PSWTool.Ophcrack
* registry path
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\ophcrack.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ophcrack
* files path
C\Users\Public\Desktop\ophcrack.lnk
C\ProgramData\Microsoft\Windows\Start Menu\Programs\ophcrack\Website.lnk
C\ProgramData\Microsoft\Windows\Start Menu\Programs\ophcrack\Uninstall.lnk
C\ProgramData\Microsoft\Windows\Start Menu\Programs\ophcrack\ophcrack.lnk
C\Program Files\ophcrack\pwdump\servpw64.exe
C\Program Files\ophcrack\pwdump\servpw.exe
C\Program Files\ophcrack\pwdump\pwdump6_setup.exe
C\Program Files\ophcrack\pwdump\lsremora64.dll
C\Program Files\ophcrack\pwdump\lsremora.dll
C\Program Files\ophcrack\uninst.exe
C\Program Files\ophcrack\ophcrack_nogui.exe
C\Program Files\ophcrack\ophcrack.url
C\Program Files\ophcrack\ophcrack.exe
|
|