F83FC24FAD3921BFB199862
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E1F6A458650BC7240B7A1EEBFD987C20
5728D7FC3F83FC24FAD3921BFB199862
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\80D953125F417394497153206DC21CCD
5728D7FC3F83FC24FAD3921BFB199862
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4DFB83B361A9F9347908DAA8635E5A4A
5728D7FC3F83FC24FAD3921BFB199862
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6A239295CFF6A74498DD04825C07239A
5728D7FC3F83FC24FAD3921BFB199862
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\663DE59704428BD488D12DB5D1E04417
5728D7FC3F83FC24FAD3921BFB199862
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E33FF57CF3689434D9D0B30A0B8EA3FD
5728D7FC3F83FC24FAD3921BFB199862
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\96383FCFC45DDD245A1900897937EBCC
5728D7FC3F83FC24FAD3921BFB199862
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0B134852DDCB2FC4CBF35140D5D09B7A
5728D7FC3F83FC24FAD3921BFB199862
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\279D0FE3E6FDECB4DB2819FA4EB4E070
5728D7FC3F83FC24FAD3921BFB199862
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B067066D696813E4DA18C6082F332EDC
5728D7FC3F83FC24FAD3921BFB199862
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A52B9D54ED049654490CC5AE1D4202E2
5728D7FC3F83FC24FAD3921BFB199862
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\328C330E57469D84CBB82F45920D2EA6
5728D7FC3F83FC24FAD3921BFB199862
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3B89B3149BEE0164FAE43046CFC0B219
5728D7FC3F83FC24FAD3921BFB199862
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F1B496B301445D115AA4000972A8B18B
5728D7FC3F83FC24FAD3921BFB199862
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files (x86)\PSI\PSIPLOT\SamplePlot\GrafPaper\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files (x86)\PSI\PSIPLOT\SamplePlot\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files (x86)\PSI\PSIPLOT\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files (x86)\PSI\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files (x86)\PSI\PSIPLOT\POSTSCRP\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files (x86)\PSI\PSIPLOT\SampleData\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files (x86)\PSI\PSIPLOT\POSTSCRP\WinEx\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files (x86)\PSI\PSIPLOT\Macro\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Windows\Installer\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PSI-Plot\
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PSIData\defaulticon
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PSIGraph.PSIPlot.8\DefaultIcon
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.pgw
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.pdw
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.prw
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.ppw
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PSIReport\defaulticon
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PSIProject\defaulticon
NULL
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\PSI\GPL GhostScript
Location
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5728D7FC3F83FC24FAD3921BFB199862\InstallProperties
LocalPackage
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5728D7FC3F83FC24FAD3921BFB199862\InstallProperties
AuthorizedCDFPrefix
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5728D7FC3F83FC24FAD3921BFB199862\InstallProperties
Comments
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5728D7FC3F83FC24FAD3921BFB199862\InstallProperties
Contact
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5728D7FC3F83FC24FAD3921BFB199862\InstallProperties
DisplayVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5728D7FC3F83FC24FAD3921BFB199862\InstallProperties
HelpLink
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5728D7FC3F83FC24FAD3921BFB199862\InstallProperties
HelpTelephone
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5728D7FC3F83FC24FAD3921BFB199862\InstallProperties
InstallDate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5728D7FC3F83FC24FAD3921BFB199862\InstallProperties
InstallLocation
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5728D7FC3F83FC24FAD3921BFB199862\InstallProperties
InstallSource
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5728D7FC3F83FC24FAD3921BFB199862\InstallProperties
ModifyPath
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5728D7FC3F83FC24FAD3921BFB199862\InstallProperties
Publisher
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5728D7FC3F83FC24FAD3921BFB199862\InstallProperties
Readme
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5728D7FC3F83FC24FAD3921BFB199862\InstallProperties
Size
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5728D7FC3F83FC24FAD3921BFB199862\InstallProperties
EstimatedSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5728D7FC3F83FC24FAD3921BFB199862\InstallProperties
UninstallString
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5728D7FC3F83FC24FAD3921BFB199862\InstallProperties
URLInfoAbout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5728D7FC3F83FC24FAD3921BFB199862\InstallProperties
URLUpdateInfo
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5728D7FC3F83FC24FAD3921BFB199862\InstallProperties
VersionMajor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5728D7FC3F83FC24FAD3921BFB199862\InstallProperties
VersionMinor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5728D7FC3F83FC24FAD3921BFB199862\InstallProperties
WindowsInstaller
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5728D7FC3F83FC24FAD3921BFB199862\InstallProperties
Version
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5728D7FC3F83FC24FAD3921BFB199862\InstallProperties
Language
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}
AuthorizedCDFPrefix
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}
Comments
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}
Contact
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}
DisplayVersion
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}
HelpLink
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}
HelpTelephone
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}
InstallDate
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}
InstallLocation
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}
InstallSource
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}
ModifyPath
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}
Publisher
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}
Readme
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}
Size
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}
EstimatedSize
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}
UninstallString
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}
URLInfoAbout
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}
URLUpdateInfo
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}
VersionMajor
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}
VersionMinor
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}
WindowsInstaller
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}
Version
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}
Language
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\108DF7389DDCD101FA0EEF9E814B96C3
5728D7FC3F83FC24FAD3921BFB199862
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5728D7FC3F83FC24FAD3921BFB199862\InstallProperties
DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}
DisplayName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\5728D7FC3F83FC24FAD3921BFB199862
AlwaysInstall
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5728D7FC3F83FC24FAD3921BFB199862\Features
AlwaysInstall
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\5728D7FC3F83FC24FAD3921BFB199862
Application_Files
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5728D7FC3F83FC24FAD3921BFB199862\Features
Application_Files
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\5728D7FC3F83FC24FAD3921BFB199862\Patches
AllPatches
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\5728D7FC3F83FC24FAD3921BFB199862
ProductName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\5728D7FC3F83FC24FAD3921BFB199862
PackageCode
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\5728D7FC3F83FC24FAD3921BFB199862
Language
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\5728D7FC3F83FC24FAD3921BFB199862
Version
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\5728D7FC3F83FC24FAD3921BFB199862
Assignment
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\5728D7FC3F83FC24FAD3921BFB199862
AdvertiseFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\5728D7FC3F83FC24FAD3921BFB199862
ProductIcon
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\5728D7FC3F83FC24FAD3921BFB199862
InstanceType
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\5728D7FC3F83FC24FAD3921BFB199862
AuthorizedLUAApp
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\5728D7FC3F83FC24FAD3921BFB199862
DeploymentFlags
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\108DF7389DDCD101FA0EEF9E814B96C3
5728D7FC3F83FC24FAD3921BFB199862
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\5728D7FC3F83FC24FAD3921BFB199862\SourceList
PackageName
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\5728D7FC3F83FC24FAD3921BFB199862\SourceList\Net
1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\5728D7FC3F83FC24FAD3921BFB199862\SourceList\Media
DiskPrompt
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\5728D7FC3F83FC24FAD3921BFB199862\SourceList\Media
1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\5728D7FC3F83FC24FAD3921BFB199862
Clients
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\5728D7FC3F83FC24FAD3921BFB199862\SourceList
LastUsedSource
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings
StringCacheGeneration
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows x64\Drivers\Version-3\PSI PostScript
Attributes
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows x64\Drivers\Version-3\PSI PostScript
Configuration File
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows x64\Drivers\Version-3\PSI PostScript
Data File
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows x64\Drivers\Version-3\PSI PostScript
Datatype
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows x64\Drivers\Version-3\PSI PostScript
Dependent Files
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows x64\Drivers\Version-3\PSI PostScript
Driver
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows x64\Drivers\Version-3\PSI PostScript
DriverDate
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows x64\Drivers\Version-3\PSI PostScript
DriverVersion
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows x64\Drivers\Version-3\PSI PostScript
HardwareID
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows x64\Drivers\Version-3\PSI PostScript
Help File
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows x64\Drivers\Version-3\PSI PostScript
Manufacturer
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows x64\Drivers\Version-3\PSI PostScript
Monitor
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows x64\Drivers\Version-3\PSI PostScript
OEM URL
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows x64\Drivers\Version-3\PSI PostScript
Previous Names
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows x64\Drivers\Version-3\PSI PostScript
Provider
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows x64\Drivers\Version-3\PSI PostScript
TempDir
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Print\Environments\Windows x64\Drivers\Version-3\PSI PostScript
Version
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript
Action
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript
Attributes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript
ChangeID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript
Datatype
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript
Default DevMode
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript
Default Priority
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript
Description
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript
dnsTimeout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript
DsKeyUpdate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript
DsKeyUpdateForeground
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript
Location
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript
Name
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript
ObjectGUID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript
Parameters
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript
Port
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript
Print Processor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript
Printer Driver
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript
Priority
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript
Security
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript
Separator File
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript
Share Name
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript
SpoolDirectory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript
StartTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript
Status
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript
txTimeout
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript
UntilTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\DsDriver
driverVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\DsDriver
printBinNames
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\DsDriver
printCollate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\DsDriver
printColor
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\DsDriver
printDuplexSupported
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\DsDriver
printLanguage
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\DsDriver
printMaxResolutionSupported
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\DsDriver
printMaxXExtent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\DsDriver
printMaxYExtent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\DsDriver
printMediaReady
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\DsDriver
printMediaSupported
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\DsDriver
printMemory
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\DsDriver
printMinXExtent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\DsDriver
printMinYExtent
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\DsDriver
printNumberUp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\DsDriver
printOrientationsSupported
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\DsDriver
printPagesPerMinute
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\DsDriver
printRate
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\DsDriver
printRateUnit
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\DsDriver
printStaplingSupported
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\DsSpooler
description
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\DsSpooler
driverName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\DsSpooler
flags
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\DsSpooler
location
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\DsSpooler
portName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\DsSpooler
printEndTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\DsSpooler
printerName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\DsSpooler
printKeepPrintedJobs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\DsSpooler
printSeparatorFile
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\DsSpooler
printShareName
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\DsSpooler
printSpooling
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\DsSpooler
printStartTime
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\DsSpooler
priority
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\DsSpooler
versionNumber
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\PnPData
HardwareID
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\PnPData
Manufacturer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\PrinterDriverData
DependentFiles
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\PrinterDriverData
FeatureKeyword
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\PrinterDriverData
FeatureKeywordSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\PrinterDriverData
Forms?
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\PrinterDriverData
FreeMem
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\PrinterDriverData
InitDriverVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\PrinterDriverData
JobTimeOut
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\PrinterDriverData
PrinterData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\PrinterDriverData
PrinterDataSize
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\PSI PostScript\PrinterDriverData
Protocol
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Devices
PSI PostScript
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PrinterPorts
PSI PostScript
There are 215 hidden registries, click here to show them.

Memdumps

Base Address
Regiontype
Protect
Malicious
730000
heap
page read and write
438000
unkown
page readonly
727000
heap
page read and write
24C6000
heap
page read and write
559000
heap
page read and write
521000
heap
page read and write
743000
heap
page read and write
432000
unkown
page read and write
568000
heap
page read and write
24C8000
heap
page read and write
401000
unkown
page execute read
428000
unkown
page readonly
517000
heap
page read and write
99000
stack
page read and write
24B3000
heap
page read and write
438000
unkown
page readonly
22E0000
heap
page read and write
5AE000
stack
page read and write
2390000
heap
page read and write
588000
heap
page read and write
740000
heap
page read and write
55B000
heap
page read and write
400000
unkown
page readonly
3B3F000
stack
page read and write
6EE000
stack
page read and write
42E000
unkown
page write copy
24CA000
heap
page read and write
24C9000
heap
page read and write
521000
heap
page read and write
42F000
unkown
page read and write
700000
heap
page read and write
517000
heap
page read and write
750000
heap
page read and write
546000
heap
page read and write
8FF000
stack
page read and write
563000
heap
page read and write
535000
heap
page read and write
546000
heap
page read and write
9A000
stack
page read and write
480000
heap
page read and write
24B0000
heap
page read and write
4B0000
heap
page read and write
74C000
heap
page read and write
437000
unkown
page readonly
743000
heap
page read and write
770000
heap
page read and write
580000
heap
page read and write
2440000
heap
page read and write
216F000
stack
page read and write
428000
unkown
page readonly
24C7000
heap
page read and write
74C000
heap
page read and write
401000
unkown
page execute read
42E000
unkown
page write copy
54A000
heap
page read and write
3A4F000
heap
page read and write
52B000
heap
page read and write
437000
unkown
page readonly
400000
unkown
page readonly
790000
heap
page read and write
557000
heap
page read and write
401000
unkown
page execute read
431000
unkown
page write copy
74C000
heap
page read and write
560000
heap
page read and write
74C000
heap
page read and write
51D000
heap
page read and write
540000
heap
page read and write
750000
heap
page read and write
547000
heap
page read and write
431000
unkown
page read and write
56C000
heap
page read and write
2443000
heap
page read and write
72B000
heap
page read and write
6AE000
stack
page read and write
545000
heap
page read and write
275E000
stack
page read and write
429000
unkown
page readonly
232F000
stack
page read and write
2280000
heap
page read and write
93E000
stack
page read and write
72D000
heap
page read and write
4EB000
heap
page read and write
6EE000
stack
page read and write
317F000
stack
page read and write
429000
unkown
page readonly
70A000
heap
page read and write
4B5000
heap
page read and write
22E5000
heap
page read and write
560000
heap
page read and write
2060000
heap
page read and write
75E000
heap
page read and write
58A000
heap
page read and write
74C000
heap
page read and write
54B000
heap
page read and write
559000
heap
page read and write
541000
heap
page read and write
72B000
heap
page read and write
546000
heap
page read and write
573000
heap
page read and write
553000
heap
page read and write
440000
heap
page read and write
22DE000
stack
page read and write
432000
unkown
page write copy
550000
heap
page read and write
2064000
heap
page read and write
22E9000
heap
page read and write
727000
heap
page read and write
577000
heap
page read and write
54E000
heap
page read and write
203F000
stack
page read and write
566000
heap
page read and write
2880000
trusted library allocation
page read and write
72E000
stack
page read and write
450000
heap
page read and write
24C6000
heap
page read and write
565000
heap
page read and write
56E000
heap
page read and write
A3F000
stack
page read and write
460000
heap
page read and write
70D000
heap
page read and write
51B000
heap
page read and write
74C000
heap
page read and write
565000
heap
page read and write
400000
unkown
page readonly
4E0000
heap
page read and write
749000
heap
page read and write
74E000
heap
page read and write
434000
unkown
page read and write
279E000
stack
page read and write
4D0000
heap
page read and write
4FD000
heap
page read and write
544000
heap
page read and write
327F000
stack
page read and write
3C3F000
stack
page read and write
759000
heap
page read and write
197000
stack
page read and write
2290000
heap
page read and write
541000
heap
page read and write
19C000
stack
page read and write
754000
heap
page read and write
730000
heap
page read and write
75B000
heap
page read and write
2330000
heap
page read and write
520000
heap
page read and write
559000
heap
page read and write
401000
unkown
page execute read
74E000
heap
page read and write
51B000
heap
page read and write
57E000
heap
page read and write
795000
heap
page read and write
743000
heap
page read and write
24C7000
heap
page read and write
400000
unkown
page readonly
24B4000
heap
page read and write
566000
heap
page read and write
There are 146 hidden memdumps, click here to show them.