Trojan.Win32.Swrort.3_e7a115b2da

by malwarelabrobot on November 22nd, 2014 in Malware Descriptions.

Trojan.Win32.Swrort.3.FD, mzpefinder_pcap_file.YR (Lavasoft MAS)
Behaviour: Trojan


The description has been automatically generated by Lavasoft Malware Analysis System and it may contain incomplete or inaccurate information.

Requires JavaScript enabled!

Summary
Dynamic Analysis
Static Analysis
Network Activity
Map
Strings from Dumps
Removals

MD5: e7a115b2da64acb140784f546a1b3463
SHA1: 6697a633a68d44291c1bc49da835d11aa7e08f02
SHA256: f3b08393d2d0ff0ddfeb586fa130171d19463924826f2806ba15a18c58c414ce
SSDeep: 98304:0My 4pkpCHvYUga1c9ztGzj2j/oVAYC4FfslVMGiqJWUmw3pF:0MyUQvYUga1c9gjbViSWVsxwX
Size: 5822848 bytes
File type: EXE
Platform: WIN32
Entropy: Packed
PEID: BorlandDelphi30, UPolyXv05_v6
Company: SnapMyScreen
Created at: 2014-07-01 20:38:05
Analyzed on: WindowsXP SP3 32-bit


Summary:

Trojan. A program that appears to do one thing but actually does another (a.k.a. Trojan Horse).

Payload

No specific payload has been found.

Process activity

The Trojan creates the following process(es):

bfHighIn.exe:232
TPIManagerConsole.exe:1900
WPFFontCache_v0400.exe:2252
%original file name%.exe:1736
ngen.exe:2108
irsetup.exe:1228
{3A8C3261-820F-4F0A-9C97-37B8F33D8519}.exe:208
000006c8T8SETUP.EXE:1932
bfbarsvc.exe:572
bfbarsvc.exe:1760
bfbarsvc.exe:1356

The Trojan injects its code into the following process(es):

SnapMyScreen.exe:2152
mscorsvw.exe:2116
AppIntegrator.exe:1944

Mutexes

The following mutexes were created/opened:
No objects were found.

File activity

The process TPIManagerConsole.exe:1900 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\81UFS96V\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\C3E814D1CB223AFCD58214D14C3B7EAB (341 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\8DFDF057024880D7A081AFBF6D26B92F (176 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\R4W6XPZO\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\8BD11C4A2318EC8E5A82462092971DEA (208 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\C3E814D1CB223AFCD58214D14C3B7EAB (220 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\75Q3FU31\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\5EH3CC9L\desktop.ini (67 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\8BD11C4A2318EC8E5A82462092971DEA (477 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\62B5AF9BE9ADC1085C3C56EC07A82BF6 (224 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\8DFDF057024880D7A081AFBF6D26B92F (533 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\{3A8C3261-820F-4F0A-9C97-37B8F33D8519}.exe (558702 bytes)
%Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\62B5AF9BE9ADC1085C3C56EC07A82BF6 (140 bytes)

The Trojan deletes the following file(s):

%Program Files%\SnapMyScreen_bf\bar\1.bin\{3A8C3261-820F-4F0A-9C97-37B8F33D8519}.exe (0 bytes)

The process %original file name%.exe:1736 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\000006c8T8SETUP.EX_ (39950 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\000006c8T8SETUP.EXE (187442 bytes)

The Trojan deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\000006c8T8SETUP.EX_ (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\000006c8T8SETUP.EXE (0 bytes)

The process ngen.exe:2108 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%WinDir%\Microsoft.NET\Framework\v4.0.30319\ngen.log (1398 bytes)

The process SnapMyScreen.exe:2152 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%System%\d3d9caps.tmp (2648 bytes)

The Trojan deletes the following file(s):

%System%\d3d9caps.dat (0 bytes)

The process irsetup.exe:1228 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Program Files%\Mindspark\SnapMyScreen\System.Windows.Interactivity.dll (46 bytes)
%Program Files%\Mindspark\SnapMyScreen\Microsoft.Expression.Interactions.dll (1137 bytes)
%Program Files%\Mindspark\SnapMyScreen\uninstall.exe (9213 bytes)
%Program Files%\Mindspark\SnapMyScreen\Uninstall\uninstall.dat (2712 bytes)
%Program Files%\Mindspark\SnapMyScreen\RebootRequired.exe (1137 bytes)
%Program Files%\Mindspark\SnapMyScreen\UnifiedLogging.dll (1137 bytes)
%Program Files%\Mindspark\SnapMyScreen\lua5.1.dll (2902 bytes)
%Program Files%\Mindspark\SnapMyScreen\Uninstall\uni1.tmp (12365 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\_ir_sf_temp_0\irsetup.dat (1209 bytes)
%Documents and Settings%\%current user%\Desktop\SnapMyScreen.lnk (1 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\_ir_sf_temp_0\IRIMG1.PNG (6 bytes)
%Program Files%\Mindspark\SnapMyScreen\Uninstall\IRIMG1.PNG (6 bytes)
%Documents and Settings%\%current user%\Start Menu\Programs\SnapMyScreen\SnapMyScreen.lnk (1 bytes)
%Program Files%\Mindspark\SnapMyScreen\Uninstall\uninstall.xml (1219 bytes)
%Program Files%\Mindspark\SnapMyScreen\DesktopSdk.dll (4695 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\SnapMyScreen Setup Log.txt (4801 bytes)
%Program Files%\Mindspark\SnapMyScreen\SnapMyScreen.exe (4920 bytes)
%Program Files%\Mindspark\SnapMyScreen\SnapMyScreen.exe.config (193 bytes)

The Trojan deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\_ir_sf_temp_0\IRIMG1.PNG (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\_ir_sf_temp_0 (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\IRW2.tmp (0 bytes)
%Program Files%\Mindspark\SnapMyScreen\Uninstall\uni1.tmp (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\_ir_sf_temp_0\irsetup.dat (0 bytes)

The process {3A8C3261-820F-4F0A-9C97-37B8F33D8519}.exe:208 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\_ir_sf_temp_0\lua5.1.dll (325 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\_ir_sf_temp_0\irsetup.exe (7386 bytes)

The Trojan deletes the following file(s):

%Documents and Settings%\%current user%\Local Settings\Temp\_ir_sf_temp_0 (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\_ir_sf_temp_0\lua5.1.dll (0 bytes)
%Documents and Settings%\%current user%\Local Settings\Temp\_ir_sf_temp_0\irsetup.exe (0 bytes)

The process mscorsvw.exe:2116 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%WinDir%\Microsoft.NET\Framework\v4.0.30319\ngen_service.log (514 bytes)

The process 000006c8T8SETUP.EXE:1932 makes changes in the file system.
The Trojan creates and/or writes to the following file(s):

%Program Files%\SnapMyScreen_bf\bar\1.bin\assists\ie_default_search_provider\ARBITER.DLL (15 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\ASSISTMONITOR.DLL (225 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\VERIFY.DLL (70 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\TOOLBARGUARD.DLL (240 bytes)
%Documents and Settings%\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat (20 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\bfhighin.exe (13 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\bftpinst.dll (179 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\TOOLBARGUARD64.DLL (251 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\bfdatact.dll (171 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\bfbar.dll (5442 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\Hpg64.dll (220 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\DPNMNGR.DLL (217 bytes)
%Documents and Settings%\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat (20 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\AppIntegrator64.exe (264 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\bfregiet.dll (87 bytes)
%Documents and Settings%\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG (1560 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\assists\ie_enable\ARBITER64.DLL (12 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\installKeys.js (207 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\CREXT.DLL (6422 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\TPIMANAGERCONSOLE.EXE (78 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\bfPlugin.dll (83 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\bfskplay.exe (55 bytes)
%System%\config\SOFTWARE.LOG (38577 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\T8EXTPEX.DLL (108 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\bfdlghk.dll (121 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\bfmlbtn.dll (98 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\assists\ie_default_search_provider\ARBITER64.DLL (17 bytes)
%Program Files%\SnapMyScreen_bf\bar\Message\COMMON.T8S (100 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\LOGO.BMP (10 bytes)
%Program Files%\SnapMyScreen_bf\bar\assists\COMMON.T8S (138 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\HKFXMGR.DLL (1628 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\bfbarsvc.exe (90 bytes)
%Program Files%\SnapMyScreen_bf\bar\gen1\COMMON.T8S (1 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\T8EPMSUP.DLL (79 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\bfhtmlmu.dll (214 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\bfscript.dll (104 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\bfSrcAs.dll (144 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\bffeedmg.dll (145 bytes)
%Program Files%\SnapMyScreen_bf\bar\Settings\s_pid.dat (8 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\BOOTSTRAP.JS (20 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\APPINTEGRATOR.EXE (229 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\T8EXTEX.DLL (102 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\assists\ie_enable\CONFIG.XML (6 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\ASSISTMONITOR64.DLL (246 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\bfbprtct.dll (121 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\bfmedint.exe (12 bytes)
%Documents and Settings%\%current user%\NTUSER.DAT.LOG (6408 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\APPINTEGRATORSTUB.DLL (197 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat (1564 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\assists\ie_default_search_provider\ASSIST.EXE (207 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\assists\ie_enable\ARBITER.DLL (12 bytes)
%System%\config (200 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\bfskin.dll (212 bytes)
%System%\config\system (2812 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\AppIntegratorStub64.dll (213 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\chrome\bfffxtbr.jar (1829 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\INSTALL.RDF (2 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\bfregfft.dll (85 bytes)
%System%\config\SYSTEM.LOG (4793 bytes)
%System%\config\software (34460 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\bfhttpct.dll (151 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\CHROME.MANIFEST (1 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\T8TICKER.DLL (171 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\assists\ie_default_search_provider\CONFIG.XML (3 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\bfidle.dll (62 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\FF-NativeMessagingDispatcher.dll (1767 bytes)
%Documents and Settings%\%current user%\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG (1896 bytes)
%Documents and Settings%\%current user%\NTUSER.DAT (3544 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\HKFXMGR64.DLL (1729 bytes)
%Documents and Settings%\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG (1560 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\T8RES.DLL (198 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\bfhkstub.dll (59 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\bfreghk.dll (80 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\T8HTML.DLL (202 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\HPG.DLL (237 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\bfdlghk64.dll (147 bytes)
%Program Files%\SnapMyScreen_bf\bar\1.bin\CrExtPbf.exe (5442 bytes)

Registry activity

The process bfHighIn.exe:232 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "0C 43 ED 2E F5 7C 0D A8 00 F4 47 B0 C9 43 00 48"

The process TPIManagerConsole.exe:1900 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\SnapMyScreen_bf\Dependencies\SnapMyScreen]
"UninstallString" = "${reg[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion:ProgramFilesDir]}\Mindspark\SnapMyScreen\uninstall.exe /U:${reg[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion:ProgramFilesDir]}\Mindspark\SnapMyScreen\Uninstall\uninstall.xml"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"

[HKLM\SOFTWARE\SnapMyScreen_bf\Dependencies\SnapMyScreen]
"uninstall" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

[HKLM\SOFTWARE\SnapMyScreen_bf\Dependencies\SnapMyScreen]
"is64bit" = "0"

[HKLM\SOFTWARE\SnapMyScreen_bf\Dependencies]
"dependencymanagerpath" = "%Program Files%\SnapMyScreen_bf\bar\1.bin\DPNMNGR.DLL"

[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1A 00 00 00 01 00 00 00 00 00 00 00"

[HKLM\SOFTWARE\SnapMyScreen_bf\Dependencies\SnapMyScreen]
"FriendlyName" = "SnapMyScreen"

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "A9 C3 82 99 AF 91 3F 72 71 99 2D 0A C0 46 17 B4"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"

The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"

The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

"ProxyBypass" = "1"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"

The Trojan deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"

The process WPFFontCache_v0400.exe:2252 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "78 E2 A1 D9 FD DF D4 DD B9 B1 6A EC 7C 1C 2E 60"

[HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Local AppData" = "%Documents and Settings%\LocalService\Local Settings\Application Data"

The process %original file name%.exe:1736 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "F9 77 F3 EE 6B C8 E2 1B B0 C4 3F 86 A8 40 22 E7"

[HKLM\SOFTWARE\SnapMyScreen_bf\bar\Switches]
"nodns" = "0"
"ffTabs" = "0"

[HKCU\Software\SnapMyScreen_bf\Events\EventData]
"00000000_6" = "01 00 00 00 E4 DD 6E 54 00 00 00 00 00 00 00 00"
"00000000_7" = "01 00 00 00 E4 DD 6E 54 00 00 00 00 00 00 00 00"

[HKLM\SOFTWARE\SnapMyScreen_bf\bar]
"OToIData" = "001"

[HKCU\Software\SnapMyScreen_bf\Events\EventData]
"00000000_5" = "01 00 00 00 E4 DD 6E 54 00 00 00 00 00 00 00 00"

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\SnapMyScreen_bf\bar]
"OToIData"

The process ngen.exe:2108 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "04 2F 5B C1 14 C4 78 FF E9 0B 69 25 72 92 79 E8"

[HKLM\SOFTWARE\Microsoft\.NETFramework\v2.0.50727\NGenService\Roots\C:/Program Files/Mindspark/SnapMyScreen/SnapMyScreen.exe\0]
"Status" = "2"

[HKLM\SOFTWARE\Microsoft\.NETFramework\v2.0.50727\NGenService\Roots\C:/Program Files/Mindspark/SnapMyScreen/SnapMyScreen.exe]
"Status" = "3"

[HKLM\SOFTWARE\Microsoft\.NETFramework\v2.0.50727\NGenService\Roots]
"WorkPending" = "1"

[HKLM\SOFTWARE\Microsoft\.NETFramework\v2.0.50727\NGenService\ListenedState]
"RootstoreDirty" = "1"

[HKLM\SOFTWARE\Microsoft\.NETFramework\v2.0.50727\NGenService\Roots\C:/Program Files/Mindspark/SnapMyScreen/SnapMyScreen.exe\0]
"Scenario" = "0"

The process SnapMyScreen.exe:2152 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "BB BB 35 D2 67 24 48 91 69 E2 66 A1 22 B4 00 44"

[HKLM\System\CurrentControlSet\Hardware Profiles\0001\System\CurrentControlSet\Control\VIDEO\{93BE68F4-CC3D-47B9-A3E0-1521247A9D19}\0000]
"Attach.ToDesktop" = "1"

[HKCU\Software\Microsoft\Direct3D\MostRecentApplication]
"Name" = "SnapMyScreen.exe"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"

The process irsetup.exe:1228 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mindspark SnapMyScreen]
"DisplayIcon" = "%Program Files%\Mindspark\SnapMyScreen\SnapMyScreen.exe,0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"My Video" = ""

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Directory" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CacheLimit" = "65452"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Fonts" = "%WinDir%\Fonts"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections]
"SavedLegacySettings" = "3C 00 00 00 1B 00 00 00 01 00 00 00 00 00 00 00"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mindspark SnapMyScreen]
"URLInfoAbout" = "http://www.mindspark.com"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Start Menu" = "%Documents and Settings%\All Users\Start Menu"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mindspark SnapMyScreen]
"InstallLocation" = "%Program Files%\Mindspark\SnapMyScreen"

[HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mindspark SnapMyScreen]
"Contact" = "Mindspark Interactive Network Support Department"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"
"Startup" = "%Documents and Settings%\%current user%\Start Menu\Programs\Startup"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache2"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mindspark SnapMyScreen]
"DisplayVersion" = "1.0.7907.151"
"UninstallString" = "%Program Files%\Mindspark\SnapMyScreen\uninstall.exe /U:%Program Files%\Mindspark\SnapMyScreen\Uninstall\uninstall.xml"
"NoModify" = "1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common AppData" = "%Documents and Settings%\All Users\Application Data"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mindspark SnapMyScreen]
"Publisher" = "Mindspark Interactive Network"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"My Pictures" = "%Documents and Settings%\%current user%\My Documents\My Pictures"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CacheLimit" = "65452"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"
"Common Startup" = "%Documents and Settings%\All Users\Start Menu\Programs\Startup"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mindspark SnapMyScreen]
"DisplayName" = "SnapMyScreen"
"HelpLink" = "http://www.mindspark.com"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"
"CommonMusic" = "%Documents and Settings%\All Users\Documents\My Music"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CacheLimit" = "65452"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path4]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache4"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Start Menu" = "%Documents and Settings%\%current user%\Start Menu"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path2]
"CacheLimit" = "65452"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"My Music" = "%Documents and Settings%\%current user%\My Documents\My Music"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"CommonVideo" = "%Documents and Settings%\All Users\Documents\My Videos"
"CommonPictures" = "%Documents and Settings%\All Users\Documents\My Pictures"

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "B2 B4 B4 16 48 EF A0 EA D5 48 BB DE BB 4C D3 BB"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Programs" = "%Documents and Settings%\All Users\Start Menu\Programs"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path1]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"MigrateProxy" = "1"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Programs" = "%Documents and Settings%\%current user%\Start Menu\Programs"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths\path3]
"CachePath" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\Cache3"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Cache\Paths]
"Paths" = "4"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"History" = "%Documents and Settings%\%current user%\Local Settings\History"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Mindspark SnapMyScreen]
"NoRepair" = "1"

The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"

Proxy settings are disabled:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyEnable" = "0"

The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"

The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

"ProxyBypass" = "1"

To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SnapMyScreen" = "%Program Files%\Mindspark\SnapMyScreen\SnapMyScreen.exe /hidden"

The Trojan deletes the following value(s) in system registry:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"
"ProxyServer"
"ProxyOverride"

The process {3A8C3261-820F-4F0A-9C97-37B8F33D8519}.exe:208 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "C2 26 81 B2 9F 95 49 E5 09 BA 49 ED A2 A9 AF C9"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\DOCUME~1\"%CurrentUserName%"\LOCALS~1\Temp\_ir_sf_temp_0]
"irsetup.exe" = "Setup Application"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"

The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"IntranetName" = "1"

The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

"UNCAsIntranet" = "1"

The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

"ProxyBypass" = "1"

The process mscorsvw.exe:2116 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "18 53 EC 86 99 DB 73 B8 65 F8 C4 82 0F 95 B6 AE"

[HKLM\SOFTWARE\Microsoft\.NETFramework\v2.0.50727\NGenService\ListenedState]
"RootstoreDirty" = "0"

[HKLM\SOFTWARE\Microsoft\.NETFramework\v2.0.50727\NGenService\State]
"AccumulatedWaitIdleTime" = "0"

The process AppIntegrator.exe:1944 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "BE 02 76 82 BE FA 0A 7B 53 6E 57 2B AB 4C 32 A8"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Local AppData" = "%Documents and Settings%\%current user%\Local Settings\Application Data"

The process 000006c8T8SETUP.EXE:1932 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6c7b31f7-a830-4c86-a7a1-b2e1b1253547}]
"(Default)" = ""

[HKCR\Interface\{B9C39A03-DBC3-4158-BB1B-3ED9F1C98129}]
"(Default)" = "IHttpControl"

[HKLM\SOFTWARE\SnapMyScreen_bf\bar\Switches]
"ua" = "0"

[HKCR\CLSID\{c4d86c62-bcee-4886-9fb9-34b1db677726}\InprocServer32]
"(Default)" = "%Program Files%\SnapMyScreen_bf\bar\1.bin\bfbprtct.dll"

[HKCR\CLSID\{f3b5e712-c267-49e0-8dfd-5b182ff08d90}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Interface\{1A327208-15F5-4C84-BB37-AEFDB2E5B049}]
"(Default)" = "BARFEED_INTERFACE"

[HKCR\Interface\{2F64F67F-3ADE-49FE-95D1-511667B1679A}\ProxyStubClsid]
"(Default)" = "{00020420-0000-0000-C000-000000000046}"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd75-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKLM\SOFTWARE\SnapMyScreen_bf\bar]
"dir" = "%Program Files%\SnapMyScreen_bf\bar\"

[HKCR\Interface\{D61A691F-FCC2-4B11-9D2B-FDBDE39BE8CF}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\CLSID\{bdffe389-a538-42f1-b36b-cbfb78e2d7fc}\InprocServer32]
"(Default)" = "%Program Files%\SnapMyScreen_bf\bar\1.bin\bfscript.dll"

[HKCR\CLSID\{f3b5e712-c267-49e0-8dfd-5b182ff08d90}\ProgID]
"(Default)" = "SnapMyScreen_bf.SettingsPlugin.1"

[HKCR\Interface\{E18CB616-56DD-4C51-9C3A-71D637DEA5BE}]
"(Default)" = "_IDataCtrlEvents"

[HKLM\SOFTWARE\SnapMyScreen_bf\bar]
"pl" = "9"

[HKLM\SOFTWARE\SnapMyScreen_bf\bar\Switches]
"bfSrcAs.dll" = "0"

[HKCR\Interface\{88521B9F-6F51-479B-990D-04FFC83453C0}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Desktop" = "%Documents and Settings%\%current user%\Desktop"

[HKCR\Interface\{64DEC467-9869-4695-BF50-4F5B76A0F10E}\TypeLib]
"(Default)" = "{DD50941D-708B-4434-ABA0-FDC9578513CF}"

[HKCR\Interface\{7E5AE580-3435-4D29-B7F3-2957102DBF65}]
"(Default)" = "ITemplatePopupMenu"

[HKCR\Interface\{755052BA-D5FD-4152-AB3E-DB447A9D9EC8}\TypeLib]
"(Default)" = "{AA398903-C818-4EEA-92D4-44AE17838787}"

[HKCR\Interface\{5E1904ED-A147-490E-A643-21A084E45B1C}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\CLSID\{6c7b31f7-a830-4c86-a7a1-b2e1b1253547}\Version]
"(Default)" = "1.0"

[HKCR\CLSID\{9646c642-4bbc-49b9-b332-f1073541e3e1}\TypeLib]
"(Default)" = "{e41a6f86-420f-45e2-9237-6aaa2c72380b}"

[HKCR\Interface\{2F64F67F-3ADE-49FE-95D1-511667B1679A}\TypeLib]
"(Default)" = "{D675A3DA-42CF-4D3D-A6C4-51688AF2C0E3}"

[HKCR\Interface\{2F64F67F-3ADE-49FE-95D1-511667B1679A}\ProxyStubClsid32]
"(Default)" = "{00020420-0000-0000-C000-000000000046}"

[HKCR\TypeLib\{D675A3DA-42CF-4D3D-A6C4-51688AF2C0E3}\1.0\FLAGS]
"(Default)" = "0"

[HKCR\Interface\{ED5C7EBB-E72B-4333-A546-F4944D982C58}]
"(Default)" = "ITemplateHTMLMenu"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Documents" = "%Documents and Settings%\All Users\Documents"

[HKCR\Interface\{86B37BFC-233A-4D67-B3BA-60559DEBAF57}\TypeLib]
"Version" = "1.0"

[HKCR\TypeLib\{D675A3DA-42CF-4D3D-A6C4-51688AF2C0E3}\1.0\HELPDIR]
"(Default)" = "%Program Files%\SnapMyScreen_bf\bar\1.bin"

[HKCR\TypeLib\{EFA0DFB6-66E5-4081-B607-BF6542818156}\1.0]
"(Default)" = "BARFEEDTYPELIB_NAME"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Personal" = "%Documents and Settings%\%current user%\My Documents"

[HKCR\CLSID\{CAA1A27E-E33D-4D25-A24F-618D516FB671}\ProgID]
"(Default)" = "SnapMyScreen_bf.HTMLMenu.1"

[HKCR\Interface\{80385B90-FB28-4942-9E64-07653DB82859}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\CLSID\{b8d6859e-e323-412c-89ff-9b05d262749a}\InprocServer32]
"(Default)" = "%Program Files%\SnapMyScreen_bf\bar\1.bin\bfhttpct.dll"

[HKLM\SOFTWARE\SnapMyScreen_bf\bar]
"RegHookPath" = "C:\PROGRA~1\SNAPMY~1\bar\1.bin\bfreghk"

[HKLM\SOFTWARE\MozillaPlugins\@SnapMyScreen_bf.com/Plugin\MimeTypes\application/x-snapmyscreen_bfplugin]
"Description" = "SnapMyScreen Plugin"

[HKLM\SOFTWARE\SnapMyScreen_bf\bar\Integrators]
"ToolbarGuard.dll" = ""

[HKCR\Interface\{0023203D-1EE3-4FFB-8C31-7E142FC5CA32}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{E18CB616-56DD-4C51-9C3A-71D637DEA5BE}\ProxyStubClsid]
"(Default)" = "{00020420-0000-0000-C000-000000000046}"

[HKCR\TypeLib\{26307A86-BF6D-485F-9859-875385C961D9}\1.0\HELPDIR]
"(Default)" = "%Program Files%\SnapMyScreen_bf\bar\1.bin"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd72-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCR\CLSID\{6c7b31f7-a830-4c86-a7a1-b2e1b1253547}\ProgID]
"(Default)" = "SnapMyScreen_bf.HTMLPanel.1"

[HKCR\Interface\{0023203D-1EE3-4FFB-8C31-7E142FC5CA32}\TypeLib]
"(Default)" = "{AA398903-C818-4EEA-92D4-44AE17838787}"

[HKCR\Interface\{292C13FB-0482-4E57-91C6-A23FBD80BB54}\TypeLib]
"(Default)" = "{4BE1D37F-2316-4857-9B2F-A523883F38B8}"

[HKCR\TypeLib\{692E8C91-3456-4DFE-9E3F-3BE70FBDF712}\1.0\FLAGS]
"(Default)" = "0"

[HKLM\SOFTWARE\SnapMyScreen_bf\bar]
"DeletedCustomizations" = "1"

[HKCR\Interface\{1405C496-0E77-453D-A629-A2D45E2C5BAC}\TypeLib]
"(Default)" = "{AA398903-C818-4EEA-92D4-44AE17838787}"

[HKCR\CLSID\{56c33cec-cd9d-4656-8900-379b4bfe3190}\VersionIndependentProgID]
"(Default)" = "SnapMyScreen_bf.PseudoTransparentPlugin"

[HKCR\Interface\{88521B9F-6F51-479B-990D-04FFC83453C0}\TypeLib]
"(Default)" = "{E41A6F86-420F-45E2-9237-6AAA2C72380B}"

[HKCR\CLSID\{76ce4e76-6620-4ed3-9372-a4cf8b3b119f}\InprocServer32]
"(Default)" = "%Program Files%\SnapMyScreen_bf\bar\1.bin\bftpinst.dll"

[HKCR\TypeLib\{AA398903-C818-4EEA-92D4-44AE17838787}\1.0\FLAGS]
"(Default)" = "0"

[HKCR\SnapMyScreen_bf.MultipleButton.1]
"(Default)" = ""

[HKLM\SOFTWARE\SnapMyScreen_bf\bar]
"sr" = "0"

[HKCR\Interface\{D61A691F-FCC2-4B11-9D2B-FDBDE39BE8CF}\TypeLib]
"(Default)" = "{EFA0DFB6-66E5-4081-B607-BF6542818156}"

[HKCR\CLSID\{82c80e87-9daa-4b04-8455-aac9ea10f2b0}\MiscStatus]
"(Default)" = "0"

[HKCR\Interface\{E259193B-1D00-42A0-8E66-87DFE3EE0BA5}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{F282368A-F145-4C0C-8691-B4DBF6DAEFCE}\TypeLib]
"(Default)" = "{AA398903-C818-4EEA-92D4-44AE17838787}"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION]
"CrExtPbf.exe" = "0"

[HKCR\CLSID\{f3b5e712-c267-49e0-8dfd-5b182ff08d90}\TypeLib]
"(Default)" = "{aa398903-c818-4eea-92d4-44ae17838787}"

[HKCR\CLSID\{c4d86c62-bcee-4886-9fb9-34b1db677726}\VersionIndependentProgID]
"(Default)" = "SnapMyScreen_bf.ToolbarProtector"

[HKCR\SnapMyScreen_bf.SettingsPlugin.1]
"(Default)" = ""

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1eab99ef-d357-4d1a-b347-ee231b4141c4}]
"Policy" = "3"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CAA1A27E-E33D-4D25-A24F-618D516FB671}]
"(Default)" = ""

[HKCR\TypeLib\{960B20A4-2C34-4AF8-B280-E45F9BE27500}\1.0\0\win32]
"(Default)" = "%Program Files%\SnapMyScreen_bf\bar\1.bin\t8res.dll\625"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f7ea4bcc-6913-4fd3-88e8-3627671a1c77}]
"Policy" = "3"

[HKCR\Interface\{1A327208-15F5-4C84-BB37-AEFDB2E5B049}\TypeLib]
"(Default)" = "{EFA0DFB6-66E5-4081-B607-BF6542818156}"

[HKCR\Interface\{1500187C-0661-43B1-9765-AC0C01B0592E}\TypeLib]
"Version" = "1.0"

[HKCR\SnapMyScreen_bf.HTMLMenu.1]
"(Default)" = "SnapMyScreen_bf HTML Menu"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b98117e8-75ca-11e2-81b2-000c293708fb}]
"BaseClass" = "Drive"

[HKCR\SnapMyScreen_bf.FeedManager]
"(Default)" = ""

[HKCR\TypeLib\{EFA0DFB6-66E5-4081-B607-BF6542818156}\1.0\FLAGS]
"(Default)" = "0"

[HKCR\Interface\{1405C496-0E77-453D-A629-A2D45E2C5BAC}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{491F0A4E-B416-4C15-8AC7-EC9305C816A8}\TypeLib]
"Version" = "1.0"

[HKCR\TypeLib\{7C34AB4E-65CE-4DFB-8F79-854A4AAF0AD1}\1.0]
"(Default)" = "TEMPLATEHTMLMenuLib"

[HKCR\CLSID\{aec668ad-ff7e-46b9-b11f-4a6b297e4cd2}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Interface\{5E1904ED-A147-490E-A643-21A084E45B1C}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\CLSID\{cd2389ad-e520-4db8-b436-fc082ee7d98c}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c155cd73-744b-11e2-8294-806d6172696f}]
"BaseClass" = "Drive"

[HKCR\CLSID\{f3b5e712-c267-49e0-8dfd-5b182ff08d90}\VersionIndependentProgID]
"(Default)" = "SnapMyScreen_bf.SettingsPlugin"

[HKCR\TypeLib\{D675A3DA-42CF-4D3D-A6C4-51688AF2C0E3}\1.0\0\win32]
"(Default)" = "%Program Files%\SnapMyScreen_bf\bar\1.bin\t8res.dll\905"

[HKCR\SnapMyScreen_bf.PseudoTransparentPlugin\CLSID]
"(Default)" = "{56c33cec-cd9d-4656-8900-379b4bfe3190}"

[HKCR\TypeLib\{E41A6F86-420F-45E2-9237-6AAA2C72380B}\1.0\0\win32]
"(Default)" = "%Program Files%\SnapMyScreen_bf\bar\1.bin\t8res.dll\405"

[HKCR\CLSID\{6c7b31f7-a830-4c86-a7a1-b2e1b1253547}\MiscStatus]
"(Default)" = "0"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0023203d-1ee3-4ffb-8c31-7e142fc5ca32}]
"AppPath" = "%Program Files%\SnapMyScreen_bf\bar\1.bin"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{755052ba-d5fd-4152-ab3e-db447a9d9ec8}]
"AppName" = "AppIntegrator.exe"

[HKCR\Interface\{292C13FB-0482-4E57-91C6-A23FBD80BB54}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{B1C3A46D-8934-4338-9D0D-68560227C984}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{7E5AE580-3435-4D29-B7F3-2957102DBF65}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{e2e2622d-480c-4123-aed5-3e7740ad3d6d}]
"AppName" = "bfmedint.exe"

[HKCR\SnapMyScreen_bf.ThirdPartyInstaller]
"(Default)" = "SnapMyScreen Third Party Installer"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1eab99ef-d357-4d1a-b347-ee231b4141c4}]
"AppName" = "CrExtPbf.exe"

[HKLM\SOFTWARE\SnapMyScreen_bf\bar]
"Build" = "109.21604"

[HKCR\Interface\{7E5AE580-3435-4D29-B7F3-2957102DBF65}\TypeLib]
"(Default)" = "{7C34AB4E-65CE-4DFB-8F79-854A4AAF0AD1}"

[HKCR\SnapMyScreen_bf.SettingsPlugin\CurVer]
"(Default)" = "SnapMyScreen_bf.SettingsPlugin.1"

[HKCR\CLSID\{2bd24259-5294-4e0d-8469-27ce1158c272}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\CLSID\{8032b822-5453-479b-ae28-47d2b62de44d}\TypeLib]
"(Default)" = "{e41a6f86-420f-45e2-9237-6aaa2c72380b}"

[HKCU\Software\Classes\CLSID\{6b1c6575-d21f-4902-a026-09c119c0c87e}]
"(Default)" = ""

[HKCR\Interface\{14522BE0-421D-4804-BF47-883129E82ABB}\TypeLib]
"Version" = "1.0"

[HKCR\CLSID\{56c33cec-cd9d-4656-8900-379b4bfe3190}\InprocServer32]
"(Default)" = "%Program Files%\SnapMyScreen_bf\bar\1.bin\bfskin.dll"

[HKCR\TypeLib\{26307A86-BF6D-485F-9859-875385C961D9}\1.0\FLAGS]
"(Default)" = "0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{76ce4e76-6620-4ed3-9372-a4cf8b3b119f}]
"(Default)" = ""

[HKCR\Interface\{E259193B-1D00-42A0-8E66-87DFE3EE0BA5}\TypeLib]
"(Default)" = "{960B20A4-2C34-4AF8-B280-E45F9BE27500}"

[HKCR\CLSID\{56c33cec-cd9d-4656-8900-379b4bfe3190}]
"(Default)" = "Pseudo Transparent Plugin"

[HKCR\Interface\{B9C39A03-DBC3-4158-BB1B-3ED9F1C98129}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\SnapMyScreen_bf.ToolbarProtector]
"(Default)" = "ProtectorControl Class"

[HKLM\SOFTWARE\MozillaPlugins\@SnapMyScreen_bf.com/Plugin\MimeTypes\application/x-snapmyscreen_bfplugin]
"Suffixes" = "bf"

[HKCR\CLSID\{aec668ad-ff7e-46b9-b11f-4a6b297e4cd2}\InprocServer32]
"(Default)" = "%Program Files%\SnapMyScreen_bf\bar\1.bin\bfdatact.dll"

[HKCR\CLSID\{CAA1A27E-E33D-4D25-A24F-618D516FB671}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\SnapMyScreen_bf.HTMLPanel.1\CLSID]
"(Default)" = "{6c7b31f7-a830-4c86-a7a1-b2e1b1253547}"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f7ea4bcc-6913-4fd3-88e8-3627671a1c77}]
"AppPath" = "%Program Files%\SnapMyScreen_bf\bar\1.bin"

[HKLM\SOFTWARE\SnapMyScreen_bf\bar]
"Maximized" = "1"

[HKCR\CLSID\{bdffe389-a538-42f1-b36b-cbfb78e2d7fc}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\CLSID\{bd3b52cc-c53d-49b5-bceb-84b18ec2f48d}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\CLSID\{6c7b31f7-a830-4c86-a7a1-b2e1b1253547}\VersionIndependentProgID]
"(Default)" = "SnapMyScreen_bf.HTMLPanel"

[HKCR\CLSID\{8032b822-5453-479b-ae28-47d2b62de44d}\MiscStatus\1]
"(Default)" = "131473"

[HKCR\SnapMyScreen_bf.HTMLPanel.1]
"(Default)" = "SnapMyScreen_bf HTML Panel"

[HKCR\CLSID\{b8d6859e-e323-412c-89ff-9b05d262749a}\TypeLib]
"(Default)" = "{d675a3da-42cf-4d3d-a6c4-51688af2c0e3}"

[HKCR\TypeLib\{AA398903-C818-4EEA-92D4-44AE17838787}\1.0\HELPDIR]
"(Default)" = "%Program Files%\SnapMyScreen_bf\bar\1.bin"

[HKCR\Interface\{4422543C-9F04-4E29-B29A-9E009F660ED8}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{0023203D-1EE3-4FFB-8C31-7E142FC5CA32}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{BD238C78-0312-4E81-B0F7-8E96D21FA57A}\TypeLib]
"Version" = "1.0"

[HKCR\SnapMyScreen_bf.HTMLMenu.1\CLSID]
"(Default)" = "{CAA1A27E-E33D-4D25-A24F-618D516FB671}"

[HKCR\CLSID\{CAA1A27E-E33D-4D25-A24F-618D516FB671}\VersionIndependentProgID]
"(Default)" = "SnapMyScreen_bf.HTMLMenu"

[HKCR\CLSID\{f3b5e712-c267-49e0-8dfd-5b182ff08d90}\MiscStatus\1]
"(Default)" = "131473"

[HKCR\SnapMyScreen_bf.MultipleButton.1\CLSID]
"(Default)" = "{a7567cad-49ed-4aed-94a8-4dcc24895222}"

[HKCR\Interface\{F282368A-F145-4C0C-8691-B4DBF6DAEFCE}\TypeLib]
"Version" = "1.0"

[HKCU\Software\Classes\CLSID\{6b1c6575-d21f-4902-a026-09c119c0c87e}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{e2e2622d-480c-4123-aed5-3e7740ad3d6d}]
"Policy" = "3"

[HKCR\Interface\{491F0A4E-B416-4C15-8AC7-EC9305C816A8}\TypeLib]
"(Default)" = "{AA398903-C818-4EEA-92D4-44AE17838787}"

[HKCR\CLSID\{9646c642-4bbc-49b9-b332-f1073541e3e1}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Interface\{D61A691F-FCC2-4B11-9D2B-FDBDE39BE8CF}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\CLSID\{3e991f5f-77b8-4e48-ba4e-7ba426ffb036}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Interface\{755052BA-D5FD-4152-AB3E-DB447A9D9EC8}]
"(Default)" = "_ITemplateBarSettingsEvents"

[HKCR\TypeLib\{DD50941D-708B-4434-ABA0-FDC9578513CF}\1.0\0\win32]
"(Default)" = "%Program Files%\SnapMyScreen_bf\bar\1.bin\t8res.dll\100"

[HKCR\Interface\{80385B90-FB28-4942-9E64-07653DB82859}\TypeLib]
"Version" = "1.0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SnapMyScreen_bfbar Uninstall Internet Explorer]
"URLInfoAbout" = "http://support.mindspark.com/"

[HKCR\SnapMyScreen_bf.FeedManager\CurVer]
"(Default)" = "SnapMyScreen_bf.FeedManager.1"

[HKLM\SOFTWARE\SnapMyScreen_bf\bar]
"UninstallString" = "%Program Files%\SnapMyScreen_bf\bar\1.bin\bfhighin.exe bfbar.dll,O uninstalltype=IE"

[HKCR\SnapMyScreen_bf.FeedManager.1]
"(Default)" = ""

[HKCR\CLSID\{9646c642-4bbc-49b9-b332-f1073541e3e1}\Version]
"(Default)" = "1.0"

[HKCR\CLSID\{82c80e87-9daa-4b04-8455-aac9ea10f2b0}\MiscStatus\1]
"(Default)" = "131473"

[HKCR\CLSID\{cd2389ad-e520-4db8-b436-fc082ee7d98c}\InprocServer32]
"(Default)" = "%Program Files%\SnapMyScreen_bf\bar\1.bin\bfbar.dll"

[HKCR\SnapMyScreen_bf.HTMLMenu]
"(Default)" = "SnapMyScreen_bf HTML Menu"

[HKCR\Interface\{E942057E-BFE8-493D-98DB-681B15EF8ABD}\TypeLib]
"Version" = "1.0"

[HKCR\CLSID\{82c80e87-9daa-4b04-8455-aac9ea10f2b0}\InprocServer32]
"(Default)" = "%Program Files%\SnapMyScreen_bf\bar\1.bin\bffeedmg.dll"

[HKLM\SOFTWARE\MozillaPlugins\@SnapMyScreen_bf.com/Plugin]
"Description" = "SnapMyScreen Plugin"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{e2e2622d-480c-4123-aed5-3e7740ad3d6d}]
"AppPath" = "%Program Files%\SnapMyScreen_bf\bar\1.bin"

[HKCR\Interface\{E942057E-BFE8-493D-98DB-681B15EF8ABD}\TypeLib]
"(Default)" = "{692E8C91-3456-4DFE-9E3F-3BE70FBDF712}"

[HKCR\SnapMyScreen_bf.ScriptButton]
"(Default)" = ""

[HKCR\SnapMyScreen_bf.MultipleButton\CLSID]
"(Default)" = "{a7567cad-49ed-4aed-94a8-4dcc24895222}"

[HKCR\Interface\{1A327208-15F5-4C84-BB37-AEFDB2E5B049}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{1A327208-15F5-4C84-BB37-AEFDB2E5B049}\TypeLib]
"Version" = "1.0"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8032b822-5453-479b-ae28-47d2b62de44d}]
"Policy" = "3"

[HKCR\CLSID\{6c7b31f7-a830-4c86-a7a1-b2e1b1253547}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Interface\{BD238C78-0312-4E81-B0F7-8E96D21FA57A}\TypeLib]
"(Default)" = "{DD50941D-708B-4434-ABA0-FDC9578513CF}"

[HKCR\CLSID\{76ce4e76-6620-4ed3-9372-a4cf8b3b119f}]
"(Default)" = "SnapMyScreen Third Party Installer"

[HKLM\SOFTWARE\SnapMyScreen_bf\bar\Switches]
"od" = "1"
"ok" = "1"

[HKLM\SOFTWARE\MozillaPlugins\@SnapMyScreen_bf.com/Plugin]
"Version" = "1.1.1.1"

[HKLM\SOFTWARE\SnapMyScreen_bf\SkinTools]
"PlayerPath" = "%Program Files%\SnapMyScreen_bf\bar\1.bin\bfSkPlay.exe"

[HKCR\TypeLib\{692E8C91-3456-4DFE-9E3F-3BE70FBDF712}\1.0]
"(Default)" = "HTML 1.0 Type Library"

[HKCR\Interface\{5E1904ED-A147-490E-A643-21A084E45B1C}]
"(Default)" = "IDataCtrl"

[HKCR\SnapMyScreen_bf.HTMLPanel]
"(Default)" = "SnapMyScreen_bf HTML Panel"

[HKCR\TypeLib\{DD50941D-708B-4434-ABA0-FDC9578513CF}\1.0\FLAGS]
"(Default)" = "0"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{755052ba-d5fd-4152-ab3e-db447a9d9ec8}]
"AppPath" = "%Program Files%\SnapMyScreen_bf\bar\1.bin"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SnapMyScreen_bfbar Uninstall Internet Explorer]
"Publisher" = "Mindspark Interactive Network"

[HKCR\TypeLib\{AA398903-C818-4EEA-92D4-44AE17838787}\1.0]
"(Default)" = "Toolbar 1.0 Type Library"

[HKCR\Interface\{B1C3A46D-8934-4338-9D0D-68560227C984}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{4422543C-9F04-4E29-B29A-9E009F660ED8}\TypeLib]
"(Default)" = "{E41A6F86-420F-45E2-9237-6AAA2C72380B}"

[HKCR\SnapMyScreen_bf.PseudoTransparentPlugin.1]
"(Default)" = "Pseudo Transparent Plugin"

[HKCR\CLSID\{a7567cad-49ed-4aed-94a8-4dcc24895222}\VersionIndependentProgID]
"(Default)" = "SnapMyScreen_bf.MultipleButton"

[HKCR\SnapMyScreen_bf.ScriptButton.1]
"(Default)" = ""

[HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" = ""

[HKCR\CLSID\{8032b822-5453-479b-ae28-47d2b62de44d}\MiscStatus]
"(Default)" = "0"

[HKCR\CLSID\{c4d86c62-bcee-4886-9fb9-34b1db677726}]
"(Default)" = "ProtectorControl Class"

[HKCR\CLSID\{a7567cad-49ed-4aed-94a8-4dcc24895222}\ProgID]
"(Default)" = "SnapMyScreen_bf.MultipleButton.1"

[HKCR\Interface\{E24A46F2-943A-4E2B-ACF2-2EFF4D8250FA}\TypeLib]
"Version" = "1.0"

[HKCR\TypeLib\{960B20A4-2C34-4AF8-B280-E45F9BE27500}\1.0\HELPDIR]
"(Default)" = "%Program Files%\SnapMyScreen_bf\bar\1.bin"

[HKCR\Interface\{6807DB38-4598-4C86-AD26-444994F377D4}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\TypeLib\{692E8C91-3456-4DFE-9E3F-3BE70FBDF712}\1.0\HELPDIR]
"(Default)" = "%Program Files%\SnapMyScreen_bf\bar\1.bin"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8032b822-5453-479b-ae28-47d2b62de44d}]
"AppName" = "bfSkPlay.exe"

[HKCR\Interface\{F282368A-F145-4C0C-8691-B4DBF6DAEFCE}]
"(Default)" = "ITemplateBarMenu"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{8032b822-5453-479b-ae28-47d2b62de44d}]
"AppPath" = "%Program Files%\SnapMyScreen_bf\bar\1.bin"

[HKCR\Interface\{491F0A4E-B416-4C15-8AC7-EC9305C816A8}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{B9C39A03-DBC3-4158-BB1B-3ED9F1C98129}\TypeLib]
"(Default)" = "{D675A3DA-42CF-4D3D-A6C4-51688AF2C0E3}"

[HKLM\SOFTWARE\SnapMyScreen_bf\bar]
"SettingsDir" = "%Program Files%\SnapMyScreen_bf\bar\Settings\"

[HKCR\Interface\{755052BA-D5FD-4152-AB3E-DB447A9D9EC8}\ProxyStubClsid]
"(Default)" = "{00020420-0000-0000-C000-000000000046}"

[HKCR\CLSID\{8032b822-5453-479b-ae28-47d2b62de44d}]
"(Default)" = "Skin Settings"

[HKCR\SnapMyScreen_bf.ToolbarProtector\CLSID]
"(Default)" = "{c4d86c62-bcee-4886-9fb9-34b1db677726}"

[HKCR\CLSID\{b8d6859e-e323-412c-89ff-9b05d262749a}]
"(Default)" = "HttpControl Class"

[HKCR\CLSID\{76ce4e76-6620-4ed3-9372-a4cf8b3b119f}\MiscStatus\1]
"(Default)" = "131473"

[HKCR\Interface\{64DEC467-9869-4695-BF50-4F5B76A0F10E}\ProxyStubClsid]
"(Default)" = "{00020420-0000-0000-C000-000000000046}"

[HKCR\CLSID\{f3b5e712-c267-49e0-8dfd-5b182ff08d90}\MiscStatus]
"(Default)" = "0"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0023203d-1ee3-4ffb-8c31-7e142fc5ca32}]
"AppName" = "bfSlSrch.exe"

[HKLM\SOFTWARE\SnapMyScreen_bf\bar]
"tiec" = "208976"

[HKCR\Interface\{E24A46F2-943A-4E2B-ACF2-2EFF4D8250FA}]
"(Default)" = "IProtectorControl"

[HKCR\TypeLib\{692E8C91-3456-4DFE-9E3F-3BE70FBDF712}\1.0\0\win32]
"(Default)" = "%Program Files%\SnapMyScreen_bf\bar\1.bin\t8res.dll\1506"

[HKCR\TypeLib\{4BE1D37F-2316-4857-9B2F-A523883F38B8}\1.0\0\win32]
"(Default)" = "%Program Files%\SnapMyScreen_bf\bar\1.bin\t8res.dll\1406"

[HKCR\CLSID\{8032b822-5453-479b-ae28-47d2b62de44d}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cache" = "%Documents and Settings%\%current user%\Local Settings\Temporary Internet Files"

[HKCR\Interface\{E259193B-1D00-42A0-8E66-87DFE3EE0BA5}]
"(Default)" = "IDisableAddonRebuttal"

[HKCR\CLSID\{82c80e87-9daa-4b04-8455-aac9ea10f2b0}]
"(Default)" = ""

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{cd2389ad-e520-4db8-b436-fc082ee7d98c}" = ""

[HKCU\Software\Classes\CLSID\{6b1c6575-d21f-4902-a026-09c119c0c87e}\InprocServer32]
"(Default)" = "%Program Files%\SnapMyScreen_bf\bar\1.bin\bfSrcAs.dll"

[HKCR\Interface\{14522BE0-421D-4804-BF47-883129E82ABB}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\TypeLib\{D675A3DA-42CF-4D3D-A6C4-51688AF2C0E3}\1.0]
"(Default)" = "HttpControl 1.0 Type Library"

[HKLM\SOFTWARE\SnapMyScreen_bf\bar\Switches]
"hpp" = "0"

[HKCR\Interface\{B9C39A03-DBC3-4158-BB1B-3ED9F1C98129}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{64DEC467-9869-4695-BF50-4F5B76A0F10E}\TypeLib]
"Version" = "1.0"

[HKCR\CLSID\{cd2389ad-e520-4db8-b436-fc082ee7d98c}]
"(Default)" = "SnapMyScreen"

[HKLM\SOFTWARE\SnapMyScreen_bf\bar]
"CurInstall" = "1"

[HKCR\CLSID\{56c33cec-cd9d-4656-8900-379b4bfe3190}\Version]
"(Default)" = "1.0"

[HKCR\SnapMyScreen_bf.HTMLPanel\CurVer]
"(Default)" = "SnapMyScreen_bf.HTMLPanel.1"

[HKCR\CLSID\{8032b822-5453-479b-ae28-47d2b62de44d}\Version]
"(Default)" = "1.0"

[HKCR\CLSID\{6c7b31f7-a830-4c86-a7a1-b2e1b1253547}\InprocServer32]
"(Default)" = "%Program Files%\SnapMyScreen_bf\bar\1.bin\T8HTML.DLL"

[HKCR\CLSID\{aec668ad-ff7e-46b9-b11f-4a6b297e4cd2}]
"(Default)" = "DataCtrl Class"

[HKCR\SnapMyScreen_bf.PseudoTransparentPlugin.1\CLSID]
"(Default)" = "{56c33cec-cd9d-4656-8900-379b4bfe3190}"

[HKCR\Interface\{1405C496-0E77-453D-A629-A2D45E2C5BAC}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\SnapMyScreen_bf.HTMLPanel\CLSID]
"(Default)" = "{6c7b31f7-a830-4c86-a7a1-b2e1b1253547}"

[HKCR\CLSID\{a7567cad-49ed-4aed-94a8-4dcc24895222}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\SnapMyScreen_bf.ScriptButton\CurVer]
"(Default)" = "SnapMyScreen_bf.ScriptButton.1"

[HKCR\CLSID\{a7567cad-49ed-4aed-94a8-4dcc24895222}\InprocServer32]
"(Default)" = "%Program Files%\SnapMyScreen_bf\bar\1.bin\bfmlbtn.dll"

[HKCR\Interface\{E18CB616-56DD-4C51-9C3A-71D637DEA5BE}\TypeLib]
"Version" = "1.0"

[HKCR\CLSID\{76ce4e76-6620-4ed3-9372-a4cf8b3b119f}\MiscStatus]
"(Default)" = "0"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Common Desktop" = "%Documents and Settings%\All Users\Desktop"

[HKCR\Interface\{88521B9F-6F51-479B-990D-04FFC83453C0}]
"(Default)" = "SKINWINDOW_INTERFACE"

[HKCR\CLSID\{f3b5e712-c267-49e0-8dfd-5b182ff08d90}\InprocServer32]
"(Default)" = "%Program Files%\SnapMyScreen_bf\bar\1.bin\bfbar.dll"

[HKCR\CLSID\{c4d86c62-bcee-4886-9fb9-34b1db677726}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Interface\{292C13FB-0482-4E57-91C6-A23FBD80BB54}]
"(Default)" = "ISessionData"

[HKCR\SnapMyScreen_bf.PseudoTransparentPlugin]
"(Default)" = "Pseudo Transparent Plugin"

[HKCR\TypeLib\{4BE1D37F-2316-4857-9B2F-A523883F38B8}\1.0]
"(Default)" = "DataCtrl 1.0 Type Library"

[HKCR\Interface\{6807DB38-4598-4C86-AD26-444994F377D4}]
"(Default)" = "PSEUDOTRANSPARENT_INTERFACE"

[HKCR\Interface\{755052BA-D5FD-4152-AB3E-DB447A9D9EC8}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{292C13FB-0482-4E57-91C6-A23FBD80BB54}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{80385B90-FB28-4942-9E64-07653DB82859}\TypeLib]
"(Default)" = "{26307A86-BF6D-485F-9859-875385C961D9}"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0023203d-1ee3-4ffb-8c31-7e142fc5ca32}]
"Policy" = "3"

[HKCR\TypeLib\{26307A86-BF6D-485F-9859-875385C961D9}\1.0\0\win32]
"(Default)" = "%Program Files%\SnapMyScreen_bf\bar\1.bin\t8res.dll\1807"

[HKCR\CLSID\{3e991f5f-77b8-4e48-ba4e-7ba426ffb036}\InprocServer32]
"(Default)" = "C:\PROGRA~1\SNAPMY~1\bar\1.bin\bfbar.dll"

[HKCR\SnapMyScreen_bf.MultipleButton]
"(Default)" = ""

[HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\PROGRA~1\SNAPMY~1\bar\1.bin]
"AppIntegrator.exe" = "Mindspark Toolbar Platform"

[HKCR\Interface\{755052BA-D5FD-4152-AB3E-DB447A9D9EC8}\ProxyStubClsid32]
"(Default)" = "{00020420-0000-0000-C000-000000000046}"

[HKCR\CLSID\{bdffe389-a538-42f1-b36b-cbfb78e2d7fc}]
"(Default)" = ""

[HKCR\Interface\{4422543C-9F04-4E29-B29A-9E009F660ED8}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\TypeLib\{E41A6F86-420F-45E2-9237-6AAA2C72380B}\1.0]
"(Default)" = "Skin 1.0 Type Library"

[HKCR\CLSID\{c4d86c62-bcee-4886-9fb9-34b1db677726}\TypeLib]
"(Default)" = "{26307a86-bf6d-485f-9859-875385c961d9}"

[HKCR\Interface\{E24A46F2-943A-4E2B-ACF2-2EFF4D8250FA}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{86B37BFC-233A-4D67-B3BA-60559DEBAF57}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{BD238C78-0312-4E81-B0F7-8E96D21FA57A}]
"(Default)" = "IThirdPartyInstaller"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SnapMyScreen_bfbar Uninstall Internet Explorer]
"UninstallString" = "rundll32 %Program Files%\SnapMyScreen_bf\bar\1.bin\bfBar.dll,O mindsparktoolbarkey=SnapMyScreen_bf uninstalltype=IE"

[HKCR\TypeLib\{E41A6F86-420F-45E2-9237-6AAA2C72380B}\1.0\FLAGS]
"(Default)" = "0"

[HKCR\CLSID\{bd3b52cc-c53d-49b5-bceb-84b18ec2f48d}]
"(Default)" = "Disable Addon Rebuttal Control"

[HKCR\Interface\{491F0A4E-B416-4C15-8AC7-EC9305C816A8}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\TypeLib\{EFA0DFB6-66E5-4081-B607-BF6542818156}\1.0\HELPDIR]
"(Default)" = "%Program Files%\SnapMyScreen_bf\bar\1.bin"

[HKCR\Interface\{2F64F67F-3ADE-49FE-95D1-511667B1679A}]
"(Default)" = "IHttpControlEvents"

[HKCR\SnapMyScreen_bf.ThirdPartyInstaller.1\CLSID]
"(Default)" = "{76ce4e76-6620-4ed3-9372-a4cf8b3b119f}"

[HKLM\SOFTWARE\SnapMyScreen_bf\bar\Integrators]
"AssistMonitor.dll" = ""

[HKLM\SOFTWARE\MozillaPlugins\@SnapMyScreen_bf.com/Plugin]
"vendor" = "SnapMyScreen_bf"

[HKCR\CLSID\{82c80e87-9daa-4b04-8455-aac9ea10f2b0}\Version]
"(Default)" = "1.0"

[HKCR\CLSID\{9646c642-4bbc-49b9-b332-f1073541e3e1}]
"(Default)" = "Popup Menu Plugin"

[HKCR\CLSID\{82c80e87-9daa-4b04-8455-aac9ea10f2b0}\ProgID]
"(Default)" = "SnapMyScreen_bf.FeedManager.1"

[HKCR\Interface\{B1C3A46D-8934-4338-9D0D-68560227C984}]
"(Default)" = "SKINSETTINGS_INTERFACE"

[HKCR\Interface\{0023203D-1EE3-4FFB-8C31-7E142FC5CA32}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\SnapMyScreen_bf.FeedManager.1\CLSID]
"(Default)" = "{82c80e87-9daa-4b04-8455-aac9ea10f2b0}"

[HKCR\Interface\{4422543C-9F04-4E29-B29A-9E009F660ED8}]
"(Default)" = "POPUPMENU_INTERFACE"

[HKCR\TypeLib\{DD50941D-708B-4434-ABA0-FDC9578513CF}\1.0]
"(Default)" = "TYPELIB_NAME"

[HKCR\Interface\{B9C39A03-DBC3-4158-BB1B-3ED9F1C98129}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{0023203D-1EE3-4FFB-8C31-7E142FC5CA32}]
"(Default)" = "ITemplateBarSettings"

[HKCR\CLSID\{6c7b31f7-a830-4c86-a7a1-b2e1b1253547}\TypeLib]
"(Default)" = "{692e8c91-3456-4dfe-9e3f-3be70fbdf712}"

[HKCR\CLSID\{9646c642-4bbc-49b9-b332-f1073541e3e1}\InprocServer32]
"(Default)" = "%Program Files%\SnapMyScreen_bf\bar\1.bin\bfskin.dll"

[HKCR\Interface\{E18CB616-56DD-4C51-9C3A-71D637DEA5BE}\ProxyStubClsid32]
"(Default)" = "{00020420-0000-0000-C000-000000000046}"

[HKCR\Interface\{B1C3A46D-8934-4338-9D0D-68560227C984}\TypeLib]
"(Default)" = "{E41A6F86-420F-45E2-9237-6AAA2C72380B}"

[HKLM\SOFTWARE\SnapMyScreen_bf\bar\Switches]
"nk" = "0"
"nd" = "0"

[HKCR\Interface\{5E1904ED-A147-490E-A643-21A084E45B1C}\TypeLib]
"Version" = "1.0"

[HKLM\SOFTWARE\SnapMyScreen_bf\Settings\SmileyCentralBtn]
"HTMLMenuPosDeleted" = "1"

[HKCR\CLSID\{bdffe389-a538-42f1-b36b-cbfb78e2d7fc}\VersionIndependentProgID]
"(Default)" = "SnapMyScreen_bf.ScriptButton"

[HKCR\Interface\{1500187C-0661-43B1-9765-AC0C01B0592E}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{1500187C-0661-43B1-9765-AC0C01B0592E}\TypeLib]
"(Default)" = "{692E8C91-3456-4DFE-9E3F-3BE70FBDF712}"

[HKLM\SOFTWARE\SnapMyScreen_bf\bar\Switches]
"au" = "1"

[HKCR\CLSID\{2bd24259-5294-4e0d-8469-27ce1158c272}]
"(Default)" = "Search Assistant BHO"

[HKCR\SnapMyScreen_bf.ThirdPartyInstaller\CLSID]
"(Default)" = "{76ce4e76-6620-4ed3-9372-a4cf8b3b119f}"

[HKCR\TypeLib\{E41A6F86-420F-45E2-9237-6AAA2C72380B}\1.0\HELPDIR]
"(Default)" = "%Program Files%\SnapMyScreen_bf\bar\1.bin"

[HKLM\SOFTWARE\SnapMyScreen_bf\bar\Integrators]
"bfDlgHk.dll" = ""

[HKCR\CLSID\{2bd24259-5294-4e0d-8469-27ce1158c272}\InprocServer32]
"(Default)" = "%Program Files%\SnapMyScreen_bf\bar\1.bin\bfSrcAs.dll"

[HKCR\Interface\{ED5C7EBB-E72B-4333-A546-F4944D982C58}\TypeLib]
"(Default)" = "{7C34AB4E-65CE-4DFB-8F79-854A4AAF0AD1}"

[HKCR\SnapMyScreen_bf.MultipleButton\CurVer]
"(Default)" = "SnapMyScreen_bf.MultipleButton.1"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f7ea4bcc-6913-4fd3-88e8-3627671a1c77}]
"AppName" = "bfSrchMn.exe"

[HKCR\SnapMyScreen_bf.ThirdPartyInstaller\CurVer]
"(Default)" = "SnapMyScreen_bf.ThirdPartyInstaller.1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SnapMyScreen_bfbar Uninstall Internet Explorer]
"DisplayName" = "SnapMyScreen Internet Explorer Toolbar"

[HKCR\CLSID\{76ce4e76-6620-4ed3-9372-a4cf8b3b119f}\Version]
"(Default)" = "1.0"

[HKCR\CLSID\{9646c642-4bbc-49b9-b332-f1073541e3e1}\MiscStatus]
"(Default)" = "0"

[HKCR\TypeLib\{4BE1D37F-2316-4857-9B2F-A523883F38B8}\1.0\FLAGS]
"(Default)" = "0"

[HKLM\SOFTWARE\SnapMyScreen_bf\bar]
"InstallingUser" = "S-1-5-21-1844237615-1960408961-1801674531-1003"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{56c33cec-cd9d-4656-8900-379b4bfe3190}]
"(Default)" = ""

[HKCR\CLSID\{6c7b31f7-a830-4c86-a7a1-b2e1b1253547}]
"(Default)" = "SnapMyScreen_bf HTML"

[HKCR\Interface\{86B37BFC-233A-4D67-B3BA-60559DEBAF57}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{ED5C7EBB-E72B-4333-A546-F4944D982C58}\TypeLib]
"Version" = "1.0"

[HKCR\TypeLib\{7C34AB4E-65CE-4DFB-8F79-854A4AAF0AD1}\1.0\FLAGS]
"(Default)" = "0"

[HKLM\SOFTWARE\SnapMyScreen_bf\bar]
"RegisteredWithFirefox" = "1"

[HKCR\CLSID\{3e991f5f-77b8-4e48-ba4e-7ba426ffb036}]
"(Default)" = "Toolbar BHO"

[HKCR\Interface\{1405C496-0E77-453D-A629-A2D45E2C5BAC}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{E24A46F2-943A-4E2B-ACF2-2EFF4D8250FA}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\SnapMyScreen_bf.HTMLMenu\CurVer]
"(Default)" = "SnapMyScreen_bf.HTMLMenu.1"

[HKCR\Interface\{6807DB38-4598-4C86-AD26-444994F377D4}\TypeLib]
"(Default)" = "{E41A6F86-420F-45E2-9237-6AAA2C72380B}"

[HKCR\SnapMyScreen_bf.SettingsPlugin.1\CLSID]
"(Default)" = "{f3b5e712-c267-49e0-8dfd-5b182ff08d90}"

[HKCR\CLSID\{CAA1A27E-E33D-4D25-A24F-618D516FB671}]
"(Default)" = "SnapMyScreen_bf HTML Menu"

[HKLM\SOFTWARE\SnapMyScreen_bf\bar\Integrators]
"bfSrcAs.dll" = ""

[HKCR\CLSID\{bdffe389-a538-42f1-b36b-cbfb78e2d7fc}\ProgID]
"(Default)" = "SnapMyScreen_bf.ScriptButton.1"

[HKCR\Interface\{7E5AE580-3435-4D29-B7F3-2957102DBF65}\TypeLib]
"Version" = "1.0"

[HKLM\SOFTWARE\SnapMyScreen_bf\bar]
"PartnerPixelNotSet" = ""

[HKCR\Interface\{2F64F67F-3ADE-49FE-95D1-511667B1679A}\TypeLib]
"Version" = "1.0"

[HKLM\SOFTWARE\SnapMyScreen_bf\bar]
"hpwl" = ".mywebsearch.com,.google.com,.yahoo.com,.bing.com,.msn.com"
"PluginPath" = "%Program Files%\SnapMyScreen_bf\bar\1.bin\"

[HKCR\CLSID\{82c80e87-9daa-4b04-8455-aac9ea10f2b0}\TypeLib]
"(Default)" = "{efa0dfb6-66e5-4081-b607-bf6542818156}"

[HKCR\CLSID\{76ce4e76-6620-4ed3-9372-a4cf8b3b119f}\TypeLib]
"(Default)" = "{dd50941d-708b-4434-aba0-fdc9578513cf}"

[HKCR\CLSID\{b8d6859e-e323-412c-89ff-9b05d262749a}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\SnapMyScreen_bf.ToolbarProtector\CurVer]
"(Default)" = "SnapMyScreen_bf.ToolbarProtector.1"

[HKCR\SnapMyScreen_bf.SettingsPlugin\CLSID]
"(Default)" = "{f3b5e712-c267-49e0-8dfd-5b182ff08d90}"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SnapMyScreen_bfbar Uninstall Internet Explorer]
"HelpLink" = "http://support.mindspark.com/"

[HKCR\Interface\{491F0A4E-B416-4C15-8AC7-EC9305C816A8}]
"(Default)" = "ITemplateBarButtonRect"

[HKCR\Interface\{E18CB616-56DD-4C51-9C3A-71D637DEA5BE}\TypeLib]
"(Default)" = "{4BE1D37F-2316-4857-9B2F-A523883F38B8}"

[HKCR\Interface\{BD238C78-0312-4E81-B0F7-8E96D21FA57A}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\SnapMyScreen_bf.ToolbarProtector.1]
"(Default)" = "ProtectorControl Class"

[HKCR\Interface\{86B37BFC-233A-4D67-B3BA-60559DEBAF57}\TypeLib]
"(Default)" = "{26307A86-BF6D-485F-9859-875385C961D9}"

[HKCR\Interface\{E942057E-BFE8-493D-98DB-681B15EF8ABD}]
"(Default)" = "HTMLPANELEVENTS_INTERFACE"

[HKLM\SOFTWARE\SnapMyScreen_bf\bar]
"UninstallFFString" = "%Program Files%\SnapMyScreen_bf\bar\1.bin\bfhighin.exe bfbar.dll,O uninstalltype=FF"

[HKCR\Interface\{5E1904ED-A147-490E-A643-21A084E45B1C}\TypeLib]
"(Default)" = "{4BE1D37F-2316-4857-9B2F-A523883F38B8}"

[HKCR\Interface\{7E5AE580-3435-4D29-B7F3-2957102DBF65}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\CLSID\{56c33cec-cd9d-4656-8900-379b4bfe3190}\ProgID]
"(Default)" = "SnapMyScreen_bf.PseudoTransparentPlugin.1"

[HKCR\TypeLib\{26307A86-BF6D-485F-9859-875385C961D9}\1.0]
"(Default)" = "ToolbarProtector 1.0 Type Library"

[HKCR\TypeLib\{960B20A4-2C34-4AF8-B280-E45F9BE27500}\1.0]
"(Default)" = "DialogHook 1.0 Type Library"

[HKLM\SOFTWARE\SnapMyScreen_bf\bar]
"un" = "SnapMyScreen"

[HKCR\CLSID\{82c80e87-9daa-4b04-8455-aac9ea10f2b0}\VersionIndependentProgID]
"(Default)" = "SnapMyScreen_bf.FeedManager"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"Cookies" = "%Documents and Settings%\%current user%\Cookies"

[HKCR\TypeLib\{4BE1D37F-2316-4857-9B2F-A523883F38B8}\1.0\HELPDIR]
"(Default)" = "%Program Files%\SnapMyScreen_bf\bar\1.bin"

[HKLM\SOFTWARE\MozillaPlugins\@SnapMyScreen_bf.com/Plugin]
"Path" = "%Program Files%\SnapMyScreen_bf\bar\1.bin\NPbfStub.dll"

[HKCR\Interface\{14522BE0-421D-4804-BF47-883129E82ABB}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{86B37BFC-233A-4D67-B3BA-60559DEBAF57}]
"(Default)" = "IIEInstalledToolbar"

[HKCR\TypeLib\{7C34AB4E-65CE-4DFB-8F79-854A4AAF0AD1}\1.0\HELPDIR]
"(Default)" = "%Program Files%\SnapMyScreen_bf\bar\1.bin"

[HKLM\SOFTWARE\SnapMyScreen_bf\bar\Integrators]
"HPG.dll" = ""

[HKCR\SnapMyScreen_bf.ScriptButton\CLSID]
"(Default)" = "{bdffe389-a538-42f1-b36b-cbfb78e2d7fc}"

[HKCR\Interface\{64DEC467-9869-4695-BF50-4F5B76A0F10E}\ProxyStubClsid32]
"(Default)" = "{00020420-0000-0000-C000-000000000046}"

[HKCR\CLSID\{56c33cec-cd9d-4656-8900-379b4bfe3190}\TypeLib]
"(Default)" = "{e41a6f86-420f-45e2-9237-6aaa2c72380b}"

[HKCR\Interface\{4422543C-9F04-4E29-B29A-9E009F660ED8}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\CLSID\{76ce4e76-6620-4ed3-9372-a4cf8b3b119f}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Interface\{E942057E-BFE8-493D-98DB-681B15EF8ABD}\ProxyStubClsid]
"(Default)" = "{00020420-0000-0000-C000-000000000046}"

[HKCR\Interface\{F282368A-F145-4C0C-8691-B4DBF6DAEFCE}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "E1 7F 1F 31 2B 49 ED 07 B1 B1 F6 82 34 B1 17 0B"

[HKCR\Interface\{6807DB38-4598-4C86-AD26-444994F377D4}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\CLSID\{a7567cad-49ed-4aed-94a8-4dcc24895222}]
"(Default)" = ""

[HKCR\Interface\{ED5C7EBB-E72B-4333-A546-F4944D982C58}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\CLSID\{82c80e87-9daa-4b04-8455-aac9ea10f2b0}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\CLSID\{c4d86c62-bcee-4886-9fb9-34b1db677726}\ProgID]
"(Default)" = "SnapMyScreen_bf.ToolbarProtector.1"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SnapMyScreen_bfbar Uninstall Firefox]
"UninstallString" = "rundll32 %Program Files%\SnapMyScreen_bf\bar\1.bin\bfBar.dll,O mindsparktoolbarkey=SnapMyScreen_bf uninstalltype=FF"

[HKCR\CLSID\{bd3b52cc-c53d-49b5-bceb-84b18ec2f48d}\InprocServer32]
"(Default)" = "%Program Files%\SnapMyScreen_bf\bar\1.bin\bfdlghk.dll"

[HKCR\Interface\{F282368A-F145-4C0C-8691-B4DBF6DAEFCE}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
"AppData" = "%Documents and Settings%\%current user%\Application Data"

[HKCR\Interface\{BD238C78-0312-4E81-B0F7-8E96D21FA57A}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKLM\SOFTWARE\SnapMyScreen_bf\bar]
"lidate" = "2014-11-21T06:38:24Z"

[HKCR\Interface\{1500187C-0661-43B1-9765-AC0C01B0592E}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\CLSID\{f3b5e712-c267-49e0-8dfd-5b182ff08d90}\Version]
"(Default)" = "1.0"

[HKCR\CLSID\{76ce4e76-6620-4ed3-9372-a4cf8b3b119f}\VersionIndependentProgID]
"(Default)" = "SnapMyScreen_bf.ThirdPartyInstaller"

[HKCR\CLSID\{8032b822-5453-479b-ae28-47d2b62de44d}\InprocServer32]
"(Default)" = "%Program Files%\SnapMyScreen_bf\bar\1.bin\bfskin.dll"

[HKCR\TypeLib\{EFA0DFB6-66E5-4081-B607-BF6542818156}\1.0\0\win32]
"(Default)" = "%Program Files%\SnapMyScreen_bf\bar\1.bin\t8res.dll\1104"

[HKLM\SOFTWARE\SnapMyScreen_bf\bar]
"PID" = "^BPR"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1eab99ef-d357-4d1a-b347-ee231b4141c4}]
"AppPath" = "%Program Files%\SnapMyScreen_bf\bar\1.bin"

[HKCR\Interface\{6807DB38-4598-4C86-AD26-444994F377D4}\TypeLib]
"Version" = "1.0"

[HKCR\SnapMyScreen_bf.PseudoTransparentPlugin\CurVer]
"(Default)" = "SnapMyScreen_bf.PseudoTransparentPlugin.1"

[HKLM\SOFTWARE\SnapMyScreen_bf\bar]
"Visible" = "1"

[HKCR\SnapMyScreen_bf.HTMLMenu\CLSID]
"(Default)" = "{CAA1A27E-E33D-4D25-A24F-618D516FB671}"

[HKCR\Interface\{E942057E-BFE8-493D-98DB-681B15EF8ABD}\ProxyStubClsid32]
"(Default)" = "{00020420-0000-0000-C000-000000000046}"

[HKCR\Interface\{64DEC467-9869-4695-BF50-4F5B76A0F10E}]
"(Default)" = "_IThirdPartyInstallerEvents"

[HKCR\Interface\{80385B90-FB28-4942-9E64-07653DB82859}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{D61A691F-FCC2-4B11-9D2B-FDBDE39BE8CF}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{14522BE0-421D-4804-BF47-883129E82ABB}]
"(Default)" = "SEARCHSCOPE_INTERFACE"

[HKCR\Interface\{88521B9F-6F51-479B-990D-04FFC83453C0}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{1500187C-0661-43B1-9765-AC0C01B0592E}]
"(Default)" = "HTMLPANEL_INTERFACE"

[HKCR\CLSID\{bd3b52cc-c53d-49b5-bceb-84b18ec2f48d}\TypeLib]
"(Default)" = "{960b20a4-2c34-4af8-b280-e45f9be27500}"

[HKCR\TypeLib\{960B20A4-2C34-4AF8-B280-E45F9BE27500}\1.0\FLAGS]
"(Default)" = "0"

[HKCR\Interface\{B1C3A46D-8934-4338-9D0D-68560227C984}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\Interface\{14522BE0-421D-4804-BF47-883129E82ABB}\TypeLib]
"(Default)" = "{AA398903-C818-4EEA-92D4-44AE17838787}"

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{f3b5e712-c267-49e0-8dfd-5b182ff08d90}]
"(Default)" = ""

[HKCR\Interface\{E259193B-1D00-42A0-8E66-87DFE3EE0BA5}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\TypeLib\{7C34AB4E-65CE-4DFB-8F79-854A4AAF0AD1}\1.0\0\win32]
"(Default)" = "%Program Files%\SnapMyScreen_bf\bar\1.bin\t8res.dll\1604"

[HKCR\CLSID\{f3b5e712-c267-49e0-8dfd-5b182ff08d90}]
"(Default)" = ""

[HKCR\Interface\{E24A46F2-943A-4E2B-ACF2-2EFF4D8250FA}\TypeLib]
"(Default)" = "{26307A86-BF6D-485F-9859-875385C961D9}"

[HKCR\Interface\{1A327208-15F5-4C84-BB37-AEFDB2E5B049}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKCR\SnapMyScreen_bf.SettingsPlugin]
"(Default)" = ""

[HKCR\CLSID\{56c33cec-cd9d-4656-8900-379b4bfe3190}\MiscStatus\1]
"(Default)" = "131473"

[HKCR\CLSID\{aec668ad-ff7e-46b9-b11f-4a6b297e4cd2}\TypeLib]
"(Default)" = "{4be1d37f-2316-4857-9b2f-a523883f38b8}"

[HKCR\Interface\{292C13FB-0482-4E57-91C6-A23FBD80BB54}\TypeLib]
"Version" = "1.0"

[HKCR\Interface\{ED5C7EBB-E72B-4333-A546-F4944D982C58}\ProxyStubClsid]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{755052ba-d5fd-4152-ab3e-db447a9d9ec8}]
"Policy" = "3"

[HKLM\SOFTWARE\SnapMyScreen_bf\bar\Switches]
"oldhpp" = "0"

[HKCR\CLSID\{9646c642-4bbc-49b9-b332-f1073541e3e1}\MiscStatus\1]
"(Default)" = "131473"

[HKCR\Interface\{88521B9F-6F51-479B-990D-04FFC83453C0}\ProxyStubClsid32]
"(Default)" = "{00020424-0000-0000-C000-000000000046}"

[HKLM\SOFTWARE\SnapMyScreen_bf\bar]
"ID" = "967E522A-9B16-4D29-93FD-65B8BCEADD49"

[HKCR\CLSID\{56c33cec-cd9d-4656-8900-379b4bfe3190}\InprocServer32]
"ThreadingModel" = "Apartment"

[HKCR\Interface\{D61A691F-FCC2-4B11-9D2B-FDBDE39BE8CF}]
"(Default)" = "BARFEEDMANAGER_INTERFACE"

[HKCR\CLSID\{6c7b31f7-a830-4c86-a7a1-b2e1b1253547}\MiscStatus\1]
"(Default)" = "131473"

[HKCR\TypeLib\{AA398903-C818-4EEA-92D4-44AE17838787}\1.0\0\win32]
"(Default)" = "%Program Files%\SnapMyScreen_bf\bar\1.bin\t8res.dll\626"

[HKCR\Interface\{80385B90-FB28-4942-9E64-07653DB82859}]
"(Default)" = "IIEInstalledToolbars"

[HKCR\TypeLib\{DD50941D-708B-4434-ABA0-FDC9578513CF}\1.0\HELPDIR]
"(Default)" = "%Program Files%\SnapMyScreen_bf\bar\1.bin"

[HKCR\Interface\{1405C496-0E77-453D-A629-A2D45E2C5BAC}]
"(Default)" = "ITemplateBarControl"

[HKLM\SOFTWARE\SnapMyScreen_bf\bar]
"HomePage" = "http://home.tb.ask.com/index.jhtml?n=780CE96C&p2=^BPR&ptb=967E522A-9B16-4D29-93FD-65B8BCEADD49"

[HKCR\SnapMyScreen_bf.ToolbarProtector.1\CLSID]
"(Default)" = "{c4d86c62-bcee-4886-9fb9-34b1db677726}"

[HKCR\Interface\{E259193B-1D00-42A0-8E66-87DFE3EE0BA5}\TypeLib]
"Version" = "1.0"

[HKCR\CLSID\{76ce4e76-6620-4ed3-9372-a4cf8b3b119f}\ProgID]
"(Default)" = "SnapMyScreen_bf.ThirdPartyInstaller.1"

[HKCR\SnapMyScreen_bf.ScriptButton.1\CLSID]
"(Default)" = "{bdffe389-a538-42f1-b36b-cbfb78e2d7fc}"

[HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{6b1c6575-d21f-4902-a026-09c119c0c87e}" = ""

[HKCR\CLSID\{CAA1A27E-E33D-4D25-A24F-618D516FB671}\InprocServer32]
"(Default)" = "%Program Files%\SnapMyScreen_bf\bar\1.bin\bfhtmlmu.dll"

[HKCR\SnapMyScreen_bf.FeedManager\CLSID]
"(Default)" = "{82c80e87-9daa-4b04-8455-aac9ea10f2b0}"

[HKCR\SnapMyScreen_bf.ThirdPartyInstaller.1]
"(Default)" = "SnapMyScreen Third Party Installer"

[HKCR\CLSID\{56c33cec-cd9d-4656-8900-379b4bfe3190}\MiscStatus]
"(Default)" = "0"

To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SnapMyScreen AppIntegrator 32-bit" = "C:\PROGRA~1\SNAPMY~1\bar\1.bin\AppIntegrator.exe"

"SnapMyScreen" = "rundll32 C:\PROGRA~1\SNAPMY~1\bar\1.bin\bfbar.dll,S"

The Trojan modifies IE settings for security zones to map all web-nodes that bypassing the proxy to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"ProxyBypass" = "1"

The Trojan modifies IE settings for security zones to map all urls to the Intranet Zone:

"IntranetName" = "1"

It registers itself as a Browser Helper Object (BHO) to ensure its automatic execution every time Internet Explorer is run. It does this by creating the following registry key(s)/entry(ies):

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2bd24259-5294-4e0d-8469-27ce1158c272}]
"(Default)" = ""

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3e991f5f-77b8-4e48-ba4e-7ba426ffb036}]
"(Default)" = ""

The Trojan modifies IE settings for security zones to map all local web-nodes with no dots which do not refer to any zone to the Intranet Zone:

[HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap]
"UNCAsIntranet" = "1"

To automatically run itself each time Windows is booted, the Trojan adds the following link to its file to the system registry autorun key:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SnapMyScreen Search Scope Monitor" = "C:\PROGRA~1\SNAPMY~1\bar\1.bin\bfsrchmn.exe /m=2 /w /h"

The Trojan deletes the following registry key(s):

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2bd24259-5294-4e0d-8469-27ce1158c272}]

The Trojan deletes the following value(s) in system registry:

[HKLM\SOFTWARE\SnapMyScreen_bf\bar]
"pid2"
"un"

[HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"

[HKLM\SOFTWARE\SnapMyScreen_bf\bar]
"ConfigDateStamp"

The Trojan disables automatic startup of the application by deleting the following autorun value:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SnapMyScreen Search Scope Monitor"

The process bfbarsvc.exe:572 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "8A 6C C3 01 F4 5E 96 78 D8 4B E9 F8 0C 88 F6 A4"

The process bfbarsvc.exe:1760 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "07 41 C7 C0 E5 63 9D 79 4A 09 2D F9 42 6D 8C 3E"

The process bfbarsvc.exe:1356 makes changes in the system registry.
The Trojan creates and/or sets the following values in system registry:

[HKLM\SOFTWARE\Microsoft\Cryptography\RNG]
"Seed" = "2D EF 14 3C 19 7E AE 6A 0B EF 01 99 CA ED 5E 4A"

Dropped PE files

MD5 File path
829fa28b94408ac5e8879200f885c725 c:\Program Files\Mindspark\SnapMyScreen\DesktopSdk.dll
019fe9b850626d5f7cd4e8faf33f296a c:\Program Files\Mindspark\SnapMyScreen\Microsoft.Expression.Interactions.dll
30b35c8547e5f761466386aafdb5fcd2 c:\Program Files\Mindspark\SnapMyScreen\RebootRequired.exe
0f6f8ac021a0a8c74f63015a9d1785aa c:\Program Files\Mindspark\SnapMyScreen\SnapMyScreen.exe
159238c2317ccb093c9c1f7ba422a485 c:\Program Files\Mindspark\SnapMyScreen\System.Windows.Interactivity.dll
dc31c5da81b5d896db1a4a1f8e6bf22c c:\Program Files\Mindspark\SnapMyScreen\UnifiedLogging.dll
8c0b6838878f3dd76135f999ddb1c900 c:\Program Files\Mindspark\SnapMyScreen\lua5.1.dll
6a51b27331dd032e718cc4834152f439 c:\Program Files\Mindspark\SnapMyScreen\uninstall.exe
10f7e914cee5636179838d7f7f976b5a c:\Program Files\SnapMyScreen_bf\bar\1.bin\APPINTEGRATOR.EXE
184f78c50bcc6c2319d56963552f2b7b c:\Program Files\SnapMyScreen_bf\bar\1.bin\APPINTEGRATORSTUB.DLL
29b69b9f0c61ae41100870500a65d219 c:\Program Files\SnapMyScreen_bf\bar\1.bin\ASSISTMONITOR.DLL
82cb70126e6223a63316b71f4cc13976 c:\Program Files\SnapMyScreen_bf\bar\1.bin\ASSISTMONITOR64.DLL
aec7ac415e570fa2566769bfbcbc7fd0 c:\Program Files\SnapMyScreen_bf\bar\1.bin\AppIntegrator64.exe
61568320cac2d0868928f9364a565b1a c:\Program Files\SnapMyScreen_bf\bar\1.bin\AppIntegratorStub64.dll
b096c32156bcd51f33e0e7f12a90e304 c:\Program Files\SnapMyScreen_bf\bar\1.bin\CREXT.DLL
9526b7e071abdd76002bbdbb21beb726 c:\Program Files\SnapMyScreen_bf\bar\1.bin\CrExtPbf.exe
4d346cd5b9d4d5be83563bc7d4af0e5c c:\Program Files\SnapMyScreen_bf\bar\1.bin\DPNMNGR.DLL
cc8978a1e61f9b95e99a5cd16aa901f9 c:\Program Files\SnapMyScreen_bf\bar\1.bin\FF-NativeMessagingDispatcher.dll
12706849799668a9a88480249b98f060 c:\Program Files\SnapMyScreen_bf\bar\1.bin\HKFXMGR.DLL
e533043cb8fdb1c96839f22e046c2f20 c:\Program Files\SnapMyScreen_bf\bar\1.bin\HKFXMGR64.DLL
186159381df948b37bfc3bbdb4fd991a c:\Program Files\SnapMyScreen_bf\bar\1.bin\HPG.DLL
2bd149504e2890da76ddf3e6a891c5cf c:\Program Files\SnapMyScreen_bf\bar\1.bin\Hpg64.dll
444e9d42e6cb5e3a90680232b4c5dd3b c:\Program Files\SnapMyScreen_bf\bar\1.bin\T8EPMSUP.DLL
abf98ad68d32356d85417b3907617250 c:\Program Files\SnapMyScreen_bf\bar\1.bin\T8EXTEX.DLL
2b203ef9ed024561e563062fc0d53dc0 c:\Program Files\SnapMyScreen_bf\bar\1.bin\T8EXTPEX.DLL
45d1827ce4abc76965688771b44771d5 c:\Program Files\SnapMyScreen_bf\bar\1.bin\T8HTML.DLL
ec89b2475cfdff54af9e04daf1020300 c:\Program Files\SnapMyScreen_bf\bar\1.bin\T8RES.DLL
391e0a8c28c520a3c131c95f9f07bbe9 c:\Program Files\SnapMyScreen_bf\bar\1.bin\T8TICKER.DLL
5cfde1c7f0a7a974dd610a8bdff23577 c:\Program Files\SnapMyScreen_bf\bar\1.bin\TOOLBARGUARD.DLL
f2248d813ae3e7c0a53f395a1485b93a c:\Program Files\SnapMyScreen_bf\bar\1.bin\TOOLBARGUARD64.DLL
3ecba52f221d561e99f23a9e9d3e45e3 c:\Program Files\SnapMyScreen_bf\bar\1.bin\TPIMANAGERCONSOLE.EXE
2f143f9d838217a4db883e8e4e8b5234 c:\Program Files\SnapMyScreen_bf\bar\1.bin\VERIFY.DLL
9bc04e8e818cdb85b2f0b2ffd8cb78dd c:\Program Files\SnapMyScreen_bf\bar\1.bin\assists\ie_default_search_provider\ARBITER.DLL
c2af09bff7579b4bf81fa8ae227b15eb c:\Program Files\SnapMyScreen_bf\bar\1.bin\assists\ie_default_search_provider\ARBITER64.DLL
7e0e289b1cf9eea5440162efcebe151b c:\Program Files\SnapMyScreen_bf\bar\1.bin\assists\ie_default_search_provider\ASSIST.EXE
e8994129fe701fb4dcb2ae5f3c65f4cc c:\Program Files\SnapMyScreen_bf\bar\1.bin\assists\ie_enable\ARBITER.DLL
0c42f8320a4f8b87b50acd2c3c987d1e c:\Program Files\SnapMyScreen_bf\bar\1.bin\assists\ie_enable\ARBITER64.DLL
ccbfb0fb6a1771a6851512c824175a8d c:\Program Files\SnapMyScreen_bf\bar\1.bin\bfPlugin.dll
3b80c3828554d878ba5b06f8bee6c241 c:\Program Files\SnapMyScreen_bf\bar\1.bin\bfSrcAs.dll
13dff983da8cf08a88f6d483e14d01e1 c:\Program Files\SnapMyScreen_bf\bar\1.bin\bfbar.dll
a629f8db2fe3f86b2b3b369ca2d22ead c:\Program Files\SnapMyScreen_bf\bar\1.bin\bfbarsvc.exe
aff3aab6d2bc9776ef16b7e310f200f8 c:\Program Files\SnapMyScreen_bf\bar\1.bin\bfbprtct.dll
99cd66b4fc8a4da919615cb00358cd89 c:\Program Files\SnapMyScreen_bf\bar\1.bin\bfdatact.dll
678d96f39fc4511c078ae18eedda725a c:\Program Files\SnapMyScreen_bf\bar\1.bin\bfdlghk.dll
47c3d4b1ec799f2410d5c4db3150830c c:\Program Files\SnapMyScreen_bf\bar\1.bin\bfdlghk64.dll
56c388f118e47a46e55c78653bf2ae8a c:\Program Files\SnapMyScreen_bf\bar\1.bin\bffeedmg.dll
9a56a71b3092fcceb6f3ccb45abad7de c:\Program Files\SnapMyScreen_bf\bar\1.bin\bfhighin.exe
78f4e5e669f4c0e4d2ab71f432b4f25b c:\Program Files\SnapMyScreen_bf\bar\1.bin\bfhkstub.dll
a28971193059661e64d84eea069331dd c:\Program Files\SnapMyScreen_bf\bar\1.bin\bfhtmlmu.dll
4548cae3d2b5256449a777aac73cc253 c:\Program Files\SnapMyScreen_bf\bar\1.bin\bfhttpct.dll
1ddc5cffd155ae909c751e4a0104d974 c:\Program Files\SnapMyScreen_bf\bar\1.bin\bfidle.dll
0eb5c27740d39b28e407e25f74a2f23a c:\Program Files\SnapMyScreen_bf\bar\1.bin\bfmedint.exe
6dfe507877f8f11f70dd6db55553a165 c:\Program Files\SnapMyScreen_bf\bar\1.bin\bfmlbtn.dll
d05813d47c423da1b8cf674cd1137d59 c:\Program Files\SnapMyScreen_bf\bar\1.bin\bfregfft.dll
ebfc2a20a4a3fbe4cd4468f57ba63e1e c:\Program Files\SnapMyScreen_bf\bar\1.bin\bfreghk.dll
8491754a8000a9265cda69a407f99b0c c:\Program Files\SnapMyScreen_bf\bar\1.bin\bfregiet.dll
cd848ca77df8282a0a4778414808154c c:\Program Files\SnapMyScreen_bf\bar\1.bin\bfscript.dll
8d0d0ae3e70363239e19c2da171558a7 c:\Program Files\SnapMyScreen_bf\bar\1.bin\bfskin.dll
cc079d45f96c2ca37f5d938ab437e985 c:\Program Files\SnapMyScreen_bf\bar\1.bin\bfskplay.exe
cf0646bb879911192c833e314e0afc57 c:\Program Files\SnapMyScreen_bf\bar\1.bin\bftpinst.dll

HOSTS file anomalies

No changes have been detected.

Rootkit activity

No anomalies have been detected.

Propagation

VersionInfo

Company Name: SnapMyScreen
Product Name: SnapMyScreen
Product Version: 2, 0, 5, 6
Legal Copyright: Copyright (c) 2009 - 2014
Legal Trademarks:
Original Filename: bfSetup.exe
Internal Name: bfSetup
File Version: 2, 0, 5, 6
File Description: SnapMyScreen
Comments:
Language: Language Neutral

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Section MD5
.text 4096 7790 8192 4.27339 e28848bc1d5d86f7e6683c7388b6f4e3
.rdata 12288 8748 12288 1.89074 6c48bc22212ce6c4e7e014775c9ae310
.data 24576 2126 4096 1.23459 127a1c017e832f6561d566d553bda6a7
.rsrc 28672 5786104 5787648 5.35677 5441eeb5e77a09e971c7954ca8bab033

Dropped from:

Downloaded by:

Similar by SSDeep:

Similar by Lavasoft Polymorphic Checker:

URLs

URL IP
hxxp://a1983.g2.akamai.net/images/nocache/vicinio/executable-packages/SnapMyScreen/1406840480131/SnapMyScreenSetup.exe
hxxp://e6845.ce.akamaiedge.net/pca3-g5.crl
hxxp://e6845.ce.akamaiedge.net/CSC3-2010.crl
hxxp://e6845.ce.akamaiedge.net/ThawteTimestampingCA.crl
hxxp://e6845.ce.akamaiedge.net/tss-ca-g2.crl
hxxp://www187.mindspark.com/xt8a.gif?installationResult=Success&dotNetVersionInstalled=&dotNetExistingVersion=4.0.30319&product=SnapMyScreen&anxe=Install&osDetail=5.1&defaultBrowser=IEXPLORE.EXE&anxd=2014-07-31&anxv=1.0.7907.151&anxa=ProductInstaller&osArchitecture=32
hxxp://www187.mindspark.com/tr.gif?anxa=SnapMyScreen&anxv=1.0.7907.151&result=Success&time=2531&totalTime=-1&dotnet=v2.1.21022/sp1;v3.1.21022/sp1;v3.5.21022.08/sp0;v4.0.30319/sp-/Client;&gpu=0&os=5.1.2600.196608:Service Pack 3&is64bitos=False&totalMemory=536330240&availableMemory=278515712&cpuCount=1&monitorCount=1&anxe=AppStartup&
hxxp://anx.mindspark.com/xt8a.gif?installationResult=Success&dotNetVersionInstalled=&dotNetExistingVersion=4.0.30319&product=SnapMyScreen&anxe=Install&osDetail=5.1&defaultBrowser=IEXPLORE.EXE&anxd=2014-07-31&anxv=1.0.7907.151&anxa=ProductInstaller&osArchitecture=32 74.113.233.187
hxxp://ak.dl.snapmyscreen.com/images/nocache/vicinio/executable-packages/SnapMyScreen/1406840480131/SnapMyScreenSetup.exe 23.15.4.19
hxxp://csc3-2010-crl.verisign.com/CSC3-2010.crl 23.50.69.163
hxxp://ts-crl.ws.symantec.com/tss-ca-g2.crl 23.50.69.163
hxxp://crl.verisign.com/pca3-g5.crl 23.50.69.163
hxxp://crl.thawte.com/ThawteTimestampingCA.crl 23.50.69.163


IDS verdicts (Suricata alerts: Emerging Threats ET ruleset)

ET TROJAN VMProtect Packed Binary Inbound via HTTP - Likely Hostile
ET SHELLCODE Possible TCP x86 JMP to CALL Shellcode Detected

Traffic

GET /CSC3-2010.crl HTTP/1.1
Accept: */*
User-Agent: Microsoft-CryptoAPI/5.131.2600.5512
Host: csc3-2010-crl.verisign.com
Connection: Keep-Alive
Cache-Control: no-cache
Pragma: no-cache


HTTP/1.1 200 OK
Server: Apache
ETag: "c69b4a4010dba5350df47deb8b1e7698:1416522320"
Last-Modified: Thu, 20 Nov 2014 22:25:20 GMT
Date: Fri, 21 Nov 2014 06:38:47 GMT
Transfer-Encoding:  chunked
Connection: keep-alive
Connection: Transfer-Encoding
Content-Type: application/pkix-crl
00006000..0..%.0..#....0...*.H........0..1.0...U....US1.0...U....VeriS
ign, Inc.1.0...U....VeriSign Trust Network1;09..U...2Terms of use at h
ttps://VVV.verisign.com/rpa (c)101.0,..U...%VeriSign Class 3 Code Sign
ing 2010 CA..141120222131Z..141204222131Z0.."[email protected]
0730092631Z0!....c..k....D.k.....120708062201Z0!... _...u.t.=.<.&..
.130218061114Z0!...&..].....P.k.:...120125130117Z0!...7P.x....8.Q...s.
.130227010252Z0!...J.....Q..Y.[.....110404153956Z0!...d...=..q!_...g9.
.130729145216Z0!...d....Y.......o...140711083257Z0!...l.....h2<.H..
....120329152211Z0!...q.9...`H.*.Y.C...120525202212Z0!...s...TM.......
0...121221080842Z0!...t..,.. ...eL.....130314222305Z0!...y..r.HW.v....
.w..140423054643Z0!..../u.......A..5...101214165045Z0!.....0.Xc...%...
iM..121102230226Z0!.......S.a&.X5t.E]..111206083350Z0!....c.(....B.[M8
3...140108164517Z0!....A.Sv.....f,.....110609003155Z0!.....z......!.ID
{]..101228182208Z0!....b^......{d.J'...130102154110Z0!.......n........
'u..140521222808Z0!......0..........I..130912181631Z0!.....1.;C,.. L..
0...141111073655Z0!....6e...~..T.......130131012247Z0!.....|.....t.l.o
....140827175301Z0!.........bD#*u......130226223939Z0!.......@..'$.).;
}\..130121172259Z0!....7.v..........n..120724160733Z0!....P;.Y..d...c.
(...120209181451Z0!.....].bb[.....!....140328205453Z0!.....a...L`..IV.
[email protected]!...........].{7.
....120730000000Z0!...".......Z.V.,.e..121031192224Z0!...'....[.1.....
.g..130318195659Z0!...,GI.jH.|...J.....120518121623Z0!...<%a.=.

<<< skipped >>>

GET /tss-ca-g2.crl HTTP/1.1
Accept: */*
User-Agent: Microsoft-CryptoAPI/5.131.2600.5512
Host: ts-crl.ws.symantec.com
Connection: Keep-Alive
Cache-Control: no-cache
Pragma: no-cache


HTTP/1.1 200 OK
Server: Apache
ETag: "f7cf7f17c92630fedd8eed37a53c5bd8:1416522428"
Last-Modified: Thu, 20 Nov 2014 22:27:08 GMT
Date: Fri, 21 Nov 2014 06:38:49 GMT
Content-Length: 477
Connection: keep-alive
Content-Type: application/pkix-crl
0...0.....0...*.H........0^1.0...U....US1.0...U....Symantec Corporatio
n100...U...'Symantec Time Stamping Services CA - G2..141120222228Z..14
1130222228Z.00.0...U.#..0..._..n\..t...}.?..L...0...U........0...*.H..
...........`.uhn.......#P...>]~....J.......e.[bB..L...OY.K.........
.]u.......cV......;K..~.....G.'....~...M2...M|k~..P.....{!.}~a...T....
%......'..4|.u..u3......{m..a............x).[t.......I8-.._.\....V"...
$...ee4.7B...]_$Y.~~h......|..5...O.;[..l..lbo3....H...M.2..HTTP/1.1 2
00 OK..Server: Apache..ETag: "f7cf7f17c92630fedd8eed37a53c5bd8:1416522
428"..Last-Modified: Thu, 20 Nov 2014 22:27:08 GMT..Date: Fri, 21 Nov
2014 06:38:49 GMT..Content-Length: 477..Connection: keep-alive..Conten
t-Type: application/pkix-crl..0...0.....0...*.H........0^1.0...U....US
1.0...U....Symantec Corporation100...U...'Symantec Time Stamping Servi
ces CA - G2..141120222228Z..141130222228Z.00.0...U.#..0..._..n\..t...}
.?..L...0...U........0...*.H.............`.uhn.......#P...>]~....J.
......e.[bB..L...OY.K..........]u.......cV......;K..~.....G.'....~...M
2...M|k~..P.....{!.}~a...T....%......'..4|.u..u3......{m..a...........
.x).[t.......I8-.._.\....V"...$...ee4.7B...]_$Y.~~h......|..5...O.;[..
l..lbo3....H...M.2....


GET /xt8a.gif?installationResult=Success&dotNetVersionInstalled=&dotNetExistingVersion=4.0.30319&product=SnapMyScreen&anxe=Install&osDetail=5.1&defaultBrowser=IEXPLORE.EXE&anxd=2014-07-31&anxv=1.0.7907.151&anxa=ProductInstaller&osArchitecture=32 HTTP/1.1
Accept: */*
Content-Type: application/x-www-form-urlencoded
User-Agent: Setup Factory 8.0
Host: anx.mindspark.com
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 204 No Content
Server: nginx/1.0.10
Date: Fri, 21 Nov 2014 06:38:51 GMT
Connection: close
Expires: Thu, 01 Jan 1970 00:00:01 GMT
Cache-Control: no-cache
Cache-Control: max-age=0


GET /pca3-g5.crl HTTP/1.1
Accept: */*
User-Agent: Microsoft-CryptoAPI/5.131.2600.5512
Host: crl.verisign.com
Connection: Keep-Alive
Cache-Control: no-cache
Pragma: no-cache


HTTP/1.1 200 OK
Server: Apache
ETag: "bd6753109994fa1bef1833b34f3e263b:1411514416"
Last-Modified: Tue, 23 Sep 2014 23:20:16 GMT
Date: Fri, 21 Nov 2014 06:38:46 GMT
Content-Length: 533
Connection: keep-alive
Content-Type: application/pkix-crl
0...0..0...*.H........0..1.0...U....US1.0...U....VeriSign, Inc.1.0...U
....VeriSign Trust Network1:08..U...1(c) 2006 VeriSign, Inc. - For aut
horized use only1E0C..U...<VeriSign Class 3 Public Primary Certific
ation Authority - G5..140922000000Z..141231235959Z0...*.H.............
O...i.i(.#..s.T....F....${|...xLT.k...(....AC.#.....Y.Ht..}.n..* ...b.
Gs...G..N.|2*.9l....\..H.Y....Wh. .....A.......?/...}.......z.Q..qP_.-
..~......!.UBW...ER..6....:.p...[...../..h...9.J(..<.;i.......?c.I.
t....LV.uD....B..z...~I .6..aR[..(..q............HTTP/1.1 200 OK..Serv
er: Apache..ETag: "bd6753109994fa1bef1833b34f3e263b:1411514416"..Last-
Modified: Tue, 23 Sep 2014 23:20:16 GMT..Date: Fri, 21 Nov 2014 06:38:
46 GMT..Content-Length: 533..Connection: keep-alive..Content-Type: app
lication/pkix-crl..0...0..0...*.H........0..1.0...U....US1.0...U....Ve
riSign, Inc.1.0...U....VeriSign Trust Network1:08..U...1(c) 2006 VeriS
ign, Inc. - For authorized use only1E0C..U...<VeriSign Class 3 Publ
ic Primary Certification Authority - G5..140922000000Z..141231235959Z0
...*.H.............O...i.i(.#..s.T....F....${|...xLT.k...(....AC.#....
.Y.Ht..}.n..* ...b.Gs...G..N.|2*.9l....\..H.Y....Wh. .....A.......?/..
.}.......z.Q..qP_.-..~......!.UBW...ER..6....:.p...[...../..h...9.J(..
<.;i.......?c.I.t....LV.uD....B..z...~I .6..aR[..(..q..............

<<< skipped >>>

GET /images/nocache/vicinio/executable-packages/SnapMyScreen/1406840480131/SnapMyScreenSetup.exe HTTP/1.1
Accept: */*
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET4.0C)
Host: ak.dl.snapmyscreen.com
Connection: Keep-Alive
Cache-Control: no-cache


HTTP/1.1 200 OK
Server: Apache
Last-Modified: Thu, 31 Jul 2014 21:01:23 GMT
ETag: "113904-32e980-4ff839345e1d1"
Accept-Ranges: bytes
Content-Length: 3336576
Cache-Control: max-age=305648565
Expires: Sat 02 Apr 1977 17:15:00 GMT
Pragma: no-cache
Content-Type: application/x-msdownload
Date: Fri, 21 Nov 2014 06:38:37 GMT
Connection: keep-alive
MZ......................@.............................................
..!..L.!This program cannot be run in DOS mode....$.........2...\...\.
..\..'....\..'....\.......\...]...\..'....\..'....\..'....\.Rich..\...
......PE..L......R.................X...........).......p....@.........
.................P........2...@.................................<..
.d........n.......... .2.`....0.......................................
...@............p..x............................text....W.......X.....
............. ..`.rdata.......p...0...\..............@[email protected]....
[email protected]..................@[email protected]
[email protected].................................
......................................................................
......................................................................
......................................................................
......................................................................
...............................................U...X......... [email protected].
SVW.}[email protected]@.P..hq@........`........V......SP.......Pp@..
..W..;.}[email protected][email protected]...
@..4.......P...p@......./ub......<Tt"<Wt.<tt.<wuL......P..
...u>.......6......P.....~(......:u....~....P......P......P........
[email protected]@[email protected];[email protected].
[email protected]@........u....M._..^3.[.........V..W3.h..
[email protected].....<[email protected]

<<< skipped >>>

GET /ThawteTimestampingCA.crl HTTP/1.1
Accept: */*
User-Agent: Microsoft-CryptoAPI/5.131.2600.5512
Host: crl.thawte.com
Connection: Keep-Alive
Cache-Control: no-cache
Pragma: no-cache


HTTP/1.1 200 OK
Server: Apache
ETag: "075003e67d35591a801778336e66e994:1411607711"
Last-Modified: Thu, 25 Sep 2014 01:15:11 GMT
Date: Fri, 21 Nov 2014 06:38:48 GMT
Content-Length: 341
Connection: keep-alive
Content-Type: application/pkix-crl
0..Q0..0...*.H........0..1.0...U....ZA1.0...U....Western Cape1.0...U..
..Durbanville1.0...U....Thawte1.0...U....Thawte Certification1.0...U..
..Thawte Timestamping CA..140922000000Z..141231235959Z0...*.H.........
......z ...H.....h.......>V......<...Y*.4..m.P{w.yN.*..rH....o7.
_..B.H..$O......D(..Or..E..e3....XR.#!1.5j.h..p......<.#..:.FI..l?.
HTTP/1.1 200 OK..Server: Apache..ETag: "075003e67d35591a801778336e66e9
94:1411607711"..Last-Modified: Thu, 25 Sep 2014 01:15:11 GMT..Date: Fr
i, 21 Nov 2014 06:38:48 GMT..Content-Length: 341..Connection: keep-ali
ve..Content-Type: application/pkix-crl..0..Q0..0...*.H........0..1.0..
.U....ZA1.0...U....Western Cape1.0...U....Durbanville1.0...U....Thawte
1.0...U....Thawte Certification1.0...U....Thawte Timestamping CA..1409
22000000Z..141231235959Z0...*.H...............z ...H.....h.......>V
......<...Y*.4..m.P{w.yN.*..rH....o7._..B.H..$O......D(..Or..E..e3.
...XR.#!1.5j.h..p......<.#..:.FI..l?...


The Trojan connects to the servers at the folowing location(s):

AppIntegrator.exe_1944:

.text
`.rdata
@.data
.rsrc
@.reloc
operator
GetProcessWindowStation
SHELL32.dll
Visual C   CRT: Not enough memory to complete call to strerror.
Broken pipe
Inappropriate I/O control operation
Operation not permitted
MaxPolicyElementKey
AppIntegrator.cpp
IAC::AppIntegrator::Application::SetupWindowsHook
C   Exception thrown in %s: %s
ATL Exception thrown in %s: 0xX
Unknown exception thrown in %s
RegOpenKeyTransactedW
E:\TeamCity\BuildAgent1\work\e76829348a1f1718\Projects\ChromeExtAPI_Dev2\Build.TT\Release.x86\AppIntegrator.pdb
KERNEL32.dll
MsgWaitForMultipleObjects
SetWindowsHookExW
UnhookWindowsHookEx
USER32.dll
RegOpenKeyExW
RegCloseKey
RegCreateKeyExW
ADVAPI32.dll
ole32.dll
SHRegOpenUSKeyW
SHRegCloseUSKey
SHRegCreateUSKeyW
SHLWAPI.dll
USERENV.dll
VERSION.dll
GetProcessHeap
GetCPInfo
AppIntegrator.exe
zcÁ
.?AV?$_Impl_no_alloc2@U?$_Callable_obj@V<lambda14>@?A0xbc07b221@AppIntegrator@IAC@@$0A@@tr1@std@@_NABVCRegKey@ATL@@PB_W@tr1@std@@
.?AV?$_Impl_no_alloc1@U?$_Callable_obj@V<lambda5>@?A0xbc07b221@AppIntegrator@IAC@@$0A@@tr1@std@@KAAV?$_Vector_const_iterator@V?$_Vector_val@V?$CStringT@_WV?$StrTraitATL@_WV?$ChTraitsCRT@_W@ATL@@@ATL@@@ATL@@V?$allocator@V?$CStringT@_WV?$StrTraitATL@_WV?$ChTraitsCRT@_W@ATL@@@ATL@@@ATL@@@std@@@std@@@3@@tr1@std@@
.?AV?$_Impl_base2@_NABVCRegKey@ATL@@PB_W@tr1@std@@
.?AV?$_Impl_base1@KAAV?$_Vector_const_iterator@V?$_Vector_val@V?$CStringT@_WV?$StrTraitATL@_WV?$ChTraitsCRT@_W@ATL@@@ATL@@@ATL@@V?$allocator@V?$CStringT@_WV?$StrTraitATL@_WV?$ChTraitsCRT@_W@ATL@@@ATL@@@ATL@@@std@@@std@@@std@@@tr1@std@@
cOXY/P.Z0.0.QR00/ZPP0000000/0PPZR.BI@/DE0,
< =/=8=\=
>$>,>4><>
6 6$6(6,606
2 2@2\2`2
mscoree.dll
- Attempt to initialize the CRT more than once.
- CRT not initialized
- floating point support not loaded
KERNEL32.DLL
WUSER32.DLL
ieframe.dll
g%s:AppIntegratorShutdown
Already running! %s
The %s event cannot be created (%u)
\AppIntegratorStub.dll
Error calling GetProcAddress %u
Error calling SetWindowsHookEx %u
Failed to enable heap terminate-on-corruption with LastError %u
Error: %S
Error: 0x%0x
TraceLogUnitTest.exe
TraceLog.cfg
).csv
\StringFileInfo\XX\OriginalFilename
@t8res.dll
Advapi32.dll
C:\PROGRA~1\SNAPMY~1\bar\1.bin\AppIntegrator.exe
C:\PROGRA~1\SNAPMY~1\bar\1.bin
@C:\PROGRA~1\SNAPMY~1\bar\1.bin\AppIntegrator.exe
1.0.7.235
2.5.15.2

mscorsvw.exe_2116:

.text
`.data
.rsrc
@.reloc
EX_CATCH line %d
CACHE_S_FORMATETC_NOTSUPPORTED
CTL_E_GETNOTSUPPORTEDATRUNTIME
CTL_E_GETNOTSUPPORTED
CTL_E_SETNOTSUPPORTEDATRUNTIME
CTL_E_SETNOTSUPPORTED
CO_E_SERVER_EXEC_FAILURE
MK_E_INTERMEDIATEINTERFACENOTSUPPORTED
REGDB_E_KEYMISSING
OLE_E_ADVISENOTSUPPORTED
CO_E_INIT_SCM_EXEC_FAILURE
EX_THROW Type = 0x%x HR = 0x%x, line %d
ThrowHR: HR = %x
mscorsvw.pdb
_amsg_exit
_acmdln
MSVCR100_CLR0400.dll
_crt_debugger_hook
RegCloseKey
RegQueryInfoKeyW
RegOpenKeyExW
ADVAPI32.dll
GetWindowsDirectoryW
GetCPInfo
GetProcessHeap
KERNEL32.dll
MsgWaitForMultipleObjectsEx
USER32.dll
mscoree.dll
ole32.dll
OLEAUT32.dll
.PAVException@@
v1.0.3705
.PAVOutOfMemoryException@@
.PAVHRException@@
7 7$7(7,7074787
6$6,686\6|6
advapi32.dll
Wtsapi32.dll
kernel32.dll
mscorsvc.dll
Microsoft .NET Runtime Optimization Service
Microsoft .NET Runtime Optimization Service has been uninstalled
Failed to uninstall Microsoft .NET Runtime Optimization Service
Microsoft .NET Runtime Optimization Service has been installed
Failed to install Microsoft .NET Runtime Optimization Service
Failed to retrieve Microsoft .NET Runtime Optimization Service interface
Set service status to %d
Service control handler op %u, event type %u
\ndpsetup.bat
Created repair process in session %d, process ID %d
Unable to create repair process, error %d
Microsoft.NET\NETFXRepair.exe
Error changing token session ID, error %d
Error duplicating current process token, error %d
Error getting current process token, error %d
Session %u has become active.
Aborting repair due to unexpected wait status %u
Found active session %u
Aborting repair due to error %u from WTSEnumerateSessions
StartServiceCtrlDispatcher failed with error %d. Will try slow path
\fusion.localgac
\v2.0.50727
SOFTWARE\Microsoft\.NetFramework
v4.0.0
SOFTWARE\Microsoft\.NETFramework\NGenQueueMSI\WIN32\Default
SOFTWARE\Microsoft\.NETFramework\NGenQueue\WIN32\Default
ngenrootstorelock.dat
ngenservicelock.dat
FastStartupCheck(isPrivateRuntime=%d)
yKERNEL32.DLL
Software\Microsoft\.NETFramework
RestrictedGCStressExe
EnableInternetHREFexes
NGENServiceWaitPassiveWork
NGENServicePassiveWorkWaitTimeout
NGENServicePassiveHardDiskIdleTimeout
NGENServicePassiveExceptInputTimeout
MD_ForceNoColDesSharing
UNSUPPORTED_DbgDontResumeThreadsOnUnhandledException
DbgTransportProxyAddress
DbgRedirectCreateCmd
DbgRedirectCommonCmd
DbgRedirectAttachCmd
mscorrc.dll
v4.0.30319
.NET Runtime Optimization Service
4.0.30319.1 (RTMRel.030319-0100)
mscorsvw.exe
.NET Framework
4.0.30319.1

SnapMyScreen.exe_2152_rwx_03CF0000_00010000:

PresentationFramework.classic
WindowsFormsIntegration

WPFFontCache_v0400.exe_2252:

.text
`.data
@.rsrc
@.reloc
t1Ht.Ht
Ht.Ht
8Y%u(
Ht.Ht$Ht
tGHt;Ht.Ht$Ht
!!"$%%&$%%&())*
%s %s line %d
SHELL32.dll
RPCRT4.dll
MSVCR100_CLR0400.dll
KERNEL32.dll
ADVAPI32.dll
RegNotifyChangeKeyValue
RegCloseKey
RegQueryInfoKeyW
RegOpenKeyExW
GetSystemWindowsDirectoryW
_crt_debugger_hook
_amsg_exit
wpffontcache_v0400.pdb
.?AVMalformedKeyException@@
.?AVNotSupportedException@@
6666666666666666
666666666666
6666666
8888888
!"#$%&'()* ,-./
0000000000000
#@$@$@$@$
@:@$@$@$@$@$@$@$@$@$@$
!"#$%&'()* ,-./0
%&'(gggg)* ,..........................................................................................MMMM..
4444444444444
#$%&'()* 
!!!!"#$%&'()* ,-./0123456789:;<=
KEYW
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" processorArchitecture="X86" name="wpffontcache_v0400" type="win32"></assemblyIdentity><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo></assembly>PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
4 4}455<5
:":&:*:.:2:
0!0&0,03090?0
1 1$1(1,1014181
>0>8>`>~>
1$1@1\1|1
Software\Microsoft\Avalon.Graphics
kernel32.dll
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts
MARLETT.TTF
E\\?\
\WPFFontCache_v0400-System.dat
{2da8dded-086f-4cb9-a77f-b974b9cb0186}
\\?\UNC\
{00000000-0000-0000-0000-000000000000}
\\?\Volume
yKERNEL32.DLL
KeySize
ElementMalformedKeyTask
CacheMissReportReceivedTask
wpffontcache_v0400.exe
4.0.30319.1 built by: RTMRel
.NET Framework
4.0.30319.1


Remove it with Ad-Aware

  1. Click (here) to download and install Ad-Aware Free Antivirus.
  2. Update the definition files.
  3. Run a full scan of your computer.


Manual removal*

  1. Terminate malicious process(es) (How to End a Process With the Task Manager):

    bfHighIn.exe:232
    TPIManagerConsole.exe:1900
    WPFFontCache_v0400.exe:2252
    %original file name%.exe:1736
    ngen.exe:2108
    irsetup.exe:1228
    {3A8C3261-820F-4F0A-9C97-37B8F33D8519}.exe:208
    000006c8T8SETUP.EXE:1932
    bfbarsvc.exe:572
    bfbarsvc.exe:1760
    bfbarsvc.exe:1356

  2. Delete the original Trojan file.
  3. Delete or disinfect the following files created/modified by the Trojan:

    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\81UFS96V\desktop.ini (67 bytes)
    %Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\C3E814D1CB223AFCD58214D14C3B7EAB (341 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\desktop.ini (67 bytes)
    %Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\8DFDF057024880D7A081AFBF6D26B92F (176 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\R4W6XPZO\desktop.ini (67 bytes)
    %Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\8BD11C4A2318EC8E5A82462092971DEA (208 bytes)
    %Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\C3E814D1CB223AFCD58214D14C3B7EAB (220 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\75Q3FU31\desktop.ini (67 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temporary Internet Files\Content.IE5\5EH3CC9L\desktop.ini (67 bytes)
    %Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\8BD11C4A2318EC8E5A82462092971DEA (477 bytes)
    %Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\MetaData\62B5AF9BE9ADC1085C3C56EC07A82BF6 (224 bytes)
    %Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\8DFDF057024880D7A081AFBF6D26B92F (533 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\{3A8C3261-820F-4F0A-9C97-37B8F33D8519}.exe (558702 bytes)
    %Documents and Settings%\%current user%\Application Data\Microsoft\CryptnetUrlCache\Content\62B5AF9BE9ADC1085C3C56EC07A82BF6 (140 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\000006c8T8SETUP.EX_ (39950 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\000006c8T8SETUP.EXE (187442 bytes)
    %WinDir%\Microsoft.NET\Framework\v4.0.30319\ngen.log (1398 bytes)
    %System%\d3d9caps.tmp (2648 bytes)
    %Program Files%\Mindspark\SnapMyScreen\System.Windows.Interactivity.dll (46 bytes)
    %Program Files%\Mindspark\SnapMyScreen\Microsoft.Expression.Interactions.dll (1137 bytes)
    %Program Files%\Mindspark\SnapMyScreen\uninstall.exe (9213 bytes)
    %Program Files%\Mindspark\SnapMyScreen\Uninstall\uninstall.dat (2712 bytes)
    %Program Files%\Mindspark\SnapMyScreen\RebootRequired.exe (1137 bytes)
    %Program Files%\Mindspark\SnapMyScreen\UnifiedLogging.dll (1137 bytes)
    %Program Files%\Mindspark\SnapMyScreen\lua5.1.dll (2902 bytes)
    %Program Files%\Mindspark\SnapMyScreen\Uninstall\uni1.tmp (12365 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\_ir_sf_temp_0\irsetup.dat (1209 bytes)
    %Documents and Settings%\%current user%\Desktop\SnapMyScreen.lnk (1 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\_ir_sf_temp_0\IRIMG1.PNG (6 bytes)
    %Program Files%\Mindspark\SnapMyScreen\Uninstall\IRIMG1.PNG (6 bytes)
    %Documents and Settings%\%current user%\Start Menu\Programs\SnapMyScreen\SnapMyScreen.lnk (1 bytes)
    %Program Files%\Mindspark\SnapMyScreen\Uninstall\uninstall.xml (1219 bytes)
    %Program Files%\Mindspark\SnapMyScreen\DesktopSdk.dll (4695 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\SnapMyScreen Setup Log.txt (4801 bytes)
    %Program Files%\Mindspark\SnapMyScreen\SnapMyScreen.exe (4920 bytes)
    %Program Files%\Mindspark\SnapMyScreen\SnapMyScreen.exe.config (193 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\_ir_sf_temp_0\lua5.1.dll (325 bytes)
    %Documents and Settings%\%current user%\Local Settings\Temp\_ir_sf_temp_0\irsetup.exe (7386 bytes)
    %WinDir%\Microsoft.NET\Framework\v4.0.30319\ngen_service.log (514 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\assists\ie_default_search_provider\ARBITER.DLL (15 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\ASSISTMONITOR.DLL (225 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\VERIFY.DLL (70 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\TOOLBARGUARD.DLL (240 bytes)
    %Documents and Settings%\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat (20 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\bfhighin.exe (13 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\bftpinst.dll (179 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\TOOLBARGUARD64.DLL (251 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\bfdatact.dll (171 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\bfbar.dll (5442 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\Hpg64.dll (220 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\DPNMNGR.DLL (217 bytes)
    %Documents and Settings%\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat (20 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\AppIntegrator64.exe (264 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\bfregiet.dll (87 bytes)
    %Documents and Settings%\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG (1560 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\assists\ie_enable\ARBITER64.DLL (12 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\installKeys.js (207 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\CREXT.DLL (6422 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\TPIMANAGERCONSOLE.EXE (78 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\bfPlugin.dll (83 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\bfskplay.exe (55 bytes)
    %System%\config\SOFTWARE.LOG (38577 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\T8EXTPEX.DLL (108 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\bfdlghk.dll (121 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\bfmlbtn.dll (98 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\assists\ie_default_search_provider\ARBITER64.DLL (17 bytes)
    %Program Files%\SnapMyScreen_bf\bar\Message\COMMON.T8S (100 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\LOGO.BMP (10 bytes)
    %Program Files%\SnapMyScreen_bf\bar\assists\COMMON.T8S (138 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\HKFXMGR.DLL (1628 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\bfbarsvc.exe (90 bytes)
    %Program Files%\SnapMyScreen_bf\bar\gen1\COMMON.T8S (1 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\T8EPMSUP.DLL (79 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\bfhtmlmu.dll (214 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\bfscript.dll (104 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\bfSrcAs.dll (144 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\bffeedmg.dll (145 bytes)
    %Program Files%\SnapMyScreen_bf\bar\Settings\s_pid.dat (8 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\BOOTSTRAP.JS (20 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\APPINTEGRATOR.EXE (229 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\T8EXTEX.DLL (102 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\assists\ie_enable\CONFIG.XML (6 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\ASSISTMONITOR64.DLL (246 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\bfbprtct.dll (121 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\bfmedint.exe (12 bytes)
    %Documents and Settings%\%current user%\NTUSER.DAT.LOG (6408 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\APPINTEGRATORSTUB.DLL (197 bytes)
    %Documents and Settings%\%current user%\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat (1564 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\assists\ie_default_search_provider\ASSIST.EXE (207 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\assists\ie_enable\ARBITER.DLL (12 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\bfskin.dll (212 bytes)
    %System%\config\system (2812 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\AppIntegratorStub64.dll (213 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\chrome\bfffxtbr.jar (1829 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\INSTALL.RDF (2 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\bfregfft.dll (85 bytes)
    %System%\config\SYSTEM.LOG (4793 bytes)
    %System%\config\software (34460 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\bfhttpct.dll (151 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\CHROME.MANIFEST (1 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\T8TICKER.DLL (171 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\assists\ie_default_search_provider\CONFIG.XML (3 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\bfidle.dll (62 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\FF-NativeMessagingDispatcher.dll (1767 bytes)
    %Documents and Settings%\%current user%\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG (1896 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\HKFXMGR64.DLL (1729 bytes)
    %Documents and Settings%\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG (1560 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\T8RES.DLL (198 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\bfhkstub.dll (59 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\bfreghk.dll (80 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\T8HTML.DLL (202 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\HPG.DLL (237 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\bfdlghk64.dll (147 bytes)
    %Program Files%\SnapMyScreen_bf\bar\1.bin\CrExtPbf.exe (5442 bytes)

  4. Delete the following value(s) in the autorun key (How to Work with System Registry):

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SnapMyScreen" = "%Program Files%\Mindspark\SnapMyScreen\SnapMyScreen.exe /hidden"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SnapMyScreen AppIntegrator 32-bit" = "C:\PROGRA~1\SNAPMY~1\bar\1.bin\AppIntegrator.exe"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SnapMyScreen" = "rundll32 C:\PROGRA~1\SNAPMY~1\bar\1.bin\bfbar.dll,S"

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SnapMyScreen Search Scope Monitor" = "C:\PROGRA~1\SNAPMY~1\bar\1.bin\bfsrchmn.exe /m=2 /w /h"

  5. Clean the Temporary Internet Files folder, which may contain infected files (How to clean Temporary Internet Files folder).
  6. Reboot the computer.

*Manual removal may cause unexpected system behaviour and should be performed at your own risk.

No votes yet

x

Our best antivirus yet!

Fresh new look. Faster scanning. Better protection.

Enjoy unique new features, lightning fast scans and a simple yet beautiful new look in our best antivirus yet!

For a quicker, lighter and more secure experience, download the all new adaware antivirus 12 now!

Download adaware antivirus 12
No thanks, continue to lavasoft.com
close x

Discover the new adaware antivirus 12

Our best antivirus yet

Download Now