Utility Imposter Using AspNetCompiler-Like Techniques for Payload Delivery


Zero‑Dwell Threat Intelligence Report

A narrative, executive‑ready view into the malware’s behavior, exposure, and reliable defenses.
Generated: 2025-10-31 10:42:55 UTC

Executive Overview — What We’re Dealing With

This specimen has persisted long enough to matter. Human experts classified it as Malware, and the telemetry confirms a capable, evasive Trojan with real impact potential.

File
8gb85hj.exe
Type
PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
SHA‑1
54cafe56f03bd4ac319b7cf7bd241caf8421d587
MD5
5b191ac23d8e7292bcbf50556be1f741
First Seen
2025-09-14 19:10:55.066290
Last Analysis
2025-09-15 07:31:08.249634
Dwell Time
0 days, 7 hours, 33 minutes

Extended Dwell Time Impact

For 12+ hours, this malware remained undetected — a half-day window that permitted the adversary to complete initial execution, establish basic persistence, and perform initial system enumeration.

Comparative Context

Industry studies report a median dwell time closer to 21–24 days. This case represents rapid detection and containment within hours rather than days.

Timeline

Time (UTC) Event Elapsed
2022-08-05 22:12:42 UTC First VirusTotal submission
2025-09-19 07:16:45 UTC Latest analysis snapshot 1140 days, 9 hours, 4 minutes
2025-10-31 10:42:55 UTC Report generation time 1182 days, 12 hours, 30 minutes

Why It Matters

Every additional day of dwell time is not just an abstract number — it is attacker opportunity. Each day equates to more time for lateral movement, stealth persistence, and intelligence gathering.

Global Detection Posture — Who Caught It, Who Missed It

VirusTotal engines: 73. Detected as malicious: 9. Missed: 64. Coverage: 12.3%.

Detected Vendors

  • Xcitium
  • +8 additional vendors (names not provided)

List includes Xcitium plus an additional 8 vendors per the provided summary.

Missed Vendors

  • Acronis
  • AhnLab-V3
  • Alibaba
  • alibabacloud
  • ALYac
  • Antiy-AVL
  • Arcabit
  • Avast
  • AVG
  • Avira
  • Baidu
  • BitDefender
  • CAT-QuickHeal
  • ClamAV
  • CMC
  • CrowdStrike
  • CTX
  • Cylance
  • Cynet
  • DrWeb
  • Elastic
  • Emsisoft
  • ESET-NOD32
  • F-Secure
  • GData
  • Google
  • google_safebrowsing
  • Gridinsoft
  • huorong
  • Ikarus
  • Jiangmin
  • K7AntiVirus
  • K7GW
  • Kaspersky
  • Kingsoft
  • Lionic
  • McAfeeD
  • Microsoft
  • MicroWorld-eScan
  • NANO-Antivirus
  • Paloalto
  • Panda
  • Rising
  • Sangfor
  • SentinelOne
  • Skyhigh
  • Sophos
  • SUPERAntiSpyware
  • Symantec
  • TACHYON
  • tehtris
  • Tencent
  • Trapmine
  • TrendMicro
  • TrendMicro-HouseCall
  • Varist
  • VIPRE
  • VirIT
  • ViRobot
  • Webroot
  • Yandex
  • Zillya
  • ZoneAlarm
  • Zoner

Why it matters: if any endpoint relies solely on a missed engine, this malware can operate with zero alerts. Prevention‑first controls close that gap regardless of signature lag.

Behavioral Storyline — How the Malware Operates

This threat shows heavy registry manipulation (45.12% of total behavior), indicating persistent backdoor installation, configuration tampering, or system policy modification attempts. The malware likely establishes persistence mechanisms and modifies security settings to maintain long-term access.

Behavior Categories (weighted)

Weight values represent the frequency and intensity of malware interactions with specific system components. Higher weights indicate more aggressive targeting of that category. Each operation (registry access, file modification, network connection, etc.) contributes to the category’s total weight, providing a quantitative measure of the malware’s behavioral focus.

Category Weight Percentage
Registry 97 45.12%
System 76 35.35%
File System 14 6.51%
Process 11 5.12%
Misc 7 3.26%
Windows 6 2.79%
Synchronization 2 0.93%
Device 2 0.93%

MITRE ATT&CK Mapping

  • T1082 – Reads software policies

Following the Trail — Network & DNS Activity

Outbound activity leans on reputable infrastructure (e.g., CDNs, cloud endpoints) to blend in. TLS sessions and
HTTP calls show routine beaconing and IP‑lookup behavior that can masquerade as normal browsing.

Contacted Domains

Domain IP Country ASN/Org
www.aieov.com 76.223.54.146 United States Amazon.com, Inc.
www.msftncsi.com 23.200.3.20 United States Akamai Technologies, Inc.

Observed IPs

IP Country ASN/Org
224.0.0.252
239.255.255.250
8.8.4.4 United States Google LLC
8.8.8.8 United States Google LLC

DNS Queries

Request Type
5isohu.com A
www.msftncsi.com A
www.aieov.com A

Contacted IPs

IP Country ASN/Org
224.0.0.252
239.255.255.250
8.8.4.4 United States Google LLC
8.8.8.8 United States Google LLC

Port Distribution

Port Count Protocols
137 1 udp
5355 5 udp
53 86 udp
3702 1 udp

UDP Packets

Source IP Dest IP Sport Dport Time Proto
192.168.56.13 192.168.56.255 137 137 3.2445311546325684 udp
192.168.56.13 224.0.0.252 49311 5355 5.7291059494018555 udp
192.168.56.13 224.0.0.252 55150 5355 3.1734671592712402 udp
192.168.56.13 224.0.0.252 60010 5355 5.386029958724976 udp
192.168.56.13 224.0.0.252 62406 5355 3.178394079208374 udp
192.168.56.13 224.0.0.252 63527 5355 4.2483069896698 udp
192.168.56.13 239.255.255.250 52252 3702 3.181941032409668 udp
192.168.56.13 8.8.4.4 50554 53 71.77544403076172 udp
192.168.56.13 8.8.4.4 52284 53 274.0101411342621 udp
192.168.56.13 8.8.4.4 52955 53 328.99378299713135 udp
192.168.56.13 8.8.4.4 53518 53 118.74437117576599 udp
192.168.56.13 8.8.4.4 53616 53 300.38524103164673 udp
192.168.56.13 8.8.4.4 53825 53 239.0564501285553 udp
192.168.56.13 8.8.4.4 53985 53 180.0722119808197 udp
192.168.56.13 8.8.4.4 54879 53 7.9479660987854 udp
192.168.56.13 8.8.4.4 54881 53 6.825188159942627 udp
192.168.56.13 8.8.4.4 55460 53 357.71274995803833 udp
192.168.56.13 8.8.4.4 55551 53 86.13453412055969 udp
192.168.56.13 8.8.4.4 55743 53 173.83766412734985 udp
192.168.56.13 8.8.4.4 56086 53 159.4625849723816 udp
192.168.56.13 8.8.4.4 56197 53 79.86887717247009 udp
192.168.56.13 8.8.4.4 56202 53 220.8063600063324 udp
192.168.56.13 8.8.4.4 56770 53 259.65372610092163 udp
192.168.56.13 8.8.4.4 56908 53 192.08816695213318 udp
192.168.56.13 8.8.4.4 57065 53 126.83769202232361 udp
192.168.56.13 8.8.4.4 57310 53 36.54101800918579 udp
192.168.56.13 8.8.4.4 57415 53 39.16617298126221 udp
192.168.56.13 8.8.4.4 57885 53 343.35374999046326 udp
192.168.56.13 8.8.4.4 58070 53 198.33349895477295 udp
192.168.56.13 8.8.4.4 58554 53 314.74438214302063 udp
192.168.56.13 8.8.4.4 58697 53 9.462804079055786 udp
192.168.56.13 8.8.4.4 58920 53 51.119346141815186 udp
192.168.56.13 8.8.4.4 59610 53 145.08760499954224 udp
192.168.56.13 8.8.4.4 60389 53 253.41630005836487 udp
192.168.56.13 8.8.4.4 60543 53 112.47896313667297 udp
192.168.56.13 8.8.4.4 60780 53 151.3534300327301 udp
192.168.56.13 8.8.4.4 60910 53 57.415903091430664 udp
192.168.56.13 8.8.4.4 61004 53 98.11911702156067 udp
192.168.56.13 8.8.4.4 61800 53 165.71262097358704 udp
192.168.56.13 8.8.4.4 61897 53 212.6814751625061 udp
192.168.56.13 8.8.4.4 62422 53 206.44726705551147 udp
192.168.56.13 8.8.4.4 62491 53 267.77530217170715 udp
192.168.56.13 8.8.4.4 62493 53 24.80695605278015 udp
192.168.56.13 8.8.4.4 62849 53 22.181334018707275 udp
192.168.56.13 8.8.4.4 62980 53 227.04074716567993 udp
192.168.56.13 8.8.4.4 64533 53 104.3846549987793 udp
192.168.56.13 8.8.4.4 64642 53 286.0251340866089 udp
192.168.56.13 8.8.4.4 64700 53 245.29101300239563 udp
192.168.56.13 8.8.4.4 64801 53 65.47832894325256 udp
192.168.56.13 8.8.4.4 64886 53 133.10379695892334 udp
192.168.56.13 8.8.8.8 50554 53 70.775808095932 udp
192.168.56.13 8.8.8.8 52284 53 273.01012897491455 udp
192.168.56.13 8.8.8.8 52955 53 327.99500608444214 udp
192.168.56.13 8.8.8.8 53518 53 117.7451400756836 udp
192.168.56.13 8.8.8.8 53616 53 299.38490200042725 udp
192.168.56.13 8.8.8.8 53825 53 238.05683994293213 udp
192.168.56.13 8.8.8.8 53985 53 179.07310795783997 udp
192.168.56.13 8.8.8.8 54879 53 8.946897029876709 udp
192.168.56.13 8.8.8.8 54881 53 7.822333097457886 udp
192.168.56.13 8.8.8.8 55460 53 356.7135090827942 udp
192.168.56.13 8.8.8.8 55551 53 85.13568115234375 udp
192.168.56.13 8.8.8.8 55743 53 172.83940505981445 udp
192.168.56.13 8.8.8.8 56086 53 158.46328496932983 udp
192.168.56.13 8.8.8.8 56197 53 78.87778496742249 udp
192.168.56.13 8.8.8.8 56202 53 219.80712413787842 udp
192.168.56.13 8.8.8.8 56770 53 258.65059304237366 udp
192.168.56.13 8.8.8.8 56908 53 191.09863805770874 udp
192.168.56.13 8.8.8.8 57065 53 125.83832216262817 udp
192.168.56.13 8.8.8.8 57310 53 35.541861057281494 udp
192.168.56.13 8.8.8.8 57415 53 38.166316986083984 udp
192.168.56.13 8.8.8.8 57885 53 342.3543190956116 udp
192.168.56.13 8.8.8.8 58070 53 197.3232021331787 udp
192.168.56.13 8.8.8.8 58554 53 313.74425315856934 udp
192.168.56.13 8.8.8.8 58697 53 10.447307109832764 udp
192.168.56.13 8.8.8.8 58920 53 50.11965012550354 udp
192.168.56.13 8.8.8.8 59610 53 144.0885260105133 udp
192.168.56.13 8.8.8.8 60389 53 252.4179229736328 udp
192.168.56.13 8.8.8.8 60543 53 111.47924399375916 udp
192.168.56.13 8.8.8.8 60780 53 150.35475397109985 udp
192.168.56.13 8.8.8.8 60910 53 56.41656804084778 udp
192.168.56.13 8.8.8.8 61004 53 97.12000608444214 udp
192.168.56.13 8.8.8.8 61800 53 164.71379899978638 udp
192.168.56.13 8.8.8.8 61897 53 211.69062614440918 udp
192.168.56.13 8.8.8.8 62422 53 205.44758105278015 udp
192.168.56.13 8.8.8.8 62491 53 266.7760100364685 udp
192.168.56.13 8.8.8.8 62493 53 23.807615995407104 udp
192.168.56.13 8.8.8.8 62849 53 21.182533979415894 udp
192.168.56.13 8.8.8.8 62980 53 226.0419270992279 udp
192.168.56.13 8.8.8.8 64533 53 103.38518214225769 udp
192.168.56.13 8.8.8.8 64642 53 285.02582001686096 udp
192.168.56.13 8.8.8.8 64700 53 244.29142308235168 udp
192.168.56.13 8.8.8.8 64801 53 64.47953295707703 udp
192.168.56.13 8.8.8.8 64886 53 132.1054720878601 udp

Hunting tip: alert on unknown binaries initiating TLS to IP‑lookup services or unusual CDN endpoints — especially early in execution.

Persistence & Policy — Registry and Services

Registry and service telemetry points to policy awareness and environment reconnaissance rather than noisy persistence. Below is a compact view of the most relevant keys and handles; expand to see the full lists where available.

Registry Opened

505

Registry Set

1

Services Started

0

Services Opened

0

Registry Opened (Top 25)

Key
\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\996E.exe
\Registry\MACHINE\System\CurrentControlSet\Control\SafeBoot\Option
\Registry\Machine\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\Safer\CodeIdentifiers\TransparentEnabled
\REGISTRY\USER\S-1-5-21-1482476501-1645522239-1417001333-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
HKCR\Component Categories
HKCR\Component Categories\{00000003-0000-0000-C000-000000000046}
HKCR\Component Categories\{00021490-0000-0000-C000-000000000046}
HKCR\Component Categories\{00021492-0000-0000-C000-000000000046}
HKCR\Component Categories\{00021493-0000-0000-C000-000000000046}
HKCR\Component Categories\{0AEE2A92-BCBB-11D0-8C72-00C04FC2B085}
HKCR\Component Categories\{0DE86A50-2BAA-11CF-A229-00AA003D7352}
HKCR\Component Categories\{0DE86A51-2BAA-11CF-A229-00AA003D7352}
HKCR\Component Categories\{0DE86A52-2BAA-11CF-A229-00AA003D7352}
HKCR\Component Categories\{0DE86A53-2BAA-11CF-A229-00AA003D7352}
HKCR\Component Categories\{0DE86A54-2BAA-11CF-A229-00AA003D7352}
HKCR\Component Categories\{0DE86A55-2BAA-11CF-A229-00AA003D7352}
HKCR\Component Categories\{0DE86A56-2BAA-11CF-A229-00AA003D7352}
HKCR\Component Categories\{0DE86A57-2BAA-11CF-A229-00AA003D7352}
HKCR\Component Categories\{217d378c-f344-4f17-bf44-7c770d7dd73d}
HKCR\Component Categories\{40FC6ED3-2438-11CF-A3DB-080036F12502}
HKCR\Component Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}
HKCR\Component Categories\{40FC6ED5-2438-11CF-A3DB-080036F12502}
HKCR\Component Categories\{40FC6ED8-2438-11CF-A3DB-080036F12502}
HKCR\Component Categories\{40FC6ED9-2438-11CF-A3DB-080036F12502}
HKCR\Component Categories\{62C8FE65-4EBB-45e7-B440-6E39B2CDBF29}
HKCR\Component Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}
HKCR\Component Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}
HKCR\Component Categories\{ACAC94FC-E5CF-11D1-9066-00C04FD9189D}
HKCR\Component Categories\{C501EDBE-9E70-11D1-9053-00C04FD9189D}
HKCR\Component Categories\{C501EDBF-9E70-11D1-9053-00C04FD9189D}
HKCR\Component Categories\{F0B7A1A1-9847-11CF-8F20-00805F2CD064}
HKCR\Component Categories\{F0B7A1A2-9847-11CF-8F20-00805F2CD064}
HKCR\Component Categories\{F0B7A1A3-9847-11CF-8F20-00805F2CD064}
HKCR\Component Categories\{FCB0C2A3-9747-4c95-9d02-820AFEDEF13F}
HKCR\CLSID
HKCR\CLSID\CLSID
HKCR\CLSID\CLSID\InProcServer32
HKCR\CLSID\CLSID\Implemented Categories
HKCR\CLSID\{0000002F-0000-0000-C000-000000000046}
HKCR\CLSID\{0000002F-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{0000002F-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{00000100-0000-0010-8000-00AA006D2EA4}
HKCR\CLSID\{00000100-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKCR\CLSID\{00000100-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKCR\CLSID\{00000101-0000-0010-8000-00AA006D2EA4}
HKCR\CLSID\{00000101-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKCR\CLSID\{00000101-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKCR\CLSID\{00000103-0000-0010-8000-00AA006D2EA4}
HKCR\CLSID\{00000103-0000-0010-8000-00AA006D2EA4}\InProcServer32
Show all (505 total)
Key
HKCR\CLSID\{00000103-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKCR\CLSID\{00000104-0000-0010-8000-00AA006D2EA4}
HKCR\CLSID\{00000104-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKCR\CLSID\{00000104-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKCR\CLSID\{00000105-0000-0010-8000-00AA006D2EA4}
HKCR\CLSID\{00000105-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKCR\CLSID\{00000105-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKCR\CLSID\{00000106-0000-0010-8000-00AA006D2EA4}
HKCR\CLSID\{00000106-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKCR\CLSID\{00000106-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKCR\CLSID\{00000107-0000-0010-8000-00AA006D2EA4}
HKCR\CLSID\{00000107-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKCR\CLSID\{00000107-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKCR\CLSID\{00000108-0000-0010-8000-00AA006D2EA4}
HKCR\CLSID\{00000108-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKCR\CLSID\{00000108-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKCR\CLSID\{00000109-0000-0010-8000-00AA006D2EA4}
HKCR\CLSID\{00000109-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKCR\CLSID\{00000109-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKCR\CLSID\{00000300-0000-0000-C000-000000000046}
HKCR\CLSID\{00000300-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{00000300-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{00000301-A8F2-4877-BA0A-FD2B6645FB94}
HKCR\CLSID\{00000301-A8F2-4877-BA0A-FD2B6645FB94}\InProcServer32
HKCR\CLSID\{00000301-A8F2-4877-BA0A-FD2B6645FB94}\Implemented Categories
HKCR\CLSID\{00000303-0000-0000-C000-000000000046}
HKCR\CLSID\{00000303-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{00000303-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{00000304-0000-0000-C000-000000000046}
HKCR\CLSID\{00000304-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{00000304-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{00000305-0000-0000-C000-000000000046}
HKCR\CLSID\{00000305-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{00000305-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{00000306-0000-0000-C000-000000000046}
HKCR\CLSID\{00000306-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{00000306-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{00000308-0000-0000-C000-000000000046}
HKCR\CLSID\{00000308-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{00000308-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{00000309-0000-0000-C000-000000000046}
HKCR\CLSID\{00000309-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{00000309-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{0000030B-0000-0000-C000-000000000046}
HKCR\CLSID\{0000030B-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{0000030B-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{00000315-0000-0000-C000-000000000046}
HKCR\CLSID\{00000315-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{00000315-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{00000316-0000-0000-C000-000000000046}
HKCR\CLSID\{00000316-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{00000316-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{00000319-0000-0000-C000-000000000046}
HKCR\CLSID\{00000319-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{00000319-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{0000031A-0000-0000-C000-000000000046}
HKCR\CLSID\{0000031A-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{0000031A-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{0000031D-0000-0000-C000-000000000046}
HKCR\CLSID\{0000031D-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{0000031D-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{00000320-0000-0000-C000-000000000046}
HKCR\CLSID\{00000320-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{00000320-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{00000327-0000-0000-C000-000000000046}
HKCR\CLSID\{00000327-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{00000327-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{0000032E-0000-0000-C000-000000000046}
HKCR\CLSID\{0000032E-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{0000032E-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{00000507-0000-0010-8000-00AA006D2EA4}
HKCR\CLSID\{00000507-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKCR\CLSID\{00000507-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKCR\CLSID\{0000050B-0000-0010-8000-00AA006D2EA4}
HKCR\CLSID\{0000050B-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKCR\CLSID\{0000050B-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKCR\CLSID\{00000514-0000-0010-8000-00AA006D2EA4}
HKCR\CLSID\{00000514-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKCR\CLSID\{00000514-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKCR\CLSID\{0000051A-0000-0010-8000-00AA006D2EA4}
HKCR\CLSID\{0000051A-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKCR\CLSID\{0000051A-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKCR\CLSID\{00000535-0000-0010-8000-00AA006D2EA4}
HKCR\CLSID\{00000535-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKCR\CLSID\{00000535-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKCR\CLSID\{00000541-0000-0010-8000-00AA006D2EA4}
HKCR\CLSID\{00000541-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKCR\CLSID\{00000541-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKCR\CLSID\{00000542-0000-0010-8000-00AA006D2EA4}
HKCR\CLSID\{00000542-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKCR\CLSID\{00000542-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKCR\CLSID\{00000560-0000-0010-8000-00AA006D2EA4}
HKCR\CLSID\{00000560-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKCR\CLSID\{00000560-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKCR\CLSID\{00000566-0000-0010-8000-00AA006D2EA4}
HKCR\CLSID\{00000566-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKCR\CLSID\{00000566-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKCR\CLSID\{00000602-0000-0010-8000-00AA006D2EA4}
HKCR\CLSID\{00000602-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKCR\CLSID\{00000602-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKCR\CLSID\{00000609-0000-0010-8000-00AA006D2EA4}
HKCR\CLSID\{00000609-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKCR\CLSID\{00000609-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKCR\CLSID\{00000615-0000-0010-8000-00AA006D2EA4}
HKCR\CLSID\{00000615-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKCR\CLSID\{00000615-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKCR\CLSID\{00000618-0000-0010-8000-00AA006D2EA4}
HKCR\CLSID\{00000618-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKCR\CLSID\{00000618-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKCR\CLSID\{0000061B-0000-0010-8000-00AA006D2EA4}
HKCR\CLSID\{0000061B-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKCR\CLSID\{0000061B-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKCR\CLSID\{0000061E-0000-0010-8000-00AA006D2EA4}
HKCR\CLSID\{0000061E-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKCR\CLSID\{0000061E-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKCR\CLSID\{00000621-0000-0010-8000-00AA006D2EA4}
HKCR\CLSID\{00000621-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKCR\CLSID\{00000621-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKCR\CLSID\{00020000-0000-0000-C000-000000000046}
HKCR\CLSID\{00020000-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{00020000-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{00020001-0000-0000-C000-000000000046}
HKCR\CLSID\{00020001-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{00020001-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{00020003-0000-0000-C000-000000000046}
HKCR\CLSID\{00020003-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{00020003-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{0002000D-0000-0000-C000-000000000046}
HKCR\CLSID\{0002000D-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{0002000D-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{0002000F-0000-0000-C000-000000000046}
HKCR\CLSID\{0002000F-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{0002000F-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{00020420-0000-0000-C000-000000000046}
HKCR\CLSID\{00020420-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{00020420-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{00020421-0000-0000-C000-000000000046}
HKCR\CLSID\{00020421-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{00020421-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{00020422-0000-0000-C000-000000000046}
HKCR\CLSID\{00020422-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{00020422-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{00020423-0000-0000-C000-000000000046}
HKCR\CLSID\{00020423-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{00020423-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{00020424-0000-0000-C000-000000000046}
HKCR\CLSID\{00020424-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{00020424-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{00020425-0000-0000-C000-000000000046}
HKCR\CLSID\{00020425-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{00020425-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{00020810-0000-0000-C000-000000000046}
HKCR\CLSID\{00020810-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{00020810-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{00020811-0000-0000-C000-000000000046}
HKCR\CLSID\{00020811-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{00020811-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{00020820-0000-0000-C000-000000000046}
HKCR\CLSID\{00020820-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{00020820-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{00020821-0000-0000-C000-000000000046}
HKCR\CLSID\{00020821-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{00020821-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{00020900-0000-0000-C000-000000000046}
HKCR\CLSID\{00020900-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{00020900-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{00020906-0000-0000-C000-000000000046}
HKCR\CLSID\{00020906-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{00020906-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{00020C01-0000-0000-C000-000000000046}
HKCR\CLSID\{00020C01-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{00020C01-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{00020D75-0000-0000-C000-000000000046}
HKCR\CLSID\{00020D75-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{00020D75-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{00021400-0000-0000-C000-000000000046}
HKCR\CLSID\{00021400-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{00021400-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{00021401-0000-0000-C000-000000000046}
HKCR\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{00021401-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{00022601-0000-0000-C000-000000000046}
HKCR\CLSID\{00022601-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{00022601-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{00022602-0000-0000-C000-000000000046}
HKCR\CLSID\{00022602-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{00022602-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{00022603-0000-0000-C000-000000000046}
HKCR\CLSID\{00022603-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{00022603-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{0002DF01-0000-0000-C000-000000000046}
HKCR\CLSID\{0002DF01-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{0002DF01-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{0002E005-0000-0000-C000-000000000046}
HKCR\CLSID\{0002E005-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{0002E005-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{0002E006-0000-0000-C000-000000000046}
HKCR\CLSID\{0002E006-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{0002E006-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{0003000A-0000-0000-C000-000000000046}
HKCR\CLSID\{0003000A-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{0003000A-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{0003000C-0000-0000-C000-000000000046}
HKCR\CLSID\{0003000C-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{0003000C-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{0003000D-0000-0000-C000-000000000046}
HKCR\CLSID\{0003000D-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{0003000D-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{0003000E-0000-0000-C000-000000000046}
HKCR\CLSID\{0003000E-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{0003000E-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{000C101C-0000-0000-C000-000000000046}
HKCR\CLSID\{000C101C-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{000C101C-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{000C101D-0000-0000-C000-000000000046}
HKCR\CLSID\{000C101D-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{000C101D-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{000C103E-0000-0000-C000-000000000046}
HKCR\CLSID\{000C103E-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{000C103E-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{000C1090-0000-0000-C000-000000000046}
HKCR\CLSID\{000C1090-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{000C1090-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{000C1094-0000-0000-C000-000000000046}
HKCR\CLSID\{000C1094-0000-0000-C000-000000000046}\InProcServer32
HKCR\CLSID\{000C1094-0000-0000-C000-000000000046}\Implemented Categories
HKCR\CLSID\{0010668C-0801-4DA6-A4A4-826522B6D28F}
HKCR\CLSID\{0010668C-0801-4DA6-A4A4-826522B6D28F}\InProcServer32
HKCR\CLSID\{0010668C-0801-4DA6-A4A4-826522B6D28F}\Implemented Categories
HKCR\CLSID\{00108226-EE41-44A2-9E9C-4BE4D5B1D2CD}
HKCR\CLSID\{00108226-EE41-44A2-9E9C-4BE4D5B1D2CD}\InProcServer32
HKCR\CLSID\{00108226-EE41-44A2-9E9C-4BE4D5B1D2CD}\Implemented Categories
HKCR\CLSID\{0010890e-8789-413c-adbc-48f5b511b3af}
HKCR\CLSID\{0010890e-8789-413c-adbc-48f5b511b3af}\InProcServer32
HKCR\CLSID\{0010890e-8789-413c-adbc-48f5b511b3af}\Implemented Categories
HKCR\CLSID\{00393519-3A67-4507-A2B8-85146167ACA7}
HKCR\CLSID\{00393519-3A67-4507-A2B8-85146167ACA7}\InProcServer32
HKCR\CLSID\{00393519-3A67-4507-A2B8-85146167ACA7}\Implemented Categories
HKCR\CLSID\{003e0278-eca8-4bb8-a256-3689ca1c2600}
HKCR\CLSID\{003e0278-eca8-4bb8-a256-3689ca1c2600}\InProcServer32
HKCR\CLSID\{003e0278-eca8-4bb8-a256-3689ca1c2600}\Implemented Categories
HKCR\CLSID\{00597829-82CE-44d4-8B0B-40BE695973B5}
HKCR\CLSID\{00597829-82CE-44d4-8B0B-40BE695973B5}\InProcServer32
HKCR\CLSID\{00597829-82CE-44d4-8B0B-40BE695973B5}\Implemented Categories
HKCR\CLSID\{006E61DF-1A43-4F2C-B26F-780BAEA3A92D}
HKCR\CLSID\{006E61DF-1A43-4F2C-B26F-780BAEA3A92D}\InProcServer32
HKCR\CLSID\{006E61DF-1A43-4F2C-B26F-780BAEA3A92D}\Implemented Categories
HKCR\CLSID\{0086c339-9c0e-4c09-9a2f-ff3d19a44a18}
HKCR\CLSID\{0086c339-9c0e-4c09-9a2f-ff3d19a44a18}\InProcServer32
HKCR\CLSID\{0086c339-9c0e-4c09-9a2f-ff3d19a44a18}\Implemented Categories
HKCR\CLSID\{0095b496-f121-4256-96a0-09179828cc16}
HKCR\CLSID\{0095b496-f121-4256-96a0-09179828cc16}\InProcServer32
HKCR\CLSID\{0095b496-f121-4256-96a0-09179828cc16}\Implemented Categories
HKCR\CLSID\{009f3b45-8a6b-4360-b997-b2a009a16402}
HKCR\CLSID\{009f3b45-8a6b-4360-b997-b2a009a16402}\InProcServer32
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
HKEY_CURRENT_USER_Classes
HKEY_CURRENT_USER_Classes\Component Categories
HKEY_CURRENT_USER_Classes\Component Categories\
HKEY_CURRENT_USER_Classes\Component Categories\{00000003-0000-0000-C000-000000000046}
HKEY_CURRENT_USER_Classes\Component Categories\{00021490-0000-0000-C000-000000000046}
HKEY_CURRENT_USER_Classes\Component Categories\{00021492-0000-0000-C000-000000000046}
HKEY_CURRENT_USER_Classes\Component Categories\{00021493-0000-0000-C000-000000000046}
HKEY_CURRENT_USER_Classes\Component Categories\{0AEE2A92-BCBB-11D0-8C72-00C04FC2B085}
HKEY_CURRENT_USER_Classes\Component Categories\{0DE86A50-2BAA-11CF-A229-00AA003D7352}
HKEY_CURRENT_USER_Classes\Component Categories\{0DE86A51-2BAA-11CF-A229-00AA003D7352}
HKEY_CURRENT_USER_Classes\Component Categories\{0DE86A52-2BAA-11CF-A229-00AA003D7352}
HKEY_CURRENT_USER_Classes\Component Categories\{0DE86A53-2BAA-11CF-A229-00AA003D7352}
HKEY_CURRENT_USER_Classes\Component Categories\{0DE86A54-2BAA-11CF-A229-00AA003D7352}
HKEY_CURRENT_USER_Classes\Component Categories\{0DE86A55-2BAA-11CF-A229-00AA003D7352}
HKEY_CURRENT_USER_Classes\Component Categories\{0DE86A56-2BAA-11CF-A229-00AA003D7352}
HKEY_CURRENT_USER_Classes\Component Categories\{0DE86A57-2BAA-11CF-A229-00AA003D7352}
HKEY_CURRENT_USER_Classes\Component Categories\{1119D272-091F-49E9-ADF4-16891AD0A2DF}
HKEY_CURRENT_USER_Classes\Component Categories\{40FC6ED3-2438-11CF-A3DB-080036F12502}
HKEY_CURRENT_USER_Classes\Component Categories\{40FC6ED4-2438-11CF-A3DB-080036F12502}
HKEY_CURRENT_USER_Classes\Component Categories\{40FC6ED5-2438-11CF-A3DB-080036F12502}
HKEY_CURRENT_USER_Classes\Component Categories\{40FC6ED8-2438-11CF-A3DB-080036F12502}
HKEY_CURRENT_USER_Classes\Component Categories\{40FC6ED9-2438-11CF-A3DB-080036F12502}
HKEY_CURRENT_USER_Classes\Component Categories\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}
HKEY_CURRENT_USER_Classes\Component Categories\{62C8FE65-4EBB-45E7-B440-6E39B2CDBF29}
HKEY_CURRENT_USER_Classes\Component Categories\{7374B140-977C-11CF-9FA9-00AA006C42C4}
HKEY_CURRENT_USER_Classes\Component Categories\{7374B142-977C-11CF-9FA9-00AA006C42C4}
HKEY_CURRENT_USER_Classes\Component Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}
HKEY_CURRENT_USER_Classes\Component Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}
HKEY_CURRENT_USER_Classes\Component Categories\{ACAC94FC-E5CF-11D1-9066-00C04FD9189D}
HKEY_CURRENT_USER_Classes\Component Categories\{C501EDBE-9E70-11D1-9053-00C04FD9189D}
HKEY_CURRENT_USER_Classes\Component Categories\{C501EDBF-9E70-11D1-9053-00C04FD9189D}
HKEY_CURRENT_USER_Classes\Component Categories\{F0B7A1A1-9847-11CF-8F20-00805F2CD064}
HKEY_CURRENT_USER_Classes\Component Categories\{F0B7A1A2-9847-11CF-8F20-00805F2CD064}
HKEY_CURRENT_USER_Classes\Component Categories\{F0B7A1A3-9847-11CF-8F20-00805F2CD064}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\CLSID
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\CLSID\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\CLSID\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0000002F-0000-0000-C000-000000000046}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0000002F-0000-0000-C000-000000000046}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0000002F-0000-0000-C000-000000000046}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0000002F-0000-0000-C000-000000000046}\InprocServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000100-0000-0010-8000-00AA006D2EA4}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000100-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000100-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000100-0000-0010-8000-00AA006D2EA4}\InprocServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000101-0000-0010-8000-00AA006D2EA4}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000101-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000101-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000101-0000-0010-8000-00AA006D2EA4}\InprocServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000103-0000-0010-8000-00AA006D2EA4}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000103-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000103-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000103-0000-0010-8000-00AA006D2EA4}\InprocServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000104-0000-0010-8000-00AA006D2EA4}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000104-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000104-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000104-0000-0010-8000-00AA006D2EA4}\InprocServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000105-0000-0010-8000-00AA006D2EA4}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000105-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000105-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000105-0000-0010-8000-00AA006D2EA4}\InprocServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000106-0000-0010-8000-00AA006D2EA4}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000106-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000106-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000106-0000-0010-8000-00AA006D2EA4}\InprocServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000107-0000-0010-8000-00AA006D2EA4}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000107-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000107-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000107-0000-0010-8000-00AA006D2EA4}\InprocServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000108-0000-0010-8000-00AA006D2EA4}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000108-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000108-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000108-0000-0010-8000-00AA006D2EA4}\InprocServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000109-0000-0010-8000-00AA006D2EA4}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000109-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000109-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000109-0000-0010-8000-00AA006D2EA4}\InprocServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000300-0000-0000-C000-000000000046}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000300-0000-0000-C000-000000000046}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000300-0000-0000-C000-000000000046}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000300-0000-0000-C000-000000000046}\InprocServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000301-A8F2-4877-BA0A-FD2B6645FB94}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000301-A8F2-4877-BA0A-FD2B6645FB94}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000301-A8F2-4877-BA0A-FD2B6645FB94}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000303-0000-0000-C000-000000000046}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000303-0000-0000-C000-000000000046}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000303-0000-0000-C000-000000000046}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000303-0000-0000-C000-000000000046}\InprocServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000304-0000-0000-C000-000000000046}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000304-0000-0000-C000-000000000046}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000304-0000-0000-C000-000000000046}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000304-0000-0000-C000-000000000046}\InprocServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000305-0000-0000-C000-000000000046}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000305-0000-0000-C000-000000000046}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000305-0000-0000-C000-000000000046}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000305-0000-0000-C000-000000000046}\InprocServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000306-0000-0000-C000-000000000046}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000306-0000-0000-C000-000000000046}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000306-0000-0000-C000-000000000046}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000306-0000-0000-C000-000000000046}\InprocServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000308-0000-0000-C000-000000000046}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000308-0000-0000-C000-000000000046}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000308-0000-0000-C000-000000000046}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000308-0000-0000-C000-000000000046}\InprocServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000309-0000-0000-C000-000000000046}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000309-0000-0000-C000-000000000046}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000309-0000-0000-C000-000000000046}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000309-0000-0000-C000-000000000046}\InprocServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0000030B-0000-0000-C000-000000000046}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0000030B-0000-0000-C000-000000000046}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0000030B-0000-0000-C000-000000000046}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0000030B-0000-0000-C000-000000000046}\InprocServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000315-0000-0000-C000-000000000046}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000315-0000-0000-C000-000000000046}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000315-0000-0000-C000-000000000046}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000315-0000-0000-C000-000000000046}\InprocServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000316-0000-0000-C000-000000000046}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000316-0000-0000-C000-000000000046}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000316-0000-0000-C000-000000000046}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000316-0000-0000-C000-000000000046}\InprocServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000319-0000-0000-C000-000000000046}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000319-0000-0000-C000-000000000046}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000319-0000-0000-C000-000000000046}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000319-0000-0000-C000-000000000046}\InprocServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0000031A-0000-0000-C000-000000000046}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0000031A-0000-0000-C000-000000000046}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0000031A-0000-0000-C000-000000000046}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0000031A-0000-0000-C000-000000000046}\InprocServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0000031D-0000-0000-C000-000000000046}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0000031D-0000-0000-C000-000000000046}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0000031D-0000-0000-C000-000000000046}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000320-0000-0000-C000-000000000046}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000320-0000-0000-C000-000000000046}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000320-0000-0000-C000-000000000046}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000320-0000-0000-C000-000000000046}\InprocServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000327-0000-0000-C000-000000000046}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000327-0000-0000-C000-000000000046}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000327-0000-0000-C000-000000000046}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000327-0000-0000-C000-000000000046}\InprocServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0000032E-0000-0000-C000-000000000046}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0000032E-0000-0000-C000-000000000046}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0000032E-0000-0000-C000-000000000046}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0000032E-0000-0000-C000-000000000046}\InprocServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000355-0000-0000-C000-000000000046}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000355-0000-0000-C000-000000000046}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000355-0000-0000-C000-000000000046}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000507-0000-0010-8000-00AA006D2EA4}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000507-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000507-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000507-0000-0010-8000-00AA006D2EA4}\InprocServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0000050B-0000-0010-8000-00AA006D2EA4}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0000050B-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0000050B-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0000050B-0000-0010-8000-00AA006D2EA4}\InprocServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000514-0000-0010-8000-00AA006D2EA4}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000514-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000514-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000514-0000-0010-8000-00AA006D2EA4}\InprocServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0000051A-0000-0010-8000-00AA006D2EA4}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0000051A-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{0000051A-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000535-0000-0010-8000-00AA006D2EA4}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000535-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000535-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000535-0000-0010-8000-00AA006D2EA4}\InprocServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000541-0000-0010-8000-00AA006D2EA4}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000541-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000541-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000541-0000-0010-8000-00AA006D2EA4}\InprocServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000542-0000-0010-8000-00AA006D2EA4}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000542-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000542-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000542-0000-0010-8000-00AA006D2EA4}\InprocServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000560-0000-0010-8000-00AA006D2EA4}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000560-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000560-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000560-0000-0010-8000-00AA006D2EA4}\InprocServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000566-0000-0010-8000-00AA006D2EA4}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000566-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000566-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000566-0000-0010-8000-00AA006D2EA4}\InprocServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000602-0000-0010-8000-00AA006D2EA4}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000602-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000602-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000602-0000-0010-8000-00AA006D2EA4}\InprocServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000609-0000-0010-8000-00AA006D2EA4}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000609-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000609-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000609-0000-0010-8000-00AA006D2EA4}\InprocServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000615-0000-0010-8000-00AA006D2EA4}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000615-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000615-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000615-0000-0010-8000-00AA006D2EA4}\InprocServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000618-0000-0010-8000-00AA006D2EA4}
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000618-0000-0010-8000-00AA006D2EA4}\Implemented Categories
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000618-0000-0010-8000-00AA006D2EA4}\InProcServer32
HKEY_CURRENT_USER_Classes\WOW6432Node\CLSID\{00000618-0000-0010-8000-00AA006D2EA4}\InprocServer32

Registry Set (Top 25)

Key Value
HKLM\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Servers\D8B548F0-E306-4B2B-BD82-25DAC3208786\FriendlyName AZURE-PC: azure:

Services Started (Top 15)

Services Opened (Top 15)

What To Do Now — Practical Defense Playbook

  • Contain unknowns: block first‑run binaries by default — signatures catch up, containment works now.
  • EDR controls: alert on keyboard hooks, screen capture APIs, VM/sandbox checks, and command‑shell launches.
  • Registry watch: flag queries/sets under policy paths (e.g., …\FipsAlgorithmPolicy\*).
  • Network rules: inspect outbound TLS to IP‑lookup services and unexpected CDN endpoints.
  • Hunt broadly: sweep endpoints for the indicators above and quarantine positives immediately.

Dwell time equals attacker opportunity. Reducing execution privileges and egress shrinks that window even when vendors disagree.

Scroll to Top