HKEY_USERS\%ID-USER-SID%\Software\Google\Common
new registry key created
HKEY_USERS\%ID-USER-SID%\Software\Google\Common\Rlz
new registry key created
HKEY_USERS\%ID-USER-SID%\Software\Google\Common\Rlz\Events
new registry key created
%PROGRAMFILES(X64)%\CryptoTab Browser\Temp
new catalogue created
%PROGRAMFILES(X64)%\CryptoTab Browser\Application\old_browser.exe
file renamed
%PROGRAMFILES(X64)%\CryptoTab Browser\Application\browser.exe
file renamed
%PROGRAMFILES(X64)%\CryptoTab Browser\Application\old_chrome_proxy.exe
file renamed
%PROGRAMFILES(X64)%\CryptoTab Browser\Application\chrome_proxy.exe
file renamed
%PROGRAMFILES(X64)%\CryptoTab Browser\Application\SetupMetrics\20210108180639.pma
file renamed
%PROGRAMFILES(X64)%\CryptoTab Browser\Temp\scoped_dir5432_1082234786
new catalogue created
%PROGRAMFILES(X64)%\CryptoTab Browser\Temp\scoped_dir5432_1082234786\old_browser.exe
file moved
%PROGRAMFILES(X64)%\CryptoTab Browser\Temp\scoped_dir5432_1064446468
new catalogue created
%PROGRAMFILES(X64)%\CryptoTab Browser\Temp\scoped_dir5432_1064446468\old_chrome_proxy.exe
file moved
%PROGRAMFILES(X64)%\CryptoTab Browser\Application\SetupMetrics\46887b19-7af1-4a02-bbcb-4e25673640e8.tmp
new file created
%PROGRAMFILES(X64)%\CryptoTab Browser\Application\SetupMetrics\20210214095314.pma
file renamed
%PROGRAMFILES(X64)%\CryptoTab Browser\Application\SetupMetrics\161553af-8fe9-41aa-9548-9b96240874c6.tmp
new file created
%PROGRAMFILES(X64)%\CryptoTab Browser\Application\SetupMetrics\20210214095329.pma
file renamed
HKEY_USERS\%ID-USER-SID%\Software\CryptoTab Browser
new registry key created
HKEY_USERS\%ID-USER-SID%\Software\CryptoTab Browser\\current_version_setup
new registry key parameter created
HKEY_USERS\%ID-USER-SID%\Software\CryptoTab Browser\\current_version_setup_path
new registry key parameter created
HKEY_USERS\%ID-USER-SID%\Software\CryptoTab Browser\\current_version_level
new registry key parameter created
%SystemDrive%\Users\Yacouba\AppData\Local\Temp\chromium_installer.log
new file created
%SystemDrive%\Users\Yacouba\AppData\Local\CryptoTab Browser
new catalogue created
%SystemDrive%\Users\Yacouba\AppData\Local\CryptoTab Browser\User Data
new catalogue created
%SystemDrive%\Users\Yacouba\AppData\Local\CryptoTab Browser\User Data\Crashpad
new catalogue created
%SystemDrive%\Users\Yacouba\AppData\Local\CryptoTab Browser\User Data\Crashpad\reports
new catalogue created
%SystemDrive%\Users\Yacouba\AppData\Local\CryptoTab Browser\User Data\Crashpad\settings.dat
new file created
%SystemDrive%\Users\Yacouba\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\CryptoTab Browser.lnk
new file created
HKEY_USERS\%ID-USER-SID%\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached\\{596AB062-B4D2-4215-9F74-E9109B0A8153} {000214E4-0000-0000-C000-000000000046} 0xFFFF
new registry key parameter created
HKEY_USERS\%ID-USER-SID%\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached\\{474C98EE-CF3D-41F5-80E3-4AAB0AB04301} {000214E4-0000-0000-C000-000000000046} 0xFFFF
new registry key parameter created
HKEY_USERS\%ID-USER-SID%\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached\\{472083B0-C522-11CF-8763-00608CC02F24} {000214E4-0000-0000-C000-000000000046} 0xFFFF
new registry key parameter created
HKEY_USERS\%ID-USER-SID%\Software\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ThumbnailCacheSQMDataCollected
new registry key created
%SystemDrive%\Users\Yacouba\AppData\Local\Microsoft\Windows\Explorer\iconcache_idx.db
new file created
%SystemDrive%\Users\Yacouba\AppData\Local\Microsoft\Windows\Explorer\iconcache_16.db
new file created
%SystemDrive%\Users\Yacouba\AppData\Local\Microsoft\Windows\Explorer\iconcache_32.db
new file created
%SystemDrive%\Users\Yacouba\AppData\Local\Microsoft\Windows\Explorer\iconcache_48.db
new file created
%SystemDrive%\Users\Yacouba\AppData\Local\Microsoft\Windows\Explorer\iconcache_96.db
new file created
%SystemDrive%\Users\Yacouba\AppData\Local\Microsoft\Windows\Explorer\iconcache_256.db
new file created
%SystemDrive%\Users\Yacouba\AppData\Local\Microsoft\Windows\Explorer\iconcache_1024.db
new file created
%SystemDrive%\Users\Yacouba\AppData\Local\Microsoft\Windows\Explorer\iconcache_1600.db
new file created
%SystemDrive%\Users\Yacouba\AppData\Local\Microsoft\Windows\Explorer\iconcache_sr.db
new file created
%SystemDrive%\Users\Yacouba\AppData\Local\Microsoft\Windows\Explorer\iconcache_wide.db
new file created
%SystemDrive%\Users\Yacouba\AppData\Local\Microsoft\Windows\Explorer\iconcache_exif.db
new file created
%SystemDrive%\Users\Yacouba\AppData\Local\Microsoft\Windows\Explorer\iconcache_wide_alternate.db
new file created
HKEY_USERS\%ID-USER-SID%\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached\\{573FFD05-2805-47C2-BCE0-5F19512BEB8D} {BDDACB60-7657-47AE-8445-D23E1ACF82AE} 0xFFFF
new registry key parameter created
HKEY_USERS\%ID-USER-SID%\Software\Microsoft\Office
new registry key created
HKEY_USERS\%ID-USER-SID%\Software\Microsoft\Office\15.0
new registry key created
HKEY_USERS\%ID-USER-SID%_Classes\Local Settings\MuiCache\36\52C64B7E\\@%systemroot%\system32\FirewallControlPanel.dll,-12122
new registry key parameter created
HKEY_USERS\%ID-USER-SID%\Software\Microsoft\Office\15.0\Groove
new registry key created
HKEY_USERS\%ID-USER-SID%\Software\Microsoft\Office\15.0\Groove\SPFS
new registry key created
HKEY_USERS\%ID-USER-SID%\Software\Microsoft\Office\15.0\Groove\SPFS\Descriptor
new registry key created
HKEY_USERS\%ID-USER-SID%\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached\\{B41DB860-64E4-11D2-9906-E49FADC173CA} {000214E4-0000-0000-C000-000000000046} 0xFFFF
new registry key parameter created
%SystemDrive%\Users\Yacouba\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned
new catalogue created
%SystemDrive%\Users\Yacouba\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts
new catalogue created
%SystemDrive%\Users\Yacouba\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar
new catalogue created
%SystemDrive%\Users\Yacouba\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\CryptoTab Browser.lnk
new file created
HKEY_USERS\%ID-USER-SID%\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband
new registry key created
HKEY_USERS\%ID-USER-SID%\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband\\FavoritesResolve
new registry key parameter created
HKEY_USERS\%ID-USER-SID%\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband\\Favorites
new registry key parameter created
HKEY_USERS\%ID-USER-SID%\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband\\FavoritesChanges
new registry key parameter created
HKEY_USERS\%ID-USER-SID%\Software\Microsoft\Windows\CurrentVersion\Explorer\Taskband\\FavoritesVersion
new registry key parameter created
%SystemDrive%\Users\Yacouba\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\CryptoTab Browser (2).lnk
new file created
%TMP%\dc8ee786-ab65-4901-bcab-073191ba96fb.tmp
new file created
%PROGRAMFILES(X86)%\CryptoTab Browser\Application\87.0.4280.88\Installer\debug.log
new file created
%TMP%\8b9a7fc1-78d2-4479-b6c6-272dd3d8dec6.tmp
new file created
%TMP%\8b9a7fc1-78d2-4479-b6c6-272dd3d8dec6.tmp
file moved
HKEY_USERS\.DEFAULT\Software\CryptoTab Browser\\current_version_setup
new registry key parameter created
HKEY_USERS\.DEFAULT\Software\CryptoTab Browser\\current_version_setup_path
new registry key parameter created
HKEY_USERS\.DEFAULT\Software\CryptoTab Browser\\current_version_level
new registry key parameter created
%PROGRAMFILES(X64)%\CryptoTab Browser\Temp\scoped_dir4772_432354978
new catalogue created
%PROGRAMFILES(X64)%\CryptoTab Browser\Temp\scoped_dir4772_432354978\old_browser.exe
file moved
%PROGRAMFILES(X64)%\CryptoTab Browser\Temp\scoped_dir4772_1024435051
new catalogue created
%PROGRAMFILES(X64)%\CryptoTab Browser\Temp\scoped_dir4772_1024435051\old_chrome_proxy.exe
file moved
%PROGRAMFILES(X64)%\CryptoTab Browser\Application\SetupMetrics\9b1816f2-452d-47d7-b5ee-905a55a3f449.tmp
new file created
%PROGRAMFILES(X64)%\CryptoTab Browser\Application\SetupMetrics\20210108180624.pma
file renamed
%PROGRAMFILES(X64)%\CryptoTab Browser\Application\SetupMetrics\a7bbf227-655d-4cc0-87ec-0ca2aad52d79.tmp
new file created