Technical Information
- %TEMP%\7ZipSfx.000\ShockwavePlayer.msi
- <SYSTEM32>\Macromed\Shockwave 10\Xtras\INetURL.x32
- <SYSTEM32>\Macromed\Shockwave 10\Xtras\MacroMix.x32
- <SYSTEM32>\Macromed\Shockwave 10\Xtras\Mix Services.x32
- <SYSTEM32>\Macromed\Shockwave 10\Xtras\MPEG 3 Import Export.x32
- <SYSTEM32>\Macromed\Shockwave 10\Xtras\Multiusr.x32
- <SYSTEM32>\Macromed\Shockwave 10\Xtras\Netfile.x32
- <SYSTEM32>\Macromed\Shockwave 10\Xtras\PNG Import Export.x32
- <SYSTEM32>\Macromed\Shockwave 10\Xtras\Speech.x32
- <SYSTEM32>\Macromed\Shockwave 10\Xtras\QT6Asset.x32
- <SYSTEM32>\Macromed\Shockwave 10\Xtras\RealMedia Asset.x32
- <SYSTEM32>\Macromed\Shockwave 10\Xtras\Shockwave 3d Asset.x32
- <SYSTEM32>\Macromed\Shockwave 10\Xtras\Shockwave Updater.x32
- <SYSTEM32>\Macromed\Shockwave 10\Xtras\Sound Control.x32
- <SYSTEM32>\Macromed\Shockwave 10\Xtras\Sound Import Export.x32
- <SYSTEM32>\Macromed\Shockwave 10\Xtras\Havok.x32
- <SYSTEM32>\Macromed\Shockwave 10\Xtras\Netlingo.x32
- <SYSTEM32>\Macromed\Shockwave 10\Xtras\Font Xtra.x32
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\XMLParser.x32
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\Swastrm.x32
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\Targa Import Export.x32
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\Text Asset.x32
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\TextXtra.x32
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\Tiff Import Export.x32
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\Windows Media Asset.x32
- <SYSTEM32>\Macromed\Shockwave 10\shockwave_Projector_Loader.dcr
- <SYSTEM32>\Macromed\Shockwave 10\Xtras\Flash Asset.x32
- <SYSTEM32>\Macromed\Shockwave 10\SwLogo.bmp
- <SYSTEM32>\Macromed\Shockwave 10\Xtras\Animated GIF Asset.x32
- <SYSTEM32>\Macromed\Shockwave 10\Xtras\CBrowser.x32
- <SYSTEM32>\Macromed\Shockwave 10\Xtras\Cursor Asset.x32
- <SYSTEM32>\Macromed\Shockwave 10\Xtras\DirectSound.x32
- <SYSTEM32>\Macromed\Shockwave 10\Xtras\DVD Asset.x32
- <SYSTEM32>\Macromed\Shockwave 10\Xtras\Font Asset.x32
- <SYSTEM32>\Macromed\Shockwave 10\Xtras\Sun AU Import Export.x32
- <SYSTEM32>\Macromed\Shockwave 10\Xtras\SWA Import Export.x32
- <SYSTEM32>\Macromed\Shockwave 10\Xtras\Swadcmpr.x32
- <SYSTEM32>\Adobe\Shockwave 12\SwHelper_1232202.exe
- <SYSTEM32>\Adobe\Shockwave 12\SwInit.exe
- <SYSTEM32>\Macromed\Shockwave 10\SwInit.exe
- <SYSTEM32>\Adobe\Shockwave 12\SwMenu.dll
- <SYSTEM32>\Macromed\Shockwave 10\SwMenuX.dll
- <SYSTEM32>\Adobe\Director\SWDNLD.exe
- <SYSTEM32>\Adobe\Director\SwDir.dll
- <SYSTEM32>\Macromed\Shockwave 10\SwOnce.dll
- <SYSTEM32>\Adobe\Shockwave 12\iml32.dll
- <SYSTEM32>\Macromed\Shockwave 10\iml32X.dll
- <SYSTEM32>\Adobe\Director\np32dsw.dll
- %WINDIR%\Installer\MSI15.tmp
- %WINDIR%\Installer\23591.msi
- <SYSTEM32>\Adobe\Shockwave 12\dirapi.dll
- <SYSTEM32>\Macromed\Shockwave 10\dirapiX.dll
- <SYSTEM32>\Macromed\Shockwave 10\Proj.dll
- <SYSTEM32>\Adobe\Shockwave 12\Proj.dll
- <SYSTEM32>\Macromed\Shockwave 10\PluginPing.dll
- <SYSTEM32>\Macromed\Shockwave 10\Xtras\Targa Import Export.x32
- <SYSTEM32>\Macromed\Shockwave 10\Xtras\Text Asset.x32
- <SYSTEM32>\Macromed\Shockwave 10\Xtras\TextXtra.x32
- <SYSTEM32>\Macromed\Shockwave 10\Xtras\Tiff Import Export.x32
- <SYSTEM32>\Macromed\Shockwave 10\Xtras\Windows Media Asset.x32
- <SYSTEM32>\Macromed\Shockwave 10\Xtras\XMLParser.x32
- <SYSTEM32>\Macromed\Shockwave 10\Xtras\Swastrm.x32
- <SYSTEM32>\Adobe\Shockwave 12\Control.dll
- <SYSTEM32>\Adobe\Shockwave 12\DynaPlayer.dll
- <SYSTEM32>\Macromed\Shockwave 10\DynaPlayer.dll
- <SYSTEM32>\Adobe\Director\M5drvr32.exe
- <SYSTEM32>\Adobe\Director\M5if32.dll
- <SYSTEM32>\Adobe\Shockwave 12\Plugin.dll
- <SYSTEM32>\Macromed\Shockwave 10\Plugin.dll
- <SYSTEM32>\Macromed\Shockwave 10\Control.dll
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\Swadcmpr.x32
- %WINDIR%\Installer\{49CD151E-5BE3-4A32-B9C3-687AD5B579B1}\ARPPRODUCTICON.exe
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\SWA Import Export.x32
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\Speech.x32
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\domain.txt
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\$WinMgmt.CFG
- %WINDIR%\Installer\2358f.ipi
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\INDEX.BTR
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\INDEX.MAP
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING.VER
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING2.MAP
- %WINDIR%\Installer\MSIC.tmp
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\OBJECTS.DATA
- %WINDIR%\Installer\MSI8.tmp
- %WINDIR%\Installer\MSI9.tmp
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\OBJECTS.MAP
- %TEMP%\~A.tmp
- C:\Config.Msi\23590.rbs
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\ComDb.Dat
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING1.MAP
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SAM
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-19
- %WINDIR%\Installer\2358d.msi
- %TEMP%\Cab1.tmp
- %TEMP%\Cab3.tmp
- %TEMP%\Cab5.tmp
- %WINDIR%\Installer\MSI7.tmp
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-18
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-19
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SOFTWARE
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-20
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-20
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2052111302-484763869-725345543-1003
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2052111302-484763869-725345543-1003
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_.DEFAULT
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SECURITY
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SYSTEM
- %TEMP%\CabD.tmp
- %TEMP%\CabF.tmp
- %TEMP%\Cab11.tmp
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\MacroMix.x32
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\Mix Services.x32
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\MP4Asset.x32
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\MPEG 3 Import Export.x32
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\Multiusr.x32
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\Havok.x32
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\INetURL.x32
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\Netfile.x32
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\QT6Asset.x32
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\RealMedia Asset.x32
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\Shockwave 3d Asset.x32
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\Sound Control.x32
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\Sound Import Export.x32
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\Netlingo.x32
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\PNG Import Export.x32
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\Font Xtra.x32
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\Font Asset.x32
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\FLVAsset.x32
- <SYSTEM32>\Adobe\Shockwave 12\shockwave_Projector_Loader.dcr
- <SYSTEM32>\Adobe\Shockwave 12\SwLogo.bmp
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\Animated GIF Asset.x32
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\AudioFilters.x32
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\AudioMixer.x32
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\BitmapFilters.x32
- %TEMP%\Cab13.tmp
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\CBrowser.x32
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\DirectSound.x32
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\DVD Asset.x32
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\Dynamiks.x32
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\Dynamiks_320.x32
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\F4VAsset.x32
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\Flash Asset.x32
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\Cursor Asset.x32
- <SYSTEM32>\Adobe\Shockwave 12\Xtras\Sun AU Import Export.x32
- %WINDIR%\Installer\MSI17.tmp
- %TEMP%\Cab1.tmp
- %WINDIR%\Installer\2358d.msi
- %WINDIR%\Installer\MSI17.tmp
- %TEMP%\~A.tmp
- C:\Config.Msi\23590.rbs
- %WINDIR%\Installer\MSI8.tmp
- %WINDIR%\Installer\MSI15.tmp
- %TEMP%\Cab13.tmp
- %TEMP%\Cab11.tmp
- %TEMP%\CabF.tmp
- %TEMP%\CabD.tmp
- %WINDIR%\Installer\MSIC.tmp
- %WINDIR%\Installer\MSI9.tmp
- %WINDIR%\Installer\MSI7.tmp
- %TEMP%\Cab5.tmp
- %TEMP%\Cab3.tmp
- %WINDIR%\Installer\2358f.ipi
- %TEMP%\7ZipSfx.000\ShockwavePlayer.msi
- 'wp#d':80
- 'ca#####.digicert.com':80
- 'download.windowsupdate.com':80
- http://11#.#11.111.1/wpad.dat via wp#d
- http://ca#####.digicert.com/DigiCertHighAssuranceEVRootCA.crt
- http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt via download.windowsupdate.com
- http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab via download.windowsupdate.com
- http://ca#####.digicert.com/DigiCertEVCodeSigningCA-SHA2.crt
- DNS ASK wp#d
- DNS ASK ca#####.digicert.com
- DNS ASK www.download.windowsupdate.com
- '<SYSTEM32>\Adobe\Shockwave 12\SwHelper_1232202.exe' /regserver
- '<SYSTEM32>\Adobe\Director\SWDNLD.exe' /regserver
- '<SYSTEM32>\msiexec.exe' /i "%TEMP%\7ZipSfx.000\ShockwavePlayer.msi" /qb /norestart
- '<SYSTEM32>\msiexec.exe' /V
- '<SYSTEM32>\msiexec.exe' -Embedding 2EBBA80E49529CDD86DCDC892753A456
- '<SYSTEM32>\msiexec.exe' -Embedding ADAB8117BAADDF17CD2091D4F5D2F451 M Global\MSI0000