Technical Information
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] 'fxpInComplete' = '%PROGRAM_FILES%\Foxit Software\Foxit Phantom\InComplete.exe'
- '%PROGRAM_FILES%\Foxit Software\Foxit Phantom\InOther.exe' /Install
- '%PROGRAM_FILES%\Foxit Software\Foxit Phantom\InPDFReaderPlugin.exe' -p %PROGRAM_FILES%\Foxit Software\Foxit Phantom\plugins\
- '%PROGRAM_FILES%\Foxit Software\Foxit Phantom\InPlugins.exe' Install=%PROGRAM_FILES%\Foxit Software\Foxit Phantom\
- '<SYSTEM32>\msiexec.exe' -Embedding 3396F4BAD9DCB85369459F6FA5514903 M Global\MSI0000
- '<SYSTEM32>\msiexec.exe' /Y "%PROGRAM_FILES%\Foxit Software\Foxit Phantom\FoxitReaderOCX.ocx"
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\msiexec.exe' /i "%TEMP%\FoxitPhantom22_enu_Setup.msi" /qb
- '<SYSTEM32>\msiexec.exe' /V
- '<SYSTEM32>\msiexec.exe' -Embedding C1C452BB293186D9DF1512DE38A087DB
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\stamps\Standard Stamps\Emergency.pdf
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\Readme.txt
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\stamps\Standard Stamps\Verified.pdf
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\License.txt
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\Foxit Phantom.exe
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\lex\userdic.tlx
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\lex\ssceca2.clx
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\plugins\ondemandcm\OnDemandPlugin.dll
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\InPlugins.exe
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\lex\correct.tlx
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\Uninst.exe
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\stamps\Standard Stamps\Confidential.pdf
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\FoxitReaderOCX.ocx
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\stamps\Sign Here\Sign Here.pdf
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\stamps\Standard Stamps\Received.pdf
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\stamps\Sign Here\Accepted.pdf
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\stamps\Standard Stamps\Completed.pdf
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\plugins\creator\FXC_ProxyProcess.exe
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\fxdecod1.dll
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\fpdfcjk.bin
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\stamps\Sign Here\Initial.pdf
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\fpc_wordaddin.dll
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\UnPDFReaderPlugin.exe
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\stamps\Standard Stamps\Draft.pdf
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\plugins\creator\fpmvpr_drv.dll
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\lex\sscebr2.clx
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\lex\tech.tlx
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\plugins\ondemandcm\curl\curl.exe
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\InComplete.exe
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\plugins\ondemandcm\curl\libeay32.dll
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\stamps\Standard Stamps\Approved.pdf
- %ALLUSERSPROFILE%\Desktop\Foxit Phantom.lnk
- <SYSTEM32>\spool\drivers\w32x86\fpmvpr_drv.dll
- <SYSTEM32>\spool\drivers\w32x86\fpmvpr_ui.dll
- %ALLUSERSPROFILE%\Start Menu\Programs\Foxit Phantom\Uninstall.lnk
- %ALLUSERSPROFILE%\Start Menu\Programs\Foxit Phantom\Foxit Phantom.lnk
- %ALLUSERSPROFILE%\Start Menu\Programs\Foxit Phantom\InstallKey.lnk
- %ALLUSERSPROFILE%\Start Menu\Programs\Foxit Phantom\Readme.lnk
- <SYSTEM32>\spool\drivers\w32x86\3\New\fpmvpr_drv.dll
- %WINDIR%\Installer\{31753CDD-A7DA-4667-BEFC-B3EA3BDF366E}\_E4473A33D427EFEFA9AEA7.exe
- %WINDIR%\Installer\{31753CDD-A7DA-4667-BEFC-B3EA3BDF366E}\_11C73E6DC2B6AC7C1C92D2.exe
- %WINDIR%\Installer\{31753CDD-A7DA-4667-BEFC-B3EA3BDF366E}\_49B2081FE89B4954F8F45E.exe
- %WINDIR%\Installer\{31753CDD-A7DA-4667-BEFC-B3EA3BDF366E}\_057922DE56CABC90869181.exe
- <SYSTEM32>\spool\drivers\w32x86\3\New\fpmvpr_ui.dll
- C:\Documents and Settings\LocalService\Application Data\Foxit Software\Foxit PDF Creator\FXCPrivate_7953.ini
- %WINDIR%\Installer\{31753CDD-A7DA-4667-BEFC-B3EA3BDF366E}\_28EB952BBDAF8E7B92A96F.exe
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\InstallKey.exe
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\lex\accent.tlx
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\stamps\Standard Stamps\Expired.pdf
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\npFoxitReaderPlugin.dll
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\stamps\Standard Stamps\Void.pdf
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\stamps\Standard Stamps\Revised.pdf
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\lex\ssceam2.clx
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\stamps\Sign Here\Witness.pdf
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\UnInstallOther.Dll
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\stamps\Sign Here\Rejected.pdf
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\plugins\ondemandcm\curl\libssl32.dll
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\lex\sscebr.tlx
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\plugins\ondemandcm\curl\libcurl.dll
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\InOther.exe
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\lex\ssceam.tlx
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\lex\ssceca.tlx
- %TEMP%\Cab11.tmp
- %TEMP%\Cab13.tmp
- %TEMP%\Cab15.tmp
- %TEMP%\CabF.tmp
- %WINDIR%\Installer\2cf3d.msi
- %TEMP%\CabB.tmp
- %TEMP%\CabD.tmp
- %WINDIR%\Installer\MSI17.tmp
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-20
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-20
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-2052111302-484763869-725345543-1003
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-19
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\rp.log
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-18
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_NTUSER_S-1-5-19
- %TEMP%\$inst\0002.tmp
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\fpmkey.txt
- %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\2BF68F4714092295550497DD56F57004
- %TEMP%\$inst\0001.tmp
- %TEMP%\$inst\2.tmp
- %TEMP%\$inst\temp_0.tmp
- %TEMP%\FoxitPhantom22_enu_Setup.msi
- %APPDATA%\Microsoft\CryptnetUrlCache\Content\2BF68F4714092295550497DD56F57004
- %TEMP%\Cab5.tmp
- %TEMP%\Cab7.tmp
- %TEMP%\Cab9.tmp
- %TEMP%\Cab3.tmp
- %APPDATA%\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
- %APPDATA%\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
- %TEMP%\Cab1.tmp
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-2052111302-484763869-725345543-1003
- %WINDIR%\Installer\MSI1A.tmp
- %TEMP%\Cab1B.tmp
- %TEMP%\Cab1D.tmp
- C:\Config.Msi\2cf40.rbs
- %WINDIR%\Installer\MSI18.tmp
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\OBJECTS.MAP
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\RestorePointSize
- %TEMP%\Cab1F.tmp
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\InPDFReaderPlugin.exe
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\stamps\Standard Stamps\Reviewed.pdf
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\plugins\creator\fpmvpr_ui.dll
- %PROGRAM_FILES%\Foxit Software\Foxit Phantom\stamps\Standard Stamps\Final.pdf
- %TEMP%\Cab21.tmp
- %TEMP%\Cab23.tmp
- %TEMP%\Cab25.tmp
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SAM
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\ComDb.Dat
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\domain.txt
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SYSTEM
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_USER_.DEFAULT
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SECURITY
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\_REGISTRY_MACHINE_SOFTWARE
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\$WinMgmt.CFG
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING1.MAP
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING2.MAP
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\OBJECTS.DATA
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\MAPPING.VER
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\INDEX.BTR
- C:\System Volume Information\_restore{E7F0F64C-F7E5-4319-8757-E9A20C1C4E14}\RP16\snapshot\Repository\FS\INDEX.MAP
- %TEMP%\Cab1F.tmp
- %TEMP%\Cab21.tmp
- %TEMP%\Cab23.tmp
- %TEMP%\Cab1D.tmp
- %WINDIR%\Installer\MSI17.tmp
- %WINDIR%\Installer\MSI1A.tmp
- %TEMP%\Cab1B.tmp
- %WINDIR%\Installer\2cf3f.ipi
- <SYSTEM32>\wbem\Performance\WmiApRpl.ini
- <SYSTEM32>\PerfStringBackup.TMP
- %WINDIR%\Installer\2cf3d.msi
- %TEMP%\Cab25.tmp
- %WINDIR%\Installer\MSI18.tmp
- C:\Config.Msi\2cf40.rbs
- %TEMP%\Cab15.tmp
- %TEMP%\Cab3.tmp
- %TEMP%\Cab5.tmp
- %TEMP%\Cab7.tmp
- %TEMP%\Cab1.tmp
- %TEMP%\$inst\temp_0.tmp
- %TEMP%\$inst\0001.tmp
- %TEMP%\$inst\0002.tmp
- %TEMP%\CabF.tmp
- %TEMP%\Cab11.tmp
- %TEMP%\Cab13.tmp
- %TEMP%\CabD.tmp
- %TEMP%\Cab9.tmp
- %TEMP%\$inst\2.tmp
- %TEMP%\CabB.tmp
- from <SYSTEM32>\spool\drivers\w32x86\3\New\fpmvpr_ui.dll to <SYSTEM32>\spool\drivers\w32x86\3\fpmvpr_ui.dll
- from <SYSTEM32>\spool\drivers\w32x86\3\New\fpmvpr_drv.dll to <SYSTEM32>\spool\drivers\w32x86\3\fpmvpr_drv.dll
- 'www.download.windowsupdate.com':80
- 'wp#d':80
- www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
- www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt
- wp#d/wpad.dat
- DNS ASK www.download.windowsupdate.com
- DNS ASK wp#d
- ClassName: 'Shell_TrayWnd' WindowName: ''