%APPDATA%\Twitch Leecher
new catalogue created
%APPDATA%\Twitch Leecher\runtime.xml
new file created
HKEY_USERS\%ID-USER-SID%_Classes\Local Settings\MuiCache\33\E27DDEF7\\@%SystemRoot%\System32\ci.dll,-100
new registry key parameter created
HKEY_USERS\%ID-USER-SID%_Classes\Local Settings\MuiCache\33\E27DDEF7\\@%SystemRoot%\System32\ci.dll,-101
new registry key parameter created
HKEY_USERS\%ID-USER-SID%_Classes\Local Settings\MuiCache\33\E27DDEF7\\@%SystemRoot%\system32\dnsapi.dll,-103
new registry key parameter created
HKEY_USERS\%ID-USER-SID%_Classes\Local Settings\MuiCache\33\E27DDEF7\\@%SystemRoot%\System32\fveui.dll,-843
new registry key parameter created
HKEY_USERS\%ID-USER-SID%_Classes\Local Settings\MuiCache\33\E27DDEF7\\@%SystemRoot%\System32\fveui.dll,-844
new registry key parameter created
HKEY_USERS\%ID-USER-SID%_Classes\Local Settings\MuiCache\33\E27DDEF7\\@%SystemRoot%\System32\wuaueng.dll,-400
new registry key parameter created
HKEY_USERS\%ID-USER-SID%_Classes\Local Settings\MuiCache\33\E27DDEF7\\@%SystemRoot%\system32\WindowsPowerShell\v1.0\powershell.exe,-124
new registry key parameter created
HKEY_USERS\%ID-USER-SID%_Classes\Local Settings\MuiCache\33\E27DDEF7\\@%SystemRoot%\system32\NgcRecovery.dll,-100
new registry key parameter created
HKEY_USERS\%ID-USER-SID%_Classes\Local Settings\MuiCache\54\655C8779\\@%SystemRoot%\System32\ci.dll,-100
new registry key parameter created
HKEY_USERS\%ID-USER-SID%_Classes\Local Settings\MuiCache\54\655C8779\\@%SystemRoot%\System32\ci.dll,-101
new registry key parameter created
HKEY_USERS\%ID-USER-SID%_Classes\Local Settings\MuiCache\54\655C8779\\@%SystemRoot%\system32\dnsapi.dll,-103
new registry key parameter created
HKEY_USERS\%ID-USER-SID%_Classes\Local Settings\MuiCache\54\655C8779\\@%SystemRoot%\System32\fveui.dll,-843
new registry key parameter created
HKEY_USERS\%ID-USER-SID%_Classes\Local Settings\MuiCache\54\655C8779\\@%SystemRoot%\System32\fveui.dll,-844
new registry key parameter created
HKEY_USERS\%ID-USER-SID%_Classes\Local Settings\MuiCache\54\655C8779\\@%SystemRoot%\System32\wuaueng.dll,-400
new registry key parameter created
HKEY_USERS\%ID-USER-SID%_Classes\Local Settings\MuiCache\54\655C8779\\@%SystemRoot%\system32\WindowsPowerShell\v1.0\powershell.exe,-124
new registry key parameter created
HKEY_USERS\%ID-USER-SID%_Classes\Local Settings\MuiCache\54\655C8779\\@%SystemRoot%\system32\NgcRecovery.dll,-100
new registry key parameter created
HKEY_USERS\%ID-USER-SID%_Classes\Local Settings\MuiCache\54\655C8779\\@windows.storage.dll,-21825
new registry key parameter created
HKEY_USERS\%ID-USER-SID%_Classes\Local Settings\MuiCache\54\655C8779\\@%systemroot%\system32\dtsh.dll,-40001
new registry key parameter created
HKEY_USERS\%ID-USER-SID%_Classes\Local Settings\MuiCache\54\655C8779\\@%systemroot%\system32\FirewallControlPanel.dll,-12122
new registry key parameter created
HKEY_USERS\%ID-USER-SID%\SOFTWARE\AMD\HKIDs\\42C4*twitchleecher.exe
new registry key parameter created
%LOCALAPPDATA%\AMD\DxCache\fee860622e497b906cd557cf05e794734502974ef1e1d82f.bin
new file created
HKEY_USERS\%ID-USER-SID%\SOFTWARE\AMD\HKIDs\\37AC*twitchleecher.exe
new registry key parameter created
HKEY_USERS\%ID-USER-SID%_Classes\Local Settings\MuiCache\38\63C768CF\\@%SystemRoot%\System32\ci.dll,-100
new registry key parameter created
HKEY_USERS\%ID-USER-SID%_Classes\Local Settings\MuiCache\38\63C768CF\\@%SystemRoot%\System32\ci.dll,-101
new registry key parameter created
HKEY_USERS\%ID-USER-SID%_Classes\Local Settings\MuiCache\38\63C768CF\\@%SystemRoot%\system32\dnsapi.dll,-103
new registry key parameter created
HKEY_USERS\%ID-USER-SID%_Classes\Local Settings\MuiCache\38\63C768CF\\@%SystemRoot%\System32\fveui.dll,-843
new registry key parameter created
HKEY_USERS\%ID-USER-SID%_Classes\Local Settings\MuiCache\38\63C768CF\\@%SystemRoot%\System32\fveui.dll,-844
new registry key parameter created
HKEY_USERS\%ID-USER-SID%_Classes\Local Settings\MuiCache\38\63C768CF\\@%SystemRoot%\System32\wuaueng.dll,-400
new registry key parameter created
HKEY_USERS\%ID-USER-SID%_Classes\Local Settings\MuiCache\38\63C768CF\\@%SystemRoot%\system32\WindowsPowerShell\v1.0\powershell.exe,-124
new registry key parameter created
HKEY_USERS\%ID-USER-SID%_Classes\Local Settings\MuiCache\38\63C768CF\\@%SystemRoot%\system32\NgcRecovery.dll,-100
new registry key parameter created