WinPcap_4_0_2.exe reg write HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed WinPcap_4_0_2.exe reg write HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed WinPcap_4_0_2.exe reg write HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed WinPcap_4_0_2.exe reg write HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed WinPcap_4_0_2.exe reg write HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed WinPcap_4_0_2.exe reg write HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed WinPcap_4_0_2.exe reg write HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed WinPcap_4_0_2.exe reg write HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed WinPcap_4_0_2.exe reg write HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7623d280-d430-11dc-a835-806d6172696f}\BaseClass WinPcap_4_0_2.exe reg write HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7623d281-d430-11dc-a835-806d6172696f}\BaseClass WinPcap_4_0_2.exe reg write HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7623d282-d430-11dc-a835-806d6172696f}\BaseClass WinPcap_4_0_2.exe reg write HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F\BaseClass WinPcap_4_0_2.exe reg write HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G\BaseClass WinPcap_4_0_2.exe reg write HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\H\BaseClass WinPcap_4_0_2.exe create file D:\Profiles\admin\Local Settings\Temp\nsx870C.tmp WinPcap_4_0_2.exe delete D:\Profiles\admin\Local Settings\Temp\nsx870C.tmp WinPcap_4_0_2.exe create file D:\Profiles\admin\Local Settings\Temp\nsn870D.tmp WinPcap_4_0_2.exe delete D:\Profiles\admin\Local Settings\Temp\nsn870D.tmp WinPcap_4_0_2.exe create directory D:\Profiles\admin\Local Settings\Temp\nsn870D.tmp\ WinPcap_4_0_2.exe create file D:\Profiles\admin\Local Settings\Temp\nsn870D.tmp\UserInfo.dll WinPcap_4_0_2.exe create file D:\Profiles\admin\Local Settings\Temp\CACE_Banner.htm WinPcap_4_0_2.exe create file D:\Profiles\admin\Local Settings\Temp\CACE_Logo.gif WinPcap_4_0_2.exe create file D:\Profiles\admin\Local Settings\Temp\NetSol.jpg WinPcap_4_0_2.exe create file D:\Profiles\admin\Local Settings\Temp\nsn870D.tmp\ioSpecial.ini WinPcap_4_0_2.exe create file D:\Profiles\admin\Local Settings\Temp\nsn870D.tmp\modern-wizard.bmp WinPcap_4_0_2.exe create file D:\Profiles\admin\Local Settings\Temp\nsn870D.tmp\modern-header.bmp WinPcap_4_0_2.exe create file D:\Profiles\admin\Local Settings\Temp\nsn870D.tmp\nsWeb.dll WinPcap_4_0_2.exe reg write HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache WinPcap_4_0_2.exe reg write HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\Directory WinPcap_4_0_2.exe reg write HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\Paths WinPcap_4_0_2.exe reg write HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1\CachePath WinPcap_4_0_2.exe reg write HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2\CachePath WinPcap_4_0_2.exe reg write HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3\CachePath WinPcap_4_0_2.exe reg write HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4\CachePath WinPcap_4_0_2.exe reg write HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1\CacheLimit WinPcap_4_0_2.exe reg write HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2\CacheLimit WinPcap_4_0_2.exe reg write HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3\CacheLimit WinPcap_4_0_2.exe reg write HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4\CacheLimit WinPcap_4_0_2.exe reg write HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cookies WinPcap_4_0_2.exe reg write HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\History WinPcap_4_0_2.exe reg write HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass WinPcap_4_0_2.exe reg write HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName WinPcap_4_0_2.exe reg write HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet WinPcap_4_0_2.exe reg write HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass WinPcap_4_0_2.exe reg write HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\IntranetName WinPcap_4_0_2.exe reg write HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet WinPcap_4_0_2.exe create file D:\Profiles\admin\Local Settings\Temp\nsn870D.tmp\InstallOptions.dll WinPcap_4_0_2.exe delete D:\Profiles\admin\Local Settings\Temp\CACE_Banner.htm WinPcap_4_0_2.exe delete D:\Profiles\admin\Local Settings\Temp\CACE_Logo.gif WinPcap_4_0_2.exe delete D:\Profiles\admin\Local Settings\Temp\NetSol.jpg WinPcap_4_0_2.exe create directory C:\Program Files\WinPcap\ WinPcap_4_0_2.exe create file C:\Program Files\WinPcap\rpcapd.exe WinPcap_4_0_2.exe create file C:\Program Files\WinPcap\WinPcapInstall.dll WinPcap_4_0_2.exe create file C:\WINDOWS\system32\wpcap.dll WinPcap_4_0_2.exe create file C:\WINDOWS\system32\pthreadVC.dll WinPcap_4_0_2.exe create file C:\WINDOWS\system32\Packet.dll WinPcap_4_0_2.exe create file C:\WINDOWS\system32\WanPacket.dll WinPcap_4_0_2.exe create file C:\WINDOWS\system32\drivers\npf.sys WinPcap_4_0_2.exe create file D:\Profiles\admin\Local Settings\Temp\nsn870D.tmp\System.dll WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Control\Network\NetCfgLockHolder\(Default) WinPcap_4_0_2.exe reg write HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\@netcfgx.dll,-50003 WinPcap_4_0_2.exe reg write HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\@netcfgx.dll,-50002 WinPcap_4_0_2.exe reg write HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\@netcfgx.dll,-50020 WinPcap_4_0_2.exe reg write HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\@netcfgx.dll,-50001 WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Control\Network\Config WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0013\Linkage\Export WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0013\Linkage\RootDevice WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0013\Linkage\UpperBind WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Services\Eacfilt\Parameters\Adapters\{E686A895-BD36-45D9-968E-FCD023FE319B}\UpperBindings WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0009\NetCfgInstanceId WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0009\Linkage\UpperBind WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0014\Linkage\Export WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0014\Linkage\RootDevice WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0014\Linkage\UpperBind WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Services\Eacfilt\Parameters\Adapters\NdisWanBh\UpperBindings WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0008\NetCfgInstanceId WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0008\Linkage\UpperBind WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0015\Linkage\Export WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0015\Linkage\RootDevice WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0015\Linkage\UpperBind WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Services\Eacfilt\Parameters\Adapters\NdisWanIp\UpperBindings WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0007\NetCfgInstanceId WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0007\Linkage\UpperBind WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0018\Linkage\Export WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0018\Linkage\RootDevice WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0018\Linkage\UpperBind WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Services\Eacfilt\Parameters\Adapters\{4D5D0464-E671-4F70-AA27-5AC16C842C29}\UpperBindings WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0016\NetCfgInstanceId WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0016\Linkage\UpperBind WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0017\Linkage\Export WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0017\Linkage\RootDevice WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0017\Linkage\UpperBind WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Services\Eacfilt\Parameters\Adapters\{E9D9F944-258A-48F7-AC4A-FD253371C8B0}\UpperBindings WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0019\NetCfgInstanceId WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0019\Linkage\UpperBind WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0021\Linkage\Export WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0021\Linkage\RootDevice WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0021\Linkage\UpperBind WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Services\Eacfilt\Parameters\Adapters\{02C0DC6E-671E-4F40-8C76-7C40A2235C73}\UpperBindings WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0020\NetCfgInstanceId WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0020\Linkage\UpperBind WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0012\Linkage\Export WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0012\Linkage\RootDevice WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0012\Linkage\UpperBind WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Services\Eacfilt\Parameters\Adapters\{C4F18899-880D-44DA-8A1C-67F769F86FE0}\UpperBindings WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0011\NetCfgInstanceId WinPcap_4_0_2.exe reg write HKLM\System\CurrentControlSet\Control\Class\{4D36E972-E325-11CE-BFC1-08002bE10318}\0011\Linkage\UpperBind WinPcap_4_0_2.exe reg write HKLM\SOFTWARE\WinPcap\(Default) WinPcap_4_0_2.exe reg write HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinPcapInst\DisplayName WinPcap_4_0_2.exe reg write HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinPcapInst\UninstallString WinPcap_4_0_2.exe reg write HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinPcapInst\Publisher WinPcap_4_0_2.exe reg write HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinPcapInst\URLInfoAbout WinPcap_4_0_2.exe reg write HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinPcapInst\URLUpdateInfo WinPcap_4_0_2.exe reg write HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinPcapInst\VersionMajor WinPcap_4_0_2.exe reg write HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinPcapInst\VersionMinor WinPcap_4_0_2.exe reg write HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinPcapInst\DisplayVersion WinPcap_4_0_2.exe reg write HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Programs WinPcap_4_0_2.exe create directory D:\Profiles\All Users\Start Menu\Programs\WinPcap\ WinPcap_4_0_2.exe create file D:\Profiles\All Users\Start Menu\Programs\WinPcap\WinPcap Web Site.url WinPcap_4_0_2.exe create file D:\Profiles\All Users\Start Menu\Programs\WinPcap\Uninstall WinPcap 4.0.2.lnk WinPcap_4_0_2.exe reg write HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Desktop WinPcap_4_0_2.exe reg write HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Start Menu WinPcap_4_0_2.exe reg write HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Start Menu WinPcap_4_0_2.exe reg write HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Desktop WinPcap_4_0_2.exe reg write HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common AppData WinPcap_4_0_2.exe reg write HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\AppData WinPcap_4_0_2.exe reg write HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\My Pictures WinPcap_4_0_2.exe reg write HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Personal WinPcap_4_0_2.exe reg write HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\CommonPictures WinPcap_4_0_2.exe reg write HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Common Documents WinPcap_4_0_2.exe reg write HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\CommonMusic WinPcap_4_0_2.exe reg write HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\CommonVideo WinPcap_4_0_2.exe create file C:\Program Files\WinPcap\Uninstall.exe WinPcap_4_0_2.exe delete C:\Program Files\WinPcap\WinPcapInstall.dll WinPcap_4_0_2.exe delete D:\Profiles\admin\Local Settings\Temp\nsn870D.tmp\InstallOptions.dll WinPcap_4_0_2.exe delete D:\Profiles\admin\Local Settings\Temp\nsn870D.tmp\ioSpecial.ini WinPcap_4_0_2.exe delete D:\Profiles\admin\Local Settings\Temp\nsn870D.tmp\modern-header.bmp WinPcap_4_0_2.exe delete D:\Profiles\admin\Local Settings\Temp\nsn870D.tmp\modern-wizard.bmp WinPcap_4_0_2.exe delete D:\Profiles\admin\Local Settings\Temp\nsn870D.tmp\nsWeb.dll WinPcap_4_0_2.exe delete D:\Profiles\admin\Local Settings\Temp\nsn870D.tmp\System.dll WinPcap_4_0_2.exe delete D:\Profiles\admin\Local Settings\Temp\nsn870D.tmp\UserInfo.dll WinPcap_4_0_2.exe delete D:\Profiles\admin\Local Settings\Temp\nsn870D.tmp