

"pwsafe.exe" wrote bytes "f8115875" to virtual address "0x755983E0" (part of module "SSPICLI.DLL") "pwsafe.exe" wrote bytes "48125875" to virtual address "0x755983C0" (part of module "SSPICLI.DLL")
/registry-editor-restore-backup-10-57f667c13df78c690f10ae66.png)
"pwsafe.exe" wrote bytes "f8115875" to virtual address "0x7559834C" (part of module "SSPICLI.DLL")

"pwsafe.exe" wrote bytes "f8110000" to virtual address "0x755812CC" (part of module "SSPICLI.DLL") "pwsafe.exe" wrote bytes "a0112a6e" to virtual address "0x76F5E324" (part of module "WININET.DLL") "pwsafe.exe" wrote bytes "f8115875" to virtual address "0x75598368" (part of module "SSPICLI.DLL") "pwsafe.exe" wrote bytes "48125875" to virtual address "0x75598348" (part of module "SSPICLI.DLL") "pwsafe.exe" wrote bytes "b890122a6effe0" to virtual address "0x75581248" (part of module "SSPICLI.DLL") "pwsafe.exe" wrote bytes "f8110000" to virtual address "0x75581408" (part of module "SSPICLI.DLL") "pwsafe.exe" wrote bytes "48125875" to virtual address "0x755983DC" (part of module "SSPICLI.DLL") "pwsafe.exe" wrote bytes "48120000" to virtual address "0x755812DC" (part of module "SSPICLI.DLL") "pwsafe.exe" wrote bytes "48120000" to virtual address "0x7558139C" (part of module "SSPICLI.DLL") "pwsafe.exe" wrote bytes "b810152a6effe0" to virtual address "0x755811F8" (part of module "SSPICLI.DLL") "pwsafe.exe" opened "C:\Users\%USERNAME%\AppData\Local\PasswordSafe\" with delete accessĬRC value set in PE header does not match actual value "pwsafe.exe" opened "C:\Users\%USERNAME%\AppData\Local\PasswordSafe\pwsafe.cfg" with delete access "pwsafe-3.55.0.exe" opened "C:\Users\%USERNAME%\AppData\Local\Temp\nsc6691.tmp\" with delete access "pwsafe-3.55.0.exe" opened "C:\Users\%USERNAME%\AppData\Local\Temp\nsc6691.tmp\System.dll" with delete access "pwsafe-3.55.0.exe" opened "C:\Users\%USERNAME%\AppData\Local\Temp\nsc6691.tmp\pws-install.ini" with delete access "pwsafe-3.55.0.exe" opened "C:\Users\%USERNAME%\AppData\Local\Temp\nsc6691.tmp\nsProcess.dll" with delete access "pwsafe-3.55.0.exe" opened "C:\Users\%USERNAME%\AppData\Local\Temp\nsc6691.tmp\LangDLL.dll" with delete access "pwsafe-3.55.0.exe" opened "C:\Users\%USERNAME%\AppData\Local\Temp\nsc6691.tmp\InstallOptions.dll" with delete access "pwsafe-3.55.0.exe" opened "C:\Users\%USERNAME%\AppData\Local\Temp\nsc6691.tmp" with delete access "pwsafe-3.55.0.exe" opened "%TEMP%\nsh6613.tmp" with delete access
