Technical Information
- %WINDIR%\SysWOW64\FlashPlayerApp.exe with %WINDIR%\syswow64\flashplayerapp.exe
- %WINDIR%\SysWOW64\FlashPlayerCPLApp.cpl with %WINDIR%\syswow64\flashplayercplapp.cpl
- '<SYSTEM32>\taskkill.exe' /f /im FlashHelperService.exe
- '<SYSTEM32>\taskkill.exe' /f /im FlashPlayerUpdateService.exe
- %TEMP%\7zipsfx.000\cafp\adobe_flash_player_activex\app\flashplayercplapp.cpl
- %TEMP%\aut52c1.tmp
- %WINDIR%\syswow64\macromed\flash\clean_flash_player_uninstall.exe
- %WINDIR%\syswow64\macromed\flash\pepflashplayer.dll
- %WINDIR%\syswow64\macromed\flash\manifest.json
- <SYSTEM32>\macromed\flash\pepflashplayer.dll
- <SYSTEM32>\macromed\flash\manifest.json
- %TEMP%\7zipsfx.000\cafp\adobe_flash_player_ppapi\install.cmd
- <SYSTEM32>\macromed\flash\flash.ocx
- %WINDIR%\syswow64\macromed\flash\flash.ocx
- %TEMP%\aut52d1.tmp
- nul
- %TEMP%\7zipsfx.000\cafp\clean_flash_player.exe
- %TEMP%\7zipsfx.000\cafp\adobe_flash_player_ppapi\x64files\pepflashplayer.dll
- %TEMP%\7zipsfx.000\cafp\adobe_flash_player_ppapi\x32files\pepflashplayer.dll
- %TEMP%\7zipsfx.000\cafp\adobe_flash_player_activex\x64files\flash7.ocx
- %TEMP%\7zipsfx.000\cafp\adobe_flash_player_activex\x32files\flash7.ocx
- %TEMP%\7zipsfx.000\cafp\adobe_flash_player_activex\x32files\flash.ocx
- %TEMP%\7zipsfx.000\cafp\adobe_flash_player_activex\app\flashplayerapp.exe
- %TEMP%\7zipsfx.000\cafp\adobe_flash_player_ppapi\x64files\manifest.json
- %TEMP%\7zipsfx.000\cafp\adobe_flash_player_ppapi\x32files\manifest.json
- %TEMP%\7zipsfx.000\cafp\adobe_flash_player_activex\install.cmd
- <SYSTEM32>\macromed\flash\mms.cfg
- %TEMP%\7zipsfx.000\cafp\adobe_flash_player_activex\install.cmd
- %TEMP%\7zipsfx.000\cafp\adobe_flash_player_ppapi\install.cmd
- <SYSTEM32>\macromed\flash\mms.cfg
- %WINDIR%\tasks\adobe flash player updater.job
- %TEMP%\7zipsfx.000\cafp\adobe_flash_player_ppapi\install.cmd
- %TEMP%\7zipsfx.000\cafp\adobe_flash_player_activex\install.cmd
- %WINDIR%\syswow64\flashplayercplapp.cpl
- %WINDIR%\syswow64\flashplayerapp.exe
- %WINDIR%\syswow64\macromed\flash\flashinstall.log
- <SYSTEM32>\macromed\flash\flashinstall.log
- %WINDIR%\syswow64\macromed\flash\mms.cfg
- %WINDIR%\syswow64\macromed\flash\flash32_19_0_0_207.ocx
- <SYSTEM32>\macromed\flash\flash64_19_0_0_207.ocx
- %WINDIR%\syswow64\macromed\flash\flashutil32_19_0_0_207_activex.exe
- <SYSTEM32>\macromed\flash\flashutil64_19_0_0_207_activex.exe
- %WINDIR%\syswow64\macromed\flash\flashutil32_19_0_0_207_activex.dll
- <SYSTEM32>\macromed\flash\flashutil64_19_0_0_207_activex.dll
- %WINDIR%\syswow64\macromed\flash\flashplayerupdateservice.exe
- <SYSTEM32>\tasks\adobe flash player updater
- %TEMP%\aut52c1.tmp
- %TEMP%\aut52d1.tmp
- ClassName: '' WindowName: ''
- '%TEMP%\7zipsfx.000\cafp\clean_flash_player.exe'
- '<SYSTEM32>\cmd.exe' /c %TEMP%\7ZipSfx.000\CAFP\Adobe_Flash_Player_ActiveX\install.cmd' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c %TEMP%\7ZipSfx.000\CAFP\Adobe_Flash_Player_PPAPI\install.cmd' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c %TEMP%\7ZipSfx.000\CAFP\Adobe_Flash_Player_ActiveX\install.cmd
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Wow6432Node\Macromedia\FlashPlayerActiveX" /f /v "PlayerPath" /d "%WINDIR%\SysWOW64\Macromed\Flash\Flash.ocx"
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Macromedia\FlashPlayerActiveX" /f /v "PlayerPath" /d "<SYSTEM32>\Macromed\Flash\Flash.ocx"
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Wow6432Node\Macromedia\FlashPlayerActiveX" /f /v "Version" /d "34.0.0.277"
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Macromedia\FlashPlayerActiveX" /f /v "Version" /d "34.0.0.277"
- '<SYSTEM32>\cmd.exe' /S /D /c" copy /y "%TEMP%\7ZipSfx.000\CAFP\Adobe_Flash_Player_ActiveX\Cleaner_Flash_Player_AX.bat" "<SYSTEM32>\Macromed\Flash\" 1>NUL 2>NUL"
- '<SYSTEM32>\regsvr32.exe' /s "%WINDIR%\SysWOW64\Macromed\Flash\Flash.ocx"
- '<SYSTEM32>\cmd.exe' /c %TEMP%\7ZipSfx.000\CAFP\Adobe_Flash_Player_PPAPI\install.cmd
- '<SYSTEM32>\regsvr32.exe' /s "<SYSTEM32>\Macromed\Flash\Flash.ocx"
- '<SYSTEM32>\xcopy.exe' /c/i/r/y "%TEMP%\7ZipSfx.000\CAFP\Adobe_Flash_Player_ActiveX\x64files\Flash7.ocx" "<SYSTEM32>\Macromed\Flash\Flash.ocx"
- '<SYSTEM32>\find.exe' "6.1."
- '<SYSTEM32>\find.exe' "6.0."
- '<SYSTEM32>\find.exe' "5."
- '<SYSTEM32>\xcopy.exe' /c/i/r/y "%TEMP%\7ZipSfx.000\CAFP\Adobe_Flash_Player_ActiveX\x32files\Flash.ocx" "%WINDIR%\SysWOW64\Macromed\Flash\"
- '<SYSTEM32>\xcopy.exe' /c/i/r/y "%TEMP%\7ZipSfx.000\CAFP\Adobe_Flash_Player_ActiveX\x64files\Flash.ocx" "<SYSTEM32>\Macromed\Flash\"
- '<SYSTEM32>\xcopy.exe' /c/i/r/y "%TEMP%\7ZipSfx.000\CAFP\Adobe_Flash_Player_ActiveX\x32files\Flash7.ocx" "%WINDIR%\SysWOW64\Macromed\Flash\Flash.ocx"
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Macromedia\FlashPlayerPepper" /f /v "isScriptDebugger" /t REG_DWORD /d "0"
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Wow6432Node\Macromedia\FlashPlayerPepperReleaseType" /f /v "Release" /t REG_DWORD /d "1"
- '<SYSTEM32>\xcopy.exe' /c/i/r/y "%TEMP%\7ZipSfx.000\CAFP\Adobe_Flash_Player_PPAPI\x64files\*" "<SYSTEM32>\Macromed\Flash\"
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Wow6432Node\Macromedia\FlashPlayerPepper" /f /v "isScriptDebugger" /t REG_DWORD /d "0"
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Wow6432Node\Macromedia\FlashPlayerPepper" /f /v "isPartner" /t REG_DWORD /d "1"
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Wow6432Node\Macromedia\FlashPlayerPepper" /f /v "isMSI" /t REG_DWORD /d "0"
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Wow6432Node\Macromedia\FlashPlayerPepper" /f /v "isESR" /t REG_DWORD /d "0"
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Wow6432Node\Macromedia\FlashPlayerPepper" /f /v "Version" /d "34.0.0.277"
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Macromedia\FlashPlayerPepper" /f /v "PlayerPath" /d "<SYSTEM32>\Macromed\Flash\pepflashplayer.dll"
- '<SYSTEM32>\xcopy.exe' /c/i/r/y "%TEMP%\7ZipSfx.000\CAFP\Adobe_Flash_Player_ActiveX\app\*" "%WINDIR%\SysWOW64\"
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Macromedia\FlashPlayerPepperReleaseType" /f /v "Release" /t REG_DWORD /d "1"
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Macromedia\FlashPlayerPepper" /f /v "isPartner" /t REG_DWORD /d "1"
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Macromedia\FlashPlayerPepper" /f /v "isMSI" /t REG_DWORD /d "0"
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Macromedia\FlashPlayerPepper" /f /v "isESR" /t REG_DWORD /d "0"
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Macromedia\FlashPlayerPepper" /f /v "Version" /d "34.0.0.277"
- '<SYSTEM32>\cmd.exe' /S /D /c" copy /y "%TEMP%\7ZipSfx.000\CAFP\Adobe_Flash_Player_PPAPI\Cleaner_Flash_Player_PPAPI.bat" "<SYSTEM32>\Macromed\Flash\" 1>NUL 2>NUL"
- '<SYSTEM32>\xcopy.exe' /c/i/r/y "%TEMP%\7ZipSfx.000\CAFP\Adobe_Flash_Player_PPAPI\x32files\*" "%WINDIR%\SysWOW64\Macromed\Flash\"
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\Macromed\Flash\*" /t /c /grant "Everyone:f"
- '<SYSTEM32>\icacls.exe' "%WINDIR%\SysWOW64\Macromed\Flash\*" /t /c /grant "Everyone:f"
- '<SYSTEM32>\cmd.exe' /S /D /c" echo f"
- '<SYSTEM32>\takeown.exe' /f "%WINDIR%\SysWOW64\FlashPlayerApp.exe" /a
- '<SYSTEM32>\findstr.exe' "\<6\.[0-9]\.[0-9][0-9]*\> \<10\.[0-9]\.[0-9][0-9]*\>"
- '<SYSTEM32>\cmd.exe' /S /D /c" ver"
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION" /f /v "FlashHelperService.exe"
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION" /f /v "FlashHelperService.exe"
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashPlayerUpdateService.exe" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashHelperService.exe" /f
- '<SYSTEM32>\takeown.exe' /f "<SYSTEM32>\Macromed\Flash\*" /a /r /d y
- '<SYSTEM32>\reg.exe' delete "HKLM\SYSTEM\CurrentControlSet\services\AdobeFlashPlayerUpdateSvc" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Wow6432Node\Macromedia\FlashHelper" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Macromedia\FlashHelper" /f
- '<SYSTEM32>\schtasks.exe' /delete /tn "FlashHelper TaskMachineCore" /f
- '<SYSTEM32>\schtasks.exe' /delete /tn "Adobe Flash Player Updater" /f
- '<SYSTEM32>\sc.exe' stop "Flash Helper Service"
- '<SYSTEM32>\reg.exe' QUERY "HKU\S-1-5-19"
- '<SYSTEM32>\reg.exe' delete "HKLM\SYSTEM\CurrentControlSet\services\Flash Helper Service" /f
- '<SYSTEM32>\icacls.exe' "%WINDIR%\SysWOW64\FlashPlayerCPLApp.cpl" /c /grant "Everyone:f"
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashUtil32_ActiveX.exe" /f
- '<SYSTEM32>\takeown.exe' /f "%WINDIR%\SysWOW64\FlashPlayerCPLApp.cpl" /a
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashPlayerApp.exe" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Wow6432Node\Macromedia\FlashPlayerActiveXReleaseType" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Wow6432Node\Macromedia\FlashPlayerActiveX" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Wow6432Node\Macromedia\FlashPlayer" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Macromedia\FlashPlayerActiveXReleaseType" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Macromedia\FlashPlayerActiveX" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\FlashUtil64_ActiveX.exe" /f
- '<SYSTEM32>\reg.exe' delete "HKLM\SOFTWARE\Macromedia\FlashPlayer" /f
- '<SYSTEM32>\icacls.exe' "%WINDIR%\SysWOW64\FlashPlayerApp.exe" /c /grant "Everyone:f"
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\FlashPlayerCPLApp.cpl" /c /grant "Everyone:f"
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\FlashPlayerApp.exe" /c /grant "Everyone:f"
- '<SYSTEM32>\icacls.exe' "%WINDIR%\SysWOW64\Macromed\*" /t /c /grant "Everyone:f"
- '<SYSTEM32>\icacls.exe' "<SYSTEM32>\Macromed\*" /t /c /grant "Everyone:f"
- '<SYSTEM32>\cmd.exe' /S /D /c" echo y"
- '<SYSTEM32>\takeown.exe' /f "%WINDIR%\SysWOW64\Macromed\Flash\*" /a /r /d y
- '<SYSTEM32>\reg.exe' add "HKLM\SOFTWARE\Wow6432Node\Macromedia\FlashPlayerPepper" /f /v "PlayerPath" /d "%WINDIR%\SysWOW64\Macromed\Flash\pepflashplayer.dll"