File: 0218178eec35acad7909a413d94d84ae3d465a6ea37e932093ec4c7a9b6a7394

Metadata
File name:jaff.pdf.infected.0218178eec35acad7909a413d94d84ae3d465a6ea37e932093ec4c7a9b6a7394
File type:PDF document, version 1.4
File size:62117 bytes
Analysis date:2017-07-05 13:04:38
MD5:7dfe13dec07e92b392062573ec837348
SHA1:c4928dfcf7e98f1245c3c60ba029b52cf071e425
SHA256:0218178eec35acad7909a413d94d84ae3d465a6ea37e932093ec4c7a9b6a7394
SHA512:cbcf32031496286f8713ea31db37121a91c1a758d6a87a155e6f20c8de5dac7ce01e90fd0337ecd330dedfa4b49c7357e25991da264204fc85fe8ddfaf56b436
SSDEEP:1536:V5zK483jOLt332pCyUG/fecwMaGBDfTfUR:n248TOZ3mpCkJwMz9UR
IMPHASH:N/A
Authentihash:N/A
Related resources
APTNotes
Cyber threat intelligence reports associated with 0218178eec35acad7909a413d94d84ae3d465a6ea37e932093ec4c7a9b6a7394.
Loading...
Domains
Domains the malware sample communicates with.
Hosts
Hosts the malware sample communicates with.
HTTP Requests
HTTP requests the malware sample makes.
Registry keys
Registry keys created by the malware sample.
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe Acrobat\9.0\Security
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\ORO
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Memory Management\PrefetchParameters
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\IMM
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers
HKEY_CURRENT_USER\SOFTWARE\Microsoft\CTF
HKEY_LOCAL_MACHINE\Software\Microsoft\CTF\SystemShared
HKEY_LOCAL_MACHINE\System
HKEY_LOCAL_MACHINE\System\Acrobatviewercpp304
HKEY_LOCAL_MACHINE\Software\Adobe
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Installer\Migrated
HKEY_LOCAL_MACHINE\Software\Adobe\Repair\Acrobat Reader\9.0\IOD
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Language\current
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\Installer
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Installer
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1547161642-507921405-839522115-1004\Installer\Products\68AB67CA7DA73301B7449A0400000010
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004\Software\Microsoft\Installer\Products\68AB67CA7DA73301B7449A0400000010
HKEY_LOCAL_MACHINE\Software\Classes\Installer\Products\68AB67CA7DA73301B7449A0400000010
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\68AB67CA7DA73301B7449A0400000010\InstallProperties
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\9.0\Installer\Migrated
HKEY_CURRENT_USER\Software\Adobe\Acrobat Distiller\9.0\Installer\Migrated
HKEY_CURRENT_USER\Software\Adobe\Acrobat Elements\9.0\Installer\Migrated
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\Installer\Migrate
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Language\path
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\Language\path
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Language\select
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Language\next
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\Language\next
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Language\UseMUI
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\AdobeViewer
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\AVGeneral
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\SDI
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Originals
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\AVPrivate
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Private
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\Private
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Hotfix
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\Hotfix
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\AVGeneral
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\AcroRd32.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Objects\{20D04FE0-3AEA-1069-A2D8-08002B30309D}
HKEY_CLASSES_ROOT\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{475c7950-e3d2-11e0-8d7a-806d6172696f}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{475c7952-e3d2-11e0-8d7a-806d6172696f}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{475c7952-e3d2-11e0-8d7a-806d6172696f}\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{475c7950-e3d2-11e0-8d7a-806d6172696f}\
HKEY_CLASSES_ROOT\Directory
HKEY_CLASSES_ROOT\Directory\CurVer
HKEY_CLASSES_ROOT\Directory\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
HKEY_CLASSES_ROOT\Directory\\ShellEx\IconHandler
HKEY_CLASSES_ROOT\Directory\\Clsid
HKEY_CLASSES_ROOT\Folder
HKEY_CLASSES_ROOT\Folder\Clsid
HKEY_CLASSES_ROOT\CLSID
HKEY_CLASSES_ROOT\CLSID\{00021401-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\CLSID\{00021401-0000-0000-C000-000000000046}\InProcServer32
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Type 1 Installer\Type 1 Fonts
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\AVConversionToPDF
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\AVConversionToPDF
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\AVConversionFromPDF
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\AVConversionFromPDF
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\Language\current
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Intl
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\AVPrivate
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\Intl
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RIF
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\RIF
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Selection
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\Selection
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Adobe\Acrobat Reader\9.0\FeatureLockdown
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Adobe\Acrobat Reader\9.0\FeatureLockdown\cDefaultExecMenuItems
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Adobe\Acrobat Reader\9.0\FeatureLockdown\cDefaultLaunchAttachmentPerms
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Adobe\Acrobat Reader\9.0\FeatureLockdown\cDefaultLaunchURLPerms
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\Originals
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\AVDisplay
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\AVDisplay
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004
HKEY_LOCAL_MACHINE\Software\Microsoft\Ole
HKEY_CLASSES_ROOT\AppID\AcroRd32.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\ComputerName
ActiveComputerName
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Workflows
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\Workflows
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\SDI
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Annots
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\Annots
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\AVAlert
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\AVAlert
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\9.0
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\9.0\DiskCabs
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Collab
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\Collab
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\AVTracker
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\AVTracker
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\TaskButtons
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\TaskButtons
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\AutoSaveDocs
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\AutoSaveDocs
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\AdobeViewer
HKEY_CURRENT_USER\Software\Adobe\Adobe Synchronizer\9.0
HKEY_CURRENT_USER\Software\Adobe\Adobe Acrobat\9.1024\AVPrivate
HKEY_LOCAL_MACHINE\SOFTWARE\Adobe\Acrobat Reader\9.0\JavaScriptPerms
HKEY_CURRENT_USER\Software\Adobe\Adobe Synchronizer\9.0\Acrobat.com
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Collab\cDocumentCenter
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Collab\cDocumentCenter\cSettings
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Collab\cEmailDistribution
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Collab\cEmailDistribution\cSettings
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Collab\cInitiationWizardFirstLaunch
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\JSPrefs
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\JSPrefs
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Preview
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\Preview
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Access
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\Access
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\LayoutAndZoom
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\LayoutAndZoom
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Class\{4D36E96E-E325-11CE-BFC1-08002BE10318}\0000
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ICM\RegisteredProfiles
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\RememberedViews
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\RememberedViews
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\TrustManager
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\TrustManager
HKEY_LOCAL_MACHINE\Software\Microsoft\COM3
HKEY_USERS\S-1-5-21-1547161642-507921405-839522115-1004_Classes
HKEY_LOCAL_MACHINE\Software\Classes
\REGISTRY\USER
HKEY_LOCAL_MACHINE\Software\Classes\CLSID
CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}
CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\TreatAs
\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}
\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\InprocServer32
\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\InprocServerX86
\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\LocalServer32
\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\InprocHandler32
\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\InprocHandlerX86
\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\LocalServer
HKEY_CLASSES_ROOT\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}
HKEY_CLASSES_ROOT\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\TreatAs
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\\Ranges\
HKEY_CLASSES_ROOT\PROTOCOLS\Name-Space Handler\
HKEY_CLASSES_ROOT\PROTOCOLS\Name-Space Handler\C\
HKEY_CLASSES_ROOT\PROTOCOLS\Name-Space Handler\*\
HKEY_CURRENT_USER\SOFTWARE\Classes\PROTOCOLS\Handler\C
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\C
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Attachments
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\Attachments
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups
CLSID\{B5F8350B-0548-48B1-A6EE-88BD00B4A5E7}
CLSID\{B5F8350B-0548-48B1-A6EE-88BD00B4A5E7}\TreatAs
\CLSID\{B5F8350B-0548-48B1-A6EE-88BD00B4A5E7}
\CLSID\{B5F8350B-0548-48B1-A6EE-88BD00B4A5E7}\InprocServer32
\CLSID\{B5F8350B-0548-48B1-A6EE-88BD00B4A5E7}\InprocServerX86
\CLSID\{B5F8350B-0548-48B1-A6EE-88BD00B4A5E7}\LocalServer32
\CLSID\{B5F8350B-0548-48B1-A6EE-88BD00B4A5E7}\InprocHandler32
\CLSID\{B5F8350B-0548-48B1-A6EE-88BD00B4A5E7}\InprocHandlerX86
\CLSID\{B5F8350B-0548-48B1-A6EE-88BD00B4A5E7}\LocalServer
\AppID\{667524BE-9EC0-4196-91C9-C6ED1F7A899D}
HKEY_CLASSES_ROOT\CLSID\{B5F8350B-0548-48B1-A6EE-88BD00B4A5E7}
HKEY_CLASSES_ROOT\CLSID\{B5F8350B-0548-48B1-A6EE-88BD00B4A5E7}\TreatAs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Accessibility\Handlers
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLEAUT
HKEY_CLASSES_ROOT\TypeLib
HKEY_CLASSES_ROOT\TypeLib\{1EA4DBF0-3C3B-11CF-810C-00AA00389B71}
HKEY_CLASSES_ROOT\TypeLib\{1EA4DBF0-3C3B-11CF-810C-00AA00389B71}\1.1
HKEY_CLASSES_ROOT\TypeLib\{1EA4DBF0-3C3B-11CF-810C-00AA00389B71}\1.1\FLAGS
HKEY_CLASSES_ROOT\TypeLib\{1EA4DBF0-3C3B-11CF-810C-00AA00389B71}\1.1\0
HKEY_CLASSES_ROOT\TypeLib\{1EA4DBF0-3C3B-11CF-810C-00AA00389B71}\1.1\0\win32
HKEY_CLASSES_ROOT\TypeLib\{1EA4DBF0-3C3B-11CF-810C-00AA00389B71}\1.1\HELPDIR
HKEY_CLASSES_ROOT\Interface
HKEY_CLASSES_ROOT\Interface\{618736E0-3C3D-11CF-810C-00AA00389B71}
HKEY_CLASSES_ROOT\Interface\{618736E0-3C3D-11CF-810C-00AA00389B71}\ProxyStubClsid
HKEY_CLASSES_ROOT\Interface\{618736E0-3C3D-11CF-810C-00AA00389B71}\ProxyStubClsid32
HKEY_CLASSES_ROOT\Interface\{618736E0-3C3D-11CF-810C-00AA00389B71}\TypeLib
HKEY_CLASSES_ROOT\Interface\{03022430-ABC4-11D0-BDE2-00AA001A1953}
HKEY_CLASSES_ROOT\Interface\{03022430-ABC4-11D0-BDE2-00AA001A1953}\ProxyStubClsid
HKEY_CLASSES_ROOT\Interface\{03022430-ABC4-11D0-BDE2-00AA001A1953}\ProxyStubClsid32
HKEY_CLASSES_ROOT\Interface\{03022430-ABC4-11D0-BDE2-00AA001A1953}\TypeLib
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\MeasuringGeo
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\MeasuringGeo
HKEY_CURRENT_USER\Keyboard Layout\Toggle
HKEY_CURRENT_USER\SOFTWARE\Microsoft\CTF\LangBarAddIn\
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\CTF\LangBarAddIn\
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Attachments\cUserLaunchAttachmentPerms
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Attachments\cUserLaunchAttachmentPerms\cAttachmentTypeToPermList
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Attachments\cUserLaunchAttachmentPerms\cAttachmentTypeToPermList\cdocm
CLSID\{B801CA65-A1FC-11D0-85AD-444553540000}
CLSID\{B801CA65-A1FC-11D0-85AD-444553540000}\TreatAs
\CLSID\{B801CA65-A1FC-11D0-85AD-444553540000}
\CLSID\{B801CA65-A1FC-11D0-85AD-444553540000}\InprocServer32
\CLSID\{B801CA65-A1FC-11D0-85AD-444553540000}\InprocServerX86
\CLSID\{B801CA65-A1FC-11D0-85AD-444553540000}\LocalServer32
\CLSID\{B801CA65-A1FC-11D0-85AD-444553540000}\InprocHandler32
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\UsageMeasurement
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\UsageMeasurement
HKEY_CURRENT_USER\Software\Adobe\CommonFiles\Usage\Reader 9
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\General
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\General
HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\9.0\Updater
HKEY_LOCAL_MACHINE\Software\Adobe\Acrobat Reader\9.0\Updater
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System
HKEY_LOCAL_MACHINE\System\WSZXSGANXFJVAYSXYQGNXKQY
HKEY_LOCAL_MACHINE\Software\Adobe\Adobe ARM\1.0\ARM
Comments
User comments about 0218178eec35acad7909a413d94d84ae3d465a6ea37e932093ec4c7a9b6a7394.
NOTICE: We have updated our privacy terms and conditions in accordance to GDPR. By using our site, you acknowledge that you have read and understand our Privacy Policy. Your use of ThreatMiner’s Products and Services is subject to these policies and terms.