ALIASES:

Downloader (Symantec); Trojan.Win32.Generic!BT (Sunbelt)

 PLATFORM:

Windows

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted:

  • In the wild: Yes

  OVERVIEW

This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

  TECHNICAL DETAILS

File Size: 4,437,000 bytes
File Type: EXE
Memory Resident: No
Initial Samples Received Date: 01 Mar 2017

Arrival Details

This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

Installation

This Trojan creates the following folders:

  • %System Root%\MSI1241e.tmp
  • %System Root%\Config.Msi
  • %Program Files%\amuleC
  • %Program Files%\amuleC\locale
  • %Program Files%\amuleC\locale\pt_PT
  • %Program Files%\amuleC\locale\et_EE
  • %Program Files%\amuleC\locale\el
  • %Program Files%\amuleC\locale\ca
  • %Program Files%\amuleC\skins
  • %User Profile%\Application Data\aMule
  • %Program Files%\amuleC\locale\de
  • %Program Files%\amuleC\locale\cs
  • %Program Files%\amuleC\locale\he
  • %Program Files%\amuleC\locale\eu
  • %Program Files%\amuleC\locale\it_CH
  • %Program Files%\amuleC\docs
  • %Program Files%\amuleC\locale\it
  • %Program Files%\amuleC\locale\uk
  • %Program Files%\amuleC\locale\ar
  • %Program Files%\amuleC\locale\fr
  • %Program Files%\amuleC\locale\sq
  • %Program Files%\amuleC\locale\hu
  • %Program Files%\amuleC\locale\gl
  • %Program Files%\amuleC\locale\tr
  • %Program Files%\amuleC\locale\pt_BR
  • %Program Files%\amuleC\locale\zh_CN
  • %Program Files%\amuleC\locale\pl
  • %Program Files%\amuleC\locale\ko_KR
  • %Program Files%\amuleC\locale\fi
  • %Program Files%\amuleC\locale\zh_TW
  • %Program Files%\amuleC\locale\hr
  • %Program Files%\amuleC\locale\bg
  • %Program Files%\amuleC\locale\nn
  • %Program Files%\amuleC\locale\lt
  • %Program Files%\amuleC\locale\ru
  • %Program Files%\amuleC\locale\sv
  • %Program Files%\amuleC\locale\da
  • %Program Files%\amuleC\locale\es
  • %Program Files%\amuleC\locale\nl
  • %Program Files%\amuleC\locale\ast
  • %Program Files%\amuleC\locale\ja
  • %Program Files%\amuleC\locale\en_GB
  • %Program Files%\amuleC\locale\sl
  • %Start Menu%\Programs\amuleC
  • %User Profile%\Microsoft\Installer
  • %User Profile%\Installer\{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}

(Note: %System Root% is the Windows root folder, where it usually is C:\ on all Windows operating system versions.. %Program Files% is the Program Files folder, where it usually is C:\Program Files on all Windows operating system versions; C:\Program Files (x86) for 32-bit applications running on Windows 64-bit operating systems.. %User Profile% is the current user's profile folder, which is usually C:\Documents and Settings\{user name} on Windows 2000, XP, and Server 2003, or C:\Users\{user name} on Windows Vista and 7.. %Start Menu% is the Start Menu folder, where it usually is C:\Documents and Settings\{user name}\Start Menu on Windows 2000, Windows Server 2003, and Windows XP (32- and 64-bit); C:\Users\{user name}\AppData\Roaming\Microsoft\Windows\Start Menu on Windows Vista (32- and 64-bit), Windows 7 (32- and 64-bit), Windows 8 (32- and 64-bit), Windows 8.1 (32- and 64-bit), Windows Server 2008, and Windows Server 2012.)

Other System Modifications

This Trojan deletes the following files:

  • %System Root%\Config.Msi\MSIF.tmp
  • %System Root%\Config.Msi\MSI85.tmp
  • CWS_H15_VC07

(Note: %System Root% is the Windows root folder, where it usually is C:\ on all Windows operating system versions.)

It deletes the following folders:

  • %User Profile%\My Documents\My Pictures
  • %Start Menu%\Programs\Administrative Tools

(Note: %User Profile% is the current user's profile folder, which is usually C:\Documents and Settings\{user name} on Windows 2000, XP, and Server 2003, or C:\Users\{user name} on Windows Vista and 7.. %Start Menu% is the Start Menu folder, where it usually is C:\Documents and Settings\{user name}\Start Menu on Windows 2000, Windows Server 2003, and Windows XP (32- and 64-bit); C:\Users\{user name}\AppData\Roaming\Microsoft\Windows\Start Menu on Windows Vista (32- and 64-bit), Windows 7 (32- and 64-bit), Windows 8 (32- and 64-bit), Windows 8.1 (32- and 64-bit), Windows Server 2008, and Windows Server 2012.)

It adds the following registry keys:

hkey_local_machine\software\microsoft\
esent\process\{malware file name}

hkey_local_machine\software\microsoft\
esent\process\{malware file name}\
debug

HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows\CurrentVersion\Installer\
InProgress

HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows\CurrentVersion\Installer\
Rollback\Scripts

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
F32566D2C1A15D258CD2886A5FE65611

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
4B1A85EE0B1113F03A43F3633FC1097E

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
9A06B67C5B71E0229D9DB3DA9F413DCE

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
6C84BCCB56C80E904F168AC72BA0CC8F

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
44E10F7B65FFBDC6F2C7EC961CC4E6FF

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
75489DB7067AD2FB6CEB32263D085370

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
A10F67DDF71B685DA5131EA3147961B7

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
67418ACCF1E3018F5C1F2737C9536FD5

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
66A3A12EC88C6762A5951FC8D056D507

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
1EB0D09D105CABCB19CAA60EF650CDF2

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
201BBF441F3AF77DCE7849159F9FC225

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
3EF64958B490A8A813D6FAA9797F3CBB

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
091417CD589D17BFFE41F439404564A2

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
D7C740408CE4573BD9AFFBBFFC0DDD78

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
33B587F08FFBE3323D7CC3A6E0FDE748

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
48AFA3CEAA852FD44C1A8D0E9A4E67A2

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
5DB9B9FDCF29176B4A3E145BD7B90B2F

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
7AB3CF5644132D0B6E3CE72A8BB3D37A

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
47777C87A7B3477ECA4466B00713FB4D

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
52CF5F71D2CA50F19B0B5B5B94FB083E

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
A4174B2F749380D522F84E050D97B8AC

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
16C0F30491F3E7610D9FF0694E9EBD90

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
BCA4CCCFE1F41DBC7605BC0A93EAD6F0

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
50C3E8F161115450BC95D4A867239412

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
5A0C62E5E28110ECD79357EC7B28CE06

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
A18938C1B189405A26B533F56B311843

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
E776B9D4EC304733C04B28C6FC8CFC99

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
F09B0616DD97AD2DE5A717C8BD176E70

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
6BEF29B8BFF602C1B1F1886B0F1EFA28

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
79F184906D5FAA2837E31036276D3520

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
42CD96D6C2D937962FE7ACC8B63D4E19

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
5EE356F4C55B21C26C9E01200E6F3518

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
2265783AB350FF6FBF0A6FCB7FFC3EBA

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
94CE0AF6E5E5EC775388942C15558DFC

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
1B56275EDF932276BE64060476D7D110

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
AF27465CAF64CC1DB5585E950BF1F843

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
3DD38CDF50F9BA8942AB0C19B7BC76C3

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
6A2C63A4EC815D44007110049B8686FD

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
9A7393D03D5504AABA95BC63FF69FC90

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
819F2BBA6DFF9D152436A978134779FA

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
9F3600890788BC092D45407A1FE60E45

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
8649C6E61720F5E9611756CD5ADB918C

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
EA341A350898696EFF10B853EF61C269

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
5463491B4A5EB719724C1F03181EC411

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
A8D65762DB264D5B790028D4ECE066D5

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
84D706D7A34527F07695465EB1755364

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
E72E6EE9DDC855685C1331401EE3E2CE

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
060D751A7FF798DD00AAE63CE6664476

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
ACDE2121DCC5556D8FA69FD102E14D20

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
C174F15F9C2F6D4214F74A26D3108E50

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
1AB32D8C4BC484AA05F677A2C7E95DE6

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
9A6455FDD581C76AD09A05E628B3C3D7

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
14AC73E838CA508220E997A0C303214E

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
936563F2143659636BFE2EDB99D72560

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
1B98FE5440C41FFFD2E848794B0C6E60

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
48FEE1B6A36C5DD1621E27E7FDB5D7C1

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
6E92991B0D1B91BE81642769533653FA

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
77A0A046F0C2B5BAC70F676F11D6A1ED

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
DA6A123DF677AA1061E700E2F232A1D6

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
57B055120139CB95AF199D0A322754B9

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
26639C04B5A8C83570A8BD92ECD74F1E

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
C8B86376095CDD569DD101CF2FA2D196

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
976739163F59336088C747E7846E52FE

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
A9E69FED7C7E48F3D322AD5272341DF5

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
2DEFCBA638B65D330E8ADCC3D8F154C5

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
3CADD814C61E2C745BEFF4CBBAE0010D

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\
3CADD814C61E2C745BEFF4CBBAE0010D\InstallProperties

HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows\CurrentVersion\Uninstall\
{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}

HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows\CurrentVersion\Installer\
UpgradeCodes\59F9B1BAE01B311409E978015D938349

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\
3CADD814C61E2C745BEFF4CBBAE0010D\Usage

HKEY_CURRENT_USER\Software\Microsoft\
Installer\Features\3CADD814C61E2C745BEFF4CBBAE0010D

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\
3CADD814C61E2C745BEFF4CBBAE0010D\Features

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\
3CADD814C61E2C745BEFF4CBBAE0010D\Patches

HKEY_CURRENT_USER\Software\Microsoft\
Installer\Products\3CADD814C61E2C745BEFF4CBBAE0010D

HKEY_CURRENT_USER\Software\Microsoft\
Installer\UpgradeCodes\59F9B1BAE01B311409E978015D938349

HKEY_CURRENT_USER\Software\Microsoft\
Installer\Products\3CADD814C61E2C745BEFF4CBBAE0010D\
SourceList

HKEY_CURRENT_USER\Software\Microsoft\
Installer\Products\3CADD814C61E2C745BEFF4CBBAE0010D\
SourceList\Net

HKEY_CURRENT_USER\Software\Microsoft\
Installer\Products\3CADD814C61E2C745BEFF4CBBAE0010D\
SourceList\Media

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
ESENT\Process\ed2k

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
ESENT\Process\ed2k\
DEBUG

It adds the following registry entries:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
Rollback\Scripts
%System Root%\Config.Msi\12420.rbs = "498788dc"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
F32566D2C1A15D258CD2886A5FE65611
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\pt_PT\amule.mo"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
4B1A85EE0B1113F03A43F3633FC1097E
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\et_EE\amule.mo"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
9A06B67C5B71E0229D9DB3DA9F413DCE
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\el\amule.mo"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
6C84BCCB56C80E904F168AC72BA0CC8F
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\ca\amule.mo"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
44E10F7B65FFBDC6F2C7EC961CC4E6FF
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\skins\Mac_Gray.zip"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
75489DB7067AD2FB6CEB32263D085370
3CADD814C61E2C745BEFF4CBBAE0010D = "%User Profile%\aMule\amule.conf"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
A10F67DDF71B685DA5131EA3147961B7
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\de\amule.mo"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
67418ACCF1E3018F5C1F2737C9536FD5
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\cs\amule.mo"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
66A3A12EC88C6762A5951FC8D056D507
3CADD814C61E2C745BEFF4CBBAE0010D = "%User Profile%\aMule\server.met"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
1EB0D09D105CABCB19CAA60EF650CDF2
3CADD814C61E2C745BEFF4CBBAE0010D = "%User Profile%\aMule\clients.met"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
201BBF441F3AF77DCE7849159F9FC225
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\he\amule.mo"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
3EF64958B490A8A813D6FAA9797F3CBB
3CADD814C61E2C745BEFF4CBBAE0010D = "%User Profile%\aMule\emfriends.met"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
091417CD589D17BFFE41F439404564A2
3CADD814C61E2C745BEFF4CBBAE0010D = "%User Profile%\aMule\logfile"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
D7C740408CE4573BD9AFFBBFFC0DDD78
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\eu\amule.mo"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
33B587F08FFBE3323D7CC3A6E0FDE748
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\it_CH\amule.mo"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
48AFA3CEAA852FD44C1A8D0E9A4E67A2
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\docs\README.txt"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
5DB9B9FDCF29176B4A3E145BD7B90B2F
3CADD814C61E2C745BEFF4CBBAE0010D = "%User Profile%\aMule\lastversion"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
7AB3CF5644132D0B6E3CE72A8BB3D37A
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\it\amule.mo"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
47777C87A7B3477ECA4466B00713FB4D
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\docs\TODO"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
52CF5F71D2CA50F19B0B5B5B94FB083E
3CADD814C61E2C745BEFF4CBBAE0010D = "%User Profile%\aMule\shareddir.dat"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
A4174B2F749380D522F84E050D97B8AC
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\uk\amule.mo"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
16C0F30491F3E7610D9FF0694E9EBD90
3CADD814C61E2C745BEFF4CBBAE0010D = "%User Profile%\aMule\cryptkey.dat"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
BCA4CCCFE1F41DBC7605BC0A93EAD6F0
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\ar\amule.mo"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
50C3E8F161115450BC95D4A867239412
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\amule.ico"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
5A0C62E5E28110ECD79357EC7B28CE06
3CADD814C61E2C745BEFF4CBBAE0010D = "%User Profile%\aMule\known.met"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
A18938C1B189405A26B533F56B311843
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\fr\amule.mo"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
E776B9D4EC304733C04B28C6FC8CFC99
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\skins\gnome.zip"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
F09B0616DD97AD2DE5A717C8BD176E70
3CADD814C61E2C745BEFF4CBBAE0010D = "%User Profile%\aMule\ipfilter_static.dat"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
6BEF29B8BFF602C1B1F1886B0F1EFA28
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\sq\amule.mo"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
79F184906D5FAA2837E31036276D3520
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\hu\amule.mo"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
42CD96D6C2D937962FE7ACC8B63D4E19
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\gl\amule.mo"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
5EE356F4C55B21C26C9E01200E6F3518
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\tr\amule.mo"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
2265783AB350FF6FBF0A6FCB7FFC3EBA
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\skins\priscilla.zip"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
94CE0AF6E5E5EC775388942C15558DFC
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\pt_BR\amule.mo"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
1B56275EDF932276BE64060476D7D110
3CADD814C61E2C745BEFF4CBBAE0010D = "%User Profile%\aMule\ipfilter.dat"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
AF27465CAF64CC1DB5585E950BF1F843
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\skins\xfce.zip"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
3DD38CDF50F9BA8942AB0C19B7BC76C3
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\skins\kde4.zip"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
6A2C63A4EC815D44007110049B8686FD
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\zh_CN\amule.mo"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
9A7393D03D5504AABA95BC63FF69FC90
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\pl\amule.mo"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
819F2BBA6DFF9D152436A978134779FA
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\ko_KR\amule.mo"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
9F3600890788BC092D45407A1FE60E45
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\skins\tango.zip"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
8649C6E61720F5E9611756CD5ADB918C
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\fi\amule.mo"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
EA341A350898696EFF10B853EF61C269
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\zh_TW\amule.mo"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
5463491B4A5EB719724C1F03181EC411
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\docs\amulesig.txt"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
A8D65762DB264D5B790028D4ECE066D5
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\docs\AUTHORS.txt"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
84D706D7A34527F07695465EB1755364
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\docs\Changelog.txt"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
E72E6EE9DDC855685C1331401EE3E2CE
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\hr\amule.mo"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
060D751A7FF798DD00AAE63CE6664476
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\bg\amule.mo"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
ACDE2121DCC5556D8FA69FD102E14D20
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\nn\amule.mo"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
C174F15F9C2F6D4214F74A26D3108E50
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\lt\amule.mo"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
1AB32D8C4BC484AA05F677A2C7E95DE6
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\ed2k.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
9A6455FDD581C76AD09A05E628B3C3D7
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\ru\amule.mo"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
14AC73E838CA508220E997A0C303214E
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\sv\amule.mo"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
936563F2143659636BFE2EDB99D72560
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\da\amule.mo"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
1B98FE5440C41FFFD2E848794B0C6E60
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\es\amule.mo"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
48FEE1B6A36C5DD1621E27E7FDB5D7C1
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\aMule.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
6E92991B0D1B91BE81642769533653FA
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\nl\amule.mo"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
77A0A046F0C2B5BAC70F676F11D6A1ED
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\docs\EC_Protocol.txt"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
DA6A123DF677AA1061E700E2F232A1D6
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\ast\amule.mo"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
57B055120139CB95AF199D0A322754B9
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\ja\amule.mo"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
26639C04B5A8C83570A8BD92ECD74F1E
3CADD814C61E2C745BEFF4CBBAE0010D = "%User Profile%\aMule\known2_64.met"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
C8B86376095CDD569DD101CF2FA2D196
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\docs\license.txt"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
976739163F59336088C747E7846E52FE
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\en_GB\amule.mo"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
A9E69FED7C7E48F3D322AD5272341DF5
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\sl\amule.mo"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
2DEFCBA638B65D330E8ADCC3D8F154C5
3CADD814C61E2C745BEFF4CBBAE0010D = "%User Profile%\aMule\preferences.dat"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\
3CADD814C61E2C745BEFF4CBBAE0010D
3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\
3CADD814C61E2C745BEFF4CBBAE0010D\InstallProperties
LocalPackage = "%Windows%\Installer\12421.msi"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\
3CADD814C61E2C745BEFF4CBBAE0010D\InstallProperties
Contact = "amuleC"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\
3CADD814C61E2C745BEFF4CBBAE0010D\InstallProperties
DisplayVersion = "1.0.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\
3CADD814C61E2C745BEFF4CBBAE0010D\InstallProperties
InstallDate = "20161207"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\
3CADD814C61E2C745BEFF4CBBAE0010D\InstallProperties
InstallSource = "%User Temp%"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\
3CADD814C61E2C745BEFF4CBBAE0010D\InstallProperties
ModifyPath = "MsiExec.exe /I{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\
3CADD814C61E2C745BEFF4CBBAE0010D\InstallProperties
Publisher = "amuleC"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\
3CADD814C61E2C745BEFF4CBBAE0010D\InstallProperties
EstimatedSize = "268"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\
3CADD814C61E2C745BEFF4CBBAE0010D\InstallProperties
UninstallString = "MsiExec.exe /I{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\
3CADD814C61E2C745BEFF4CBBAE0010D\InstallProperties
VersionMajor = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\
3CADD814C61E2C745BEFF4CBBAE0010D\InstallProperties
VersionMinor = "0"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\
3CADD814C61E2C745BEFF4CBBAE0010D\InstallProperties
WindowsInstaller = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\
3CADD814C61E2C745BEFF4CBBAE0010D\InstallProperties
Version = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\
3CADD814C61E2C745BEFF4CBBAE0010D\InstallProperties
Language = "49"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}
Contact = "amuleC"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}
DisplayVersion = "1.0.0"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}
InstallDate = "20161207"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}
InstallSource = "%User Temp%"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}
ModifyPath = "MsiExec.exe /I{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}
Publisher = "amuleC"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}
EstimatedSize = "268"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}
UninstallString = "MsiExec.exe /I{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}
VersionMajor = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}
VersionMinor = "0"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}
WindowsInstaller = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}
Version = "1"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}
Language = "49"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\
3CADD814C61E2C745BEFF4CBBAE0010D\InstallProperties
DisplayName = "amuleC"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Uninstall\
{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}
DisplayName = "amuleC"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\
3CADD814C61E2C745BEFF4CBBAE0010D\Features
DefaultFeature = "{random characters}"

HKEY_CURRENT_USER\Software\Microsoft\
Installer\Products\3CADD814C61E2C745BEFF4CBBAE0010D
ProductName = "amuleC"

HKEY_CURRENT_USER\Software\Microsoft\
Installer\Products\3CADD814C61E2C745BEFF4CBBAE0010D
PackageCode = "5BD7E97D6632D2B4582098357EE39071"

HKEY_CURRENT_USER\Software\Microsoft\
Installer\Products\3CADD814C61E2C745BEFF4CBBAE0010D
Language = "49"

HKEY_CURRENT_USER\Software\Microsoft\
Installer\Products\3CADD814C61E2C745BEFF4CBBAE0010D
Version = "1"

HKEY_CURRENT_USER\Software\Microsoft\
Installer\Products\3CADD814C61E2C745BEFF4CBBAE0010D
Assignment = "0"

HKEY_CURRENT_USER\Software\Microsoft\
Installer\Products\3CADD814C61E2C745BEFF4CBBAE0010D
AdvertiseFlags = "184"

HKEY_CURRENT_USER\Software\Microsoft\
Installer\Products\3CADD814C61E2C745BEFF4CBBAE0010D
InstanceType = "0"

HKEY_CURRENT_USER\Software\Microsoft\
Installer\Products\3CADD814C61E2C745BEFF4CBBAE0010D
AuthorizedLUAApp = "0"

HKEY_CURRENT_USER\Software\Microsoft\
Installer\Products\3CADD814C61E2C745BEFF4CBBAE0010D\
SourceList
PackageName = "am_1.tmp"

HKEY_CURRENT_USER\Software\Microsoft\
Installer\Products\3CADD814C61E2C745BEFF4CBBAE0010D\
SourceList\Net
1 = "%User Temp%"

HKEY_CURRENT_USER\Software\Microsoft\
Installer\Products\3CADD814C61E2C745BEFF4CBBAE0010D\
SourceList\Media
1 = ";"

HKEY_CURRENT_USER\Software\Microsoft\
Installer\Products\3CADD814C61E2C745BEFF4CBBAE0010D\
SourceList
LastUsedSource = "n;1;%User Temp%"

It modifies the following registry entries:

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Services\Eventlog\Application\
ESENT
EventMessageFile = "%System%\ESENT.dll"

(Note: The default value data of the said registry entry is {random values}.)

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Services\Eventlog\Application\
ESENT
CategoryMessageFile = "%System%\ESENT.dll"

(Note: The default value data of the said registry entry is {random values}.)

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Services\Eventlog\Application\
ESENT
CategoryCount = "1"

(Note: The default value data of the said registry entry is 10.)

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\
Services\Eventlog\Application\
ESENT
TypesSupported = "7"

(Note: The default value data of the said registry entry is 7.)

It deletes the following registry keys:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
Rollback\Scripts

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Windows\CurrentVersion\Installer\
Rollback

Dropping Routine

This Trojan drops the following files:

  • %User Temp%\am_1.tmp
  • %Windows%\Installer\1241d.msi
  • %Windows%\Installer\1241f.ipi
  • %Windows%\Installer\MSIB.tmp
  • %System Root%\Config.Msi\12420.rbs
  • %Program Files%\amuleC\locale\pt_PT\amule.mo
  • %Program Files%\amuleC\locale\et_EE\amule.mo
  • %Program Files%\amuleC\locale\el\amule.mo
  • %Program Files%\amuleC\locale\ca\amule.mo
  • %Program Files%\amuleC\skins\Mac_Gray.zip
  • %User Profile%\aMule\amule.conf
  • %Program Files%\amuleC\locale\de\amule.mo
  • %Program Files%\amuleC\locale\cs\amule.mo
  • %User Profile%\aMule\server.met
  • %User Profile%\aMule\clients.met
  • %Program Files%\amuleC\locale\he\amule.mo
  • %User Profile%\aMule\emfriends.met
  • %User Profile%\aMule\logfile
  • %Program Files%\amuleC\locale\eu\amule.mo
  • %Program Files%\amuleC\locale\it_CH\amule.mo
  • %Program Files%\amuleC\docs\README.txt
  • %User Profile%\aMule\lastversion
  • %Program Files%\amuleC\locale\it\amule.mo
  • %Program Files%\amuleC\docs\TODO
  • %User Profile%\aMule\shareddir.dat
  • %Program Files%\amuleC\locale\uk\amule.mo
  • %User Profile%\aMule\cryptkey.dat
  • %Program Files%\amuleC\locale\ar\amule.mo
  • %Program Files%\amuleC\amule.ico
  • %User Profile%\aMule\known.met
  • %Program Files%\amuleC\locale\fr\amule.mo
  • %Program Files%\amuleC\skins\gnome.zip
  • %User Profile%\aMule\ipfilter_static.dat
  • %Program Files%\amuleC\locale\sq\amule.mo
  • %Program Files%\amuleC\locale\hu\amule.mo
  • %Program Files%\amuleC\locale\gl\amule.mo
  • %Program Files%\amuleC\locale\tr\amule.mo
  • %Program Files%\amuleC\skins\priscilla.zip
  • %Program Files%\amuleC\locale\pt_BR\amule.mo
  • %User Profile%\aMule\ipfilter.dat
  • %Program Files%\amuleC\skins\xfce.zip
  • %Program Files%\amuleC\skins\kde4.zip
  • %Program Files%\amuleC\locale\zh_CN\amule.mo
  • %Program Files%\amuleC\locale\pl\amule.mo
  • %Program Files%\amuleC\locale\ko_KR\amule.mo
  • %Program Files%\amuleC\skins\tango.zip
  • %Program Files%\amuleC\locale\fi\amule.mo
  • %Program Files%\amuleC\locale\zh_TW\amule.mo
  • %Program Files%\amuleC\docs\amulesig.txt
  • %Program Files%\amuleC\docs\AUTHORS.txt
  • %Program Files%\amuleC\docs\Changelog.txt
  • %Program Files%\amuleC\locale\hr\amule.mo
  • %Program Files%\amuleC\locale\bg\amule.mo
  • %Program Files%\amuleC\locale\nn\amule.mo
  • %Program Files%\amuleC\locale\lt\amule.mo
  • %Program Files%\amuleC\ed2k.exe
  • %Program Files%\amuleC\locale\ru\amule.mo
  • %Program Files%\amuleC\locale\sv\amule.mo
  • %Program Files%\amuleC\locale\da\amule.mo
  • %Program Files%\amuleC\locale\es\amule.mo
  • %Program Files%\amuleC\aMule.exe
  • %Program Files%\amuleC\locale\nl\amule.mo
  • %Program Files%\amuleC\docs\EC_Protocol.txt
  • %Program Files%\amuleC\locale\ast\amule.mo
  • %Program Files%\amuleC\locale\ja\amule.mo
  • %User Profile%\aMule\known2_64.met
  • %Program Files%\amuleC\docs\license.txt
  • %Program Files%\amuleC\locale\en_GB\amule.mo
  • %Program Files%\amuleC\locale\sl\amule.mo
  • %User Profile%\aMule\preferences.dat
  • %Start Menu%\Programs\amuleC\aMuleC.lnk
  • %Windows%\Installer\12421.msi
  • %User Profile%\{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}\_951C230AB0400AF8D55261.exe

(Note: %User Temp% is the user's temporary folder, where it usually is C:\Documents and Settings\{user name}\Local Settings\Temp on Windows 2000, Windows Server 2003, and Windows XP (32- and 64-bit); C:\Users\{user name}\AppData\Local\Temp on Windows Vista (32- and 64-bit), Windows 7 (32- and 64-bit), Windows 8 (32- and 64-bit), Windows 8.1 (32- and 64-bit), Windows Server 2008, and Windows Server 2012.. %Windows% is the Windows folder, where it usually is C:\Windows on all Windows operating system versions.. %System Root% is the Windows root folder, where it usually is C:\ on all Windows operating system versions.. %Program Files% is the Program Files folder, where it usually is C:\Program Files on all Windows operating system versions; C:\Program Files (x86) for 32-bit applications running on Windows 64-bit operating systems.. %User Profile% is the current user's profile folder, which is usually C:\Documents and Settings\{user name} on Windows 2000, XP, and Server 2003, or C:\Users\{user name} on Windows Vista and 7.. %Start Menu% is the Start Menu folder, where it usually is C:\Documents and Settings\{user name}\Start Menu on Windows 2000, Windows Server 2003, and Windows XP (32- and 64-bit); C:\Users\{user name}\AppData\Roaming\Microsoft\Windows\Start Menu on Windows Vista (32- and 64-bit), Windows 7 (32- and 64-bit), Windows 8 (32- and 64-bit), Windows 8.1 (32- and 64-bit), Windows Server 2008, and Windows Server 2012.)

Other Details

This Trojan connects to the following possibly malicious URL:

  • http://d2xpmajse0mo96.{BLOCKED}ront.net/app/ver/ssl.php?{random characters}
  • http://dmv9o2kt858uv.{BLOCKED}ront.net/v4/service/EEC45E0D47AB8AC7A801C31E41B1D43D?action=cdamule.amule.start
  • {BLOCKED}.141.104
  • {BLOCKED}0.1
  • {BLOCKED}.141.39

This report is generated via an automated analysis system.

  SOLUTION

Minimum Scan Engine: 9.8

Step 1

Before doing any scans, Windows XP, Windows Vista, and Windows 7 users must disable System Restore to allow full scanning of their computers.

Step 2

Delete this registry key

[ Learn More ]

Important: Editing the Windows Registry incorrectly can lead to irreversible system malfunction. Please do this step only if you know how or you can ask assistance from your system administrator. Else, check this Microsoft article first before modifying your computer's registry.

  • In hkey_local_machine\software\microsoft\esent\process
    • {malware file name}
  • In hkey_local_machine\software\microsoft\esent\process\{malware file name}
    • debug
  • In HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer
    • InProgress
  • In HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\Rollback
    • Scripts
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • F32566D2C1A15D258CD2886A5FE65611
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 4B1A85EE0B1113F03A43F3633FC1097E
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 9A06B67C5B71E0229D9DB3DA9F413DCE
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 6C84BCCB56C80E904F168AC72BA0CC8F
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 44E10F7B65FFBDC6F2C7EC961CC4E6FF
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 75489DB7067AD2FB6CEB32263D085370
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • A10F67DDF71B685DA5131EA3147961B7
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 67418ACCF1E3018F5C1F2737C9536FD5
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 66A3A12EC88C6762A5951FC8D056D507
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 1EB0D09D105CABCB19CAA60EF650CDF2
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 201BBF441F3AF77DCE7849159F9FC225
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 3EF64958B490A8A813D6FAA9797F3CBB
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 091417CD589D17BFFE41F439404564A2
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • D7C740408CE4573BD9AFFBBFFC0DDD78
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 33B587F08FFBE3323D7CC3A6E0FDE748
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 48AFA3CEAA852FD44C1A8D0E9A4E67A2
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 5DB9B9FDCF29176B4A3E145BD7B90B2F
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 7AB3CF5644132D0B6E3CE72A8BB3D37A
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 47777C87A7B3477ECA4466B00713FB4D
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 52CF5F71D2CA50F19B0B5B5B94FB083E
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • A4174B2F749380D522F84E050D97B8AC
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 16C0F30491F3E7610D9FF0694E9EBD90
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • BCA4CCCFE1F41DBC7605BC0A93EAD6F0
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 50C3E8F161115450BC95D4A867239412
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 5A0C62E5E28110ECD79357EC7B28CE06
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • A18938C1B189405A26B533F56B311843
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • E776B9D4EC304733C04B28C6FC8CFC99
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • F09B0616DD97AD2DE5A717C8BD176E70
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 6BEF29B8BFF602C1B1F1886B0F1EFA28
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 79F184906D5FAA2837E31036276D3520
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 42CD96D6C2D937962FE7ACC8B63D4E19
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 5EE356F4C55B21C26C9E01200E6F3518
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 2265783AB350FF6FBF0A6FCB7FFC3EBA
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 94CE0AF6E5E5EC775388942C15558DFC
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 1B56275EDF932276BE64060476D7D110
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • AF27465CAF64CC1DB5585E950BF1F843
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 3DD38CDF50F9BA8942AB0C19B7BC76C3
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 6A2C63A4EC815D44007110049B8686FD
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 9A7393D03D5504AABA95BC63FF69FC90
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 819F2BBA6DFF9D152436A978134779FA
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 9F3600890788BC092D45407A1FE60E45
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 8649C6E61720F5E9611756CD5ADB918C
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • EA341A350898696EFF10B853EF61C269
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 5463491B4A5EB719724C1F03181EC411
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • A8D65762DB264D5B790028D4ECE066D5
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 84D706D7A34527F07695465EB1755364
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • E72E6EE9DDC855685C1331401EE3E2CE
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 060D751A7FF798DD00AAE63CE6664476
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • ACDE2121DCC5556D8FA69FD102E14D20
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • C174F15F9C2F6D4214F74A26D3108E50
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 1AB32D8C4BC484AA05F677A2C7E95DE6
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 9A6455FDD581C76AD09A05E628B3C3D7
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 14AC73E838CA508220E997A0C303214E
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 936563F2143659636BFE2EDB99D72560
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 1B98FE5440C41FFFD2E848794B0C6E60
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 48FEE1B6A36C5DD1621E27E7FDB5D7C1
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 6E92991B0D1B91BE81642769533653FA
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 77A0A046F0C2B5BAC70F676F11D6A1ED
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • DA6A123DF677AA1061E700E2F232A1D6
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 57B055120139CB95AF199D0A322754B9
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 26639C04B5A8C83570A8BD92ECD74F1E
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • C8B86376095CDD569DD101CF2FA2D196
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 976739163F59336088C747E7846E52FE
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • A9E69FED7C7E48F3D322AD5272341DF5
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 2DEFCBA638B65D330E8ADCC3D8F154C5
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components
    • 3CADD814C61E2C745BEFF4CBBAE0010D
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\3CADD814C61E2C745BEFF4CBBAE0010D
    • InstallProperties
  • In HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall
    • {418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}
  • In HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes
    • 59F9B1BAE01B311409E978015D938349
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\3CADD814C61E2C745BEFF4CBBAE0010D
    • Usage
  • In HKEY_CURRENT_USER\Software\Microsoft\Installer\Features
    • 3CADD814C61E2C745BEFF4CBBAE0010D
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\3CADD814C61E2C745BEFF4CBBAE0010D
    • Features
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\3CADD814C61E2C745BEFF4CBBAE0010D
    • Patches
  • In HKEY_CURRENT_USER\Software\Microsoft\Installer\Products
    • 3CADD814C61E2C745BEFF4CBBAE0010D
  • In HKEY_CURRENT_USER\Software\Microsoft\Installer\UpgradeCodes
    • 59F9B1BAE01B311409E978015D938349
  • In HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\3CADD814C61E2C745BEFF4CBBAE0010D
    • SourceList
  • In HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\3CADD814C61E2C745BEFF4CBBAE0010D\SourceList
    • Net
  • In HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\3CADD814C61E2C745BEFF4CBBAE0010D\SourceList
    • Media
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ESENT\Process
    • ed2k
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ESENT\Process\ed2k
    • DEBUG

Step 3

Delete this registry value

[ Learn More ]

Important: Editing the Windows Registry incorrectly can lead to irreversible system malfunction. Please do this step only if you know how or you can ask assistance from your system administrator. Else, check this Microsoft article first before modifying your computer's registry.

  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
    • %System Root%\Config.Msi\12420.rbs = "498788dc"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\F32566D2C1A15D258CD2886A5FE65611
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\pt_PT\amule.mo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\4B1A85EE0B1113F03A43F3633FC1097E
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\et_EE\amule.mo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\9A06B67C5B71E0229D9DB3DA9F413DCE
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\el\amule.mo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\6C84BCCB56C80E904F168AC72BA0CC8F
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\ca\amule.mo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\44E10F7B65FFBDC6F2C7EC961CC4E6FF
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\skins\Mac_Gray.zip"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\75489DB7067AD2FB6CEB32263D085370
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%User Profile%\aMule\amule.conf"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\A10F67DDF71B685DA5131EA3147961B7
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\de\amule.mo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\67418ACCF1E3018F5C1F2737C9536FD5
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\cs\amule.mo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\66A3A12EC88C6762A5951FC8D056D507
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%User Profile%\aMule\server.met"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\1EB0D09D105CABCB19CAA60EF650CDF2
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%User Profile%\aMule\clients.met"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\201BBF441F3AF77DCE7849159F9FC225
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\he\amule.mo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\3EF64958B490A8A813D6FAA9797F3CBB
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%User Profile%\aMule\emfriends.met"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\091417CD589D17BFFE41F439404564A2
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%User Profile%\aMule\logfile"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\D7C740408CE4573BD9AFFBBFFC0DDD78
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\eu\amule.mo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\33B587F08FFBE3323D7CC3A6E0FDE748
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\it_CH\amule.mo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\48AFA3CEAA852FD44C1A8D0E9A4E67A2
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\docs\README.txt"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\5DB9B9FDCF29176B4A3E145BD7B90B2F
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%User Profile%\aMule\lastversion"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\7AB3CF5644132D0B6E3CE72A8BB3D37A
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\it\amule.mo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\47777C87A7B3477ECA4466B00713FB4D
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\docs\TODO"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\52CF5F71D2CA50F19B0B5B5B94FB083E
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%User Profile%\aMule\shareddir.dat"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\A4174B2F749380D522F84E050D97B8AC
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\uk\amule.mo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\16C0F30491F3E7610D9FF0694E9EBD90
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%User Profile%\aMule\cryptkey.dat"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\BCA4CCCFE1F41DBC7605BC0A93EAD6F0
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\ar\amule.mo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\50C3E8F161115450BC95D4A867239412
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\amule.ico"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\5A0C62E5E28110ECD79357EC7B28CE06
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%User Profile%\aMule\known.met"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\A18938C1B189405A26B533F56B311843
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\fr\amule.mo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\E776B9D4EC304733C04B28C6FC8CFC99
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\skins\gnome.zip"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\F09B0616DD97AD2DE5A717C8BD176E70
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%User Profile%\aMule\ipfilter_static.dat"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\6BEF29B8BFF602C1B1F1886B0F1EFA28
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\sq\amule.mo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\79F184906D5FAA2837E31036276D3520
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\hu\amule.mo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\42CD96D6C2D937962FE7ACC8B63D4E19
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\gl\amule.mo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\5EE356F4C55B21C26C9E01200E6F3518
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\tr\amule.mo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\2265783AB350FF6FBF0A6FCB7FFC3EBA
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\skins\priscilla.zip"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\94CE0AF6E5E5EC775388942C15558DFC
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\pt_BR\amule.mo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\1B56275EDF932276BE64060476D7D110
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%User Profile%\aMule\ipfilter.dat"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\AF27465CAF64CC1DB5585E950BF1F843
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\skins\xfce.zip"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\3DD38CDF50F9BA8942AB0C19B7BC76C3
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\skins\kde4.zip"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\6A2C63A4EC815D44007110049B8686FD
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\zh_CN\amule.mo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\9A7393D03D5504AABA95BC63FF69FC90
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\pl\amule.mo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\819F2BBA6DFF9D152436A978134779FA
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\ko_KR\amule.mo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\9F3600890788BC092D45407A1FE60E45
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\skins\tango.zip"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\8649C6E61720F5E9611756CD5ADB918C
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\fi\amule.mo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\EA341A350898696EFF10B853EF61C269
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\zh_TW\amule.mo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\5463491B4A5EB719724C1F03181EC411
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\docs\amulesig.txt"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\A8D65762DB264D5B790028D4ECE066D5
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\docs\AUTHORS.txt"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\84D706D7A34527F07695465EB1755364
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\docs\Changelog.txt"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\E72E6EE9DDC855685C1331401EE3E2CE
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\hr\amule.mo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\060D751A7FF798DD00AAE63CE6664476
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\bg\amule.mo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\ACDE2121DCC5556D8FA69FD102E14D20
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\nn\amule.mo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\C174F15F9C2F6D4214F74A26D3108E50
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\lt\amule.mo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\1AB32D8C4BC484AA05F677A2C7E95DE6
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\ed2k.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\9A6455FDD581C76AD09A05E628B3C3D7
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\ru\amule.mo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\14AC73E838CA508220E997A0C303214E
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\sv\amule.mo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\936563F2143659636BFE2EDB99D72560
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\da\amule.mo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\1B98FE5440C41FFFD2E848794B0C6E60
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\es\amule.mo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\48FEE1B6A36C5DD1621E27E7FDB5D7C1
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\aMule.exe"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\6E92991B0D1B91BE81642769533653FA
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\nl\amule.mo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\77A0A046F0C2B5BAC70F676F11D6A1ED
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\docs\EC_Protocol.txt"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\DA6A123DF677AA1061E700E2F232A1D6
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\ast\amule.mo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\57B055120139CB95AF199D0A322754B9
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\ja\amule.mo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\26639C04B5A8C83570A8BD92ECD74F1E
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%User Profile%\aMule\known2_64.met"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\C8B86376095CDD569DD101CF2FA2D196
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\docs\license.txt"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\976739163F59336088C747E7846E52FE
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\en_GB\amule.mo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\A9E69FED7C7E48F3D322AD5272341DF5
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%\amuleC\locale\sl\amule.mo"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\2DEFCBA638B65D330E8ADCC3D8F154C5
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%User Profile%\aMule\preferences.dat"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Components\3CADD814C61E2C745BEFF4CBBAE0010D
    • 3CADD814C61E2C745BEFF4CBBAE0010D = "%Program Files%"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\3CADD814C61E2C745BEFF4CBBAE0010D\InstallProperties
    • LocalPackage = "%Windows%\Installer\12421.msi"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\3CADD814C61E2C745BEFF4CBBAE0010D\InstallProperties
    • Contact = "amuleC"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\3CADD814C61E2C745BEFF4CBBAE0010D\InstallProperties
    • DisplayVersion = "1.0.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\3CADD814C61E2C745BEFF4CBBAE0010D\InstallProperties
    • InstallDate = "20161207"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\3CADD814C61E2C745BEFF4CBBAE0010D\InstallProperties
    • InstallSource = "%User Temp%"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\3CADD814C61E2C745BEFF4CBBAE0010D\InstallProperties
    • ModifyPath = "MsiExec.exe /I{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\3CADD814C61E2C745BEFF4CBBAE0010D\InstallProperties
    • Publisher = "amuleC"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\3CADD814C61E2C745BEFF4CBBAE0010D\InstallProperties
    • EstimatedSize = "268"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\3CADD814C61E2C745BEFF4CBBAE0010D\InstallProperties
    • UninstallString = "MsiExec.exe /I{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\3CADD814C61E2C745BEFF4CBBAE0010D\InstallProperties
    • VersionMajor = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\3CADD814C61E2C745BEFF4CBBAE0010D\InstallProperties
    • VersionMinor = "0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\3CADD814C61E2C745BEFF4CBBAE0010D\InstallProperties
    • WindowsInstaller = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\3CADD814C61E2C745BEFF4CBBAE0010D\InstallProperties
    • Version = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\3CADD814C61E2C745BEFF4CBBAE0010D\InstallProperties
    • Language = "49"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}
    • Contact = "amuleC"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}
    • DisplayVersion = "1.0.0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}
    • InstallDate = "20161207"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}
    • InstallSource = "%User Temp%"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}
    • ModifyPath = "MsiExec.exe /I{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}
    • Publisher = "amuleC"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}
    • EstimatedSize = "268"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}
    • UninstallString = "MsiExec.exe /I{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}
    • VersionMajor = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}
    • VersionMinor = "0"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}
    • WindowsInstaller = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}
    • Version = "1"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}
    • Language = "49"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\3CADD814C61E2C745BEFF4CBBAE0010D\InstallProperties
    • DisplayName = "amuleC"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}
    • DisplayName = "amuleC"
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1645522239-1292428093-682003330-1003\Products\3CADD814C61E2C745BEFF4CBBAE0010D\Features
    • DefaultFeature = "{random characters}"
  • In HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\3CADD814C61E2C745BEFF4CBBAE0010D
    • ProductName = "amuleC"
  • In HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\3CADD814C61E2C745BEFF4CBBAE0010D
    • PackageCode = "5BD7E97D6632D2B4582098357EE39071"
  • In HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\3CADD814C61E2C745BEFF4CBBAE0010D
    • Language = "49"
  • In HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\3CADD814C61E2C745BEFF4CBBAE0010D
    • Version = "1"
  • In HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\3CADD814C61E2C745BEFF4CBBAE0010D
    • Assignment = "0"
  • In HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\3CADD814C61E2C745BEFF4CBBAE0010D
    • AdvertiseFlags = "184"
  • In HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\3CADD814C61E2C745BEFF4CBBAE0010D
    • InstanceType = "0"
  • In HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\3CADD814C61E2C745BEFF4CBBAE0010D
    • AuthorizedLUAApp = "0"
  • In HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\3CADD814C61E2C745BEFF4CBBAE0010D\SourceList
    • PackageName = "am_1.tmp"
  • In HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\3CADD814C61E2C745BEFF4CBBAE0010D\SourceList\Net
    • 1 = "%User Temp%"
  • In HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\3CADD814C61E2C745BEFF4CBBAE0010D\SourceList\Media
    • 1 = ";"
  • In HKEY_CURRENT_USER\Software\Microsoft\Installer\Products\3CADD814C61E2C745BEFF4CBBAE0010D\SourceList
    • LastUsedSource = "n;1;%User Temp%"

Step 4

Restore these modified registry values

[ Learn More ]

Important:Editing the Windows Registry incorrectly can lead to irreversible system malfunction. Please do this only if you know how to or you can seek your system administrator's help. You may also check out this Microsoft article first before modifying your computer's registry.

  • In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Application\ESENT
    • From: EventMessageFile = "%System%\ESENT.dll"
      To: EventMessageFile = ""{random values}""
  • In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Application\ESENT
    • From: CategoryMessageFile = "%System%\ESENT.dll"
      To: CategoryMessageFile = ""{random values}""
  • In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Application\ESENT
    • From: CategoryCount = "1"
      To: CategoryCount = ""10""
  • In HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Eventlog\Application\ESENT
    • From: TypesSupported = "7"
      To: TypesSupported = ""7""

Step 5

Search and delete these components

[ Learn More ]
There may be some components that are hidden. Please make sure you check the Search Hidden Files and Folders checkbox in the "More advanced options" option to include all hidden files and folders in the search result.
  • %User Temp%\am_1.tmp
  • %Windows%\Installer\1241d.msi
  • %Windows%\Installer\1241f.ipi
  • %Windows%\Installer\MSIB.tmp
  • %System Root%\Config.Msi\12420.rbs
  • %Program Files%\amuleC\locale\pt_PT\amule.mo
  • %Program Files%\amuleC\locale\et_EE\amule.mo
  • %Program Files%\amuleC\locale\el\amule.mo
  • %Program Files%\amuleC\locale\ca\amule.mo
  • %Program Files%\amuleC\skins\Mac_Gray.zip
  • %User Profile%\aMule\amule.conf
  • %Program Files%\amuleC\locale\de\amule.mo
  • %Program Files%\amuleC\locale\cs\amule.mo
  • %User Profile%\aMule\server.met
  • %User Profile%\aMule\clients.met
  • %Program Files%\amuleC\locale\he\amule.mo
  • %User Profile%\aMule\emfriends.met
  • %User Profile%\aMule\logfile
  • %Program Files%\amuleC\locale\eu\amule.mo
  • %Program Files%\amuleC\locale\it_CH\amule.mo
  • %Program Files%\amuleC\docs\README.txt
  • %User Profile%\aMule\lastversion
  • %Program Files%\amuleC\locale\it\amule.mo
  • %Program Files%\amuleC\docs\TODO
  • %User Profile%\aMule\shareddir.dat
  • %Program Files%\amuleC\locale\uk\amule.mo
  • %User Profile%\aMule\cryptkey.dat
  • %Program Files%\amuleC\locale\ar\amule.mo
  • %Program Files%\amuleC\amule.ico
  • %User Profile%\aMule\known.met
  • %Program Files%\amuleC\locale\fr\amule.mo
  • %Program Files%\amuleC\skins\gnome.zip
  • %User Profile%\aMule\ipfilter_static.dat
  • %Program Files%\amuleC\locale\sq\amule.mo
  • %Program Files%\amuleC\locale\hu\amule.mo
  • %Program Files%\amuleC\locale\gl\amule.mo
  • %Program Files%\amuleC\locale\tr\amule.mo
  • %Program Files%\amuleC\skins\priscilla.zip
  • %Program Files%\amuleC\locale\pt_BR\amule.mo
  • %User Profile%\aMule\ipfilter.dat
  • %Program Files%\amuleC\skins\xfce.zip
  • %Program Files%\amuleC\skins\kde4.zip
  • %Program Files%\amuleC\locale\zh_CN\amule.mo
  • %Program Files%\amuleC\locale\pl\amule.mo
  • %Program Files%\amuleC\locale\ko_KR\amule.mo
  • %Program Files%\amuleC\skins\tango.zip
  • %Program Files%\amuleC\locale\fi\amule.mo
  • %Program Files%\amuleC\locale\zh_TW\amule.mo
  • %Program Files%\amuleC\docs\amulesig.txt
  • %Program Files%\amuleC\docs\AUTHORS.txt
  • %Program Files%\amuleC\docs\Changelog.txt
  • %Program Files%\amuleC\locale\hr\amule.mo
  • %Program Files%\amuleC\locale\bg\amule.mo
  • %Program Files%\amuleC\locale\nn\amule.mo
  • %Program Files%\amuleC\locale\lt\amule.mo
  • %Program Files%\amuleC\ed2k.exe
  • %Program Files%\amuleC\locale\ru\amule.mo
  • %Program Files%\amuleC\locale\sv\amule.mo
  • %Program Files%\amuleC\locale\da\amule.mo
  • %Program Files%\amuleC\locale\es\amule.mo
  • %Program Files%\amuleC\aMule.exe
  • %Program Files%\amuleC\locale\nl\amule.mo
  • %Program Files%\amuleC\docs\EC_Protocol.txt
  • %Program Files%\amuleC\locale\ast\amule.mo
  • %Program Files%\amuleC\locale\ja\amule.mo
  • %User Profile%\aMule\known2_64.met
  • %Program Files%\amuleC\docs\license.txt
  • %Program Files%\amuleC\locale\en_GB\amule.mo
  • %Program Files%\amuleC\locale\sl\amule.mo
  • %User Profile%\aMule\preferences.dat
  • %Start Menu%\Programs\amuleC\aMuleC.lnk
  • %Windows%\Installer\12421.msi
  • %User Profile%\{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}\_951C230AB0400AF8D55261.exe

Step 6

Search and delete these folders

[ Learn More ]
Please make sure you check the Search Hidden Files and Folders checkbox in the More advanced options option to include all hidden folders in the search result.
  • %System Root%\MSI1241e.tmp
  • %System Root%\Config.Msi
  • %Program Files%\amuleC
  • %Program Files%\amuleC\locale
  • %Program Files%\amuleC\locale\pt_PT
  • %Program Files%\amuleC\locale\et_EE
  • %Program Files%\amuleC\locale\el
  • %Program Files%\amuleC\locale\ca
  • %Program Files%\amuleC\skins
  • %User Profile%\Application Data\aMule
  • %Program Files%\amuleC\locale\de
  • %Program Files%\amuleC\locale\cs
  • %Program Files%\amuleC\locale\he
  • %Program Files%\amuleC\locale\eu
  • %Program Files%\amuleC\locale\it_CH
  • %Program Files%\amuleC\docs
  • %Program Files%\amuleC\locale\it
  • %Program Files%\amuleC\locale\uk
  • %Program Files%\amuleC\locale\ar
  • %Program Files%\amuleC\locale\fr
  • %Program Files%\amuleC\locale\sq
  • %Program Files%\amuleC\locale\hu
  • %Program Files%\amuleC\locale\gl
  • %Program Files%\amuleC\locale\tr
  • %Program Files%\amuleC\locale\pt_BR
  • %Program Files%\amuleC\locale\zh_CN
  • %Program Files%\amuleC\locale\pl
  • %Program Files%\amuleC\locale\ko_KR
  • %Program Files%\amuleC\locale\fi
  • %Program Files%\amuleC\locale\zh_TW
  • %Program Files%\amuleC\locale\hr
  • %Program Files%\amuleC\locale\bg
  • %Program Files%\amuleC\locale\nn
  • %Program Files%\amuleC\locale\lt
  • %Program Files%\amuleC\locale\ru
  • %Program Files%\amuleC\locale\sv
  • %Program Files%\amuleC\locale\da
  • %Program Files%\amuleC\locale\es
  • %Program Files%\amuleC\locale\nl
  • %Program Files%\amuleC\locale\ast
  • %Program Files%\amuleC\locale\ja
  • %Program Files%\amuleC\locale\en_GB
  • %Program Files%\amuleC\locale\sl
  • %Start Menu%\Programs\amuleC
  • %User Profile%\Microsoft\Installer
  • %User Profile%\Installer\{418DDAC3-E16C-47C2-B5FE-4FBCAB0E10D0}

Step 7

Scan your computer with your Trend Micro product to delete files detected as PUA_Sasquor. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check this Knowledge Base page for more information.

Step 8

Restore this file from backup only Microsoft-related files will be restored. If this malware/grayware also deleted files related to programs that are not from Microsoft, please reinstall those programs on you computer again.

  • %System Root%\Config.Msi\MSIF.tmp
  • %System Root%\Config.Msi\MSI85.tmp
  • CWS_H15_VC07

Step 9

Restore these deleted registry keys/values from backup

*Note: Only Microsoft-related keys/values will be restored. If the malware/grayware also deleted registry keys/values related to programs that are not from Microsoft, please reinstall those programs on your computer.

  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback
    • Scripts
  • In HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer
    • Rollback


Did this description help? Tell us how we did.