General Info

File name

gSyncit_5_3_21.msi

Full analysis
https://app.any.run/tasks/518b4801-0c5a-4c1b-b4fa-e0f2b1bdd55c
Verdict
Malicious activity
Analysis date
1/11/2019, 10:41:03
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-msi
File info:
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Create Time/Date: Mon Jun 21 08:00:00 1999, Name of Creating Application: Windows Installer, Security: 1, Code page: 1252, Template: Intel;1033, Number of Pages: 200, Revision Number: {75E6C46E-92C1-4768-98EB-98F58D24F125}, Title: gSyncit for Microsoft Outlook, Author: Fieldston Software, Number of Words: 2, Last Saved Time/Date: Wed Jan 9 19:17:04 2019, Last Printed: Wed Jan 9 19:17:04 2019
MD5

08fafee91a1182e1217abb03bed16f43

SHA1

fb19b3c6ca81db4b2228cc15fe7137536eb595f9

SHA256

0594d14667c3df494dba92f4a71e284d8e45baff1c8547cc08efae6877412fc8

SSDEEP

196608:UF/lgvM4+47WjFGBvj0HlfPk8sJlmTmjXBRNaMqA4oLq:w/lSMCIsBoFfPkPiTmP8tA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
120 seconds
Additional time used
60 seconds
Fakenet option
off
Heavy Evaision option
on
MITM proxy
off
Route via Tor
on
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
off

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads dropped or rewritten executable
  • gsyncit.exe (PID: 3492)
  • OUTLOOK.EXE (PID: 3200)
Application was dropped or rewritten from another process
  • gsyncit.exe (PID: 3492)
Changes settings of System certificates
  • msiexec.exe (PID: 3300)
Reads Internet Cache Settings
  • OUTLOOK.EXE (PID: 3200)
Creates files in the user directory
  • OUTLOOK.EXE (PID: 3200)
  • gsyncit.exe (PID: 3492)
Reads Environment values
  • OUTLOOK.EXE (PID: 3200)
Starts Microsoft Office Application
  • MsiExec.exe (PID: 3948)
Reads internet explorer settings
  • OUTLOOK.EXE (PID: 3200)
Creates COM task schedule object
  • msiexec.exe (PID: 2192)
Executable content was dropped or overwritten
  • msiexec.exe (PID: 2192)
Changes the autorun value in the registry
  • msiexec.exe (PID: 2192)
Creates a software uninstall entry
  • msiexec.exe (PID: 2192)
Loads dropped or rewritten executable
  • MsiExec.exe (PID: 2412)
  • MsiExec.exe (PID: 3948)
  • msiexec.exe (PID: 2192)
Reads Microsoft Office registry keys
  • gsyncit.exe (PID: 3492)
  • OUTLOOK.EXE (PID: 3200)
Creates files in the program directory
  • MsiExec.exe (PID: 2412)
  • msiexec.exe (PID: 2192)
Application launched itself
  • msiexec.exe (PID: 2192)
Searches for installed software
  • msiexec.exe (PID: 2192)
Low-level read access rights to disk partition
  • vssvc.exe (PID: 3980)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.msi
|   Microsoft Windows Installer (90.2%)
.msp
|   Windows Installer Patch (8.4%)
.msi
|   Microsoft Installer (100%)
EXIF
FlashPix
CreateDate:
1999:06:21 07:00:00
Software:
Windows Installer
Security:
Password protected
CodePage:
Windows Latin 1 (Western European)
Template:
Intel;1033
Pages:
200
RevisionNumber:
{75E6C46E-92C1-4768-98EB-98F58D24F125}
Title:
gSyncit for Microsoft Outlook
Subject:
null
Author:
Fieldston Software
Keywords:
null
Comments:
null
Words:
2
ModifyDate:
2019:01:09 19:17:04
LastPrinted:
2019:01:09 19:17:04

Screenshots

Processes

Total processes
43
Monitored processes
9
Malicious processes
4
Suspicious processes
0

Behavior graph

+
start msiexec.exe msiexec.exe msiexec.exe no specs vssvc.exe no specs drvinst.exe no specs msiexec.exe no specs msiexec.exe no specs gsyncit.exe outlook.exe
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3300
CMD
"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\Downloads\gSyncit_5_3_21.msi"
Path
C:\Windows\System32\msiexec.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\msimsg.dll
c:\windows\system32\propsys.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msisip.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\credssp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\microsoft.net\framework\v4.0.30319\fusion.dll
c:\windows\system32\msihnd.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\vccorlib140.dll
c:\windows\system32\concrt140.dll
c:\windows\system32\msvcp140_2.dll
c:\windows\system32\msvcp140_1.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\riched20.dll

PID
2192
CMD
C:\Windows\system32\msiexec.exe /V
Path
C:\Windows\system32\msiexec.exe
Indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\msimsg.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\srclient.dll
c:\windows\system32\spp.dll
c:\windows\system32\vssapi.dll
c:\windows\system32\atl.dll
c:\windows\system32\vsstrace.dll
c:\windows\system32\vss_ps.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\es.dll
c:\windows\system32\sxs.dll
c:\windows\system32\propsys.dll
c:\windows\system32\samlib.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msisip.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\winsta.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\microsoft.net\framework\v4.0.30319\fusion.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\vccorlib140.dll
c:\windows\system32\concrt140.dll
c:\windows\system32\msvcp140_2.dll
c:\windows\system32\msvcp140_1.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\cabinet.dll
c:\program files\fieldston software\gsyncit\newtonsoft.json.dll
c:\program files\fieldston software\gsyncit\htmlagilitypack.dll
c:\program files\fieldston software\gsyncit\system.data.sqlite.dll
c:\program files\fieldston software\gsyncit\sqlitecache.dll
c:\program files\fieldston software\gsyncit\zlib.portable.dll

PID
3948
CMD
C:\Windows\system32\MsiExec.exe -Embedding 81F4FC124851856B53DD4D0327D8C052 C
Path
C:\Windows\system32\MsiExec.exe
Indicators
No indicators
Parent process
msiexec.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\users\admin\appdata\local\temp\msid45d.tmp
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\temp\msid529.tmp
c:\program files\fieldston software\gsyncit\installhelper3.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\devrtl.dll
c:\program files\fieldston software\gsyncit\gsyncit.exe
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\program files\microsoft office\office14\outlook.exe

PID
3980
CMD
C:\Windows\system32\vssvc.exe
Path
C:\Windows\system32\vssvc.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Microsoft® Volume Shadow Copy Service
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\vssvc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\atl.dll
c:\windows\system32\ole32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\vssapi.dll
c:\windows\system32\vsstrace.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\clusapi.dll
c:\windows\system32\cryptdll.dll
c:\windows\system32\xolehlp.dll
c:\windows\system32\version.dll
c:\windows\system32\resutils.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\authz.dll
c:\windows\system32\virtdisk.dll
c:\windows\system32\fltlib.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\vss_ps.dll
c:\windows\system32\samlib.dll
c:\windows\system32\es.dll
c:\windows\system32\propsys.dll
c:\windows\system32\catsrvut.dll
c:\windows\system32\mfcsubs.dll
c:\windows\system32\sxs.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll

PID
2640
CMD
DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot18" "" "" "6792c44eb" "00000000" "000003A8" "00000540"
Path
C:\Windows\system32\DrvInst.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Driver Installation Module
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\spinf.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\spfileq.dll

PID
2092
CMD
C:\Windows\system32\MsiExec.exe -Embedding D9430351A4B1C733B2A9DC6EF1C9560E
Path
C:\Windows\system32\MsiExec.exe
Indicators
No indicators
Parent process
msiexec.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\installer\msi4893.tmp
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\installer\msi4a79.tmp

PID
2412
CMD
C:\Windows\system32\MsiExec.exe -Embedding 81D6DE2EAAF36FFCC2E722170E05A3B7 M Global\MSI0000
Path
C:\Windows\system32\MsiExec.exe
Indicators
No indicators
Parent process
msiexec.exe
User
SYSTEM
Integrity Level
SYSTEM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\fieldston software\gsyncit\installhelper3.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\program files\fieldston software\gsyncit\gsyncit.exe
c:\windows\system32\netutils.dll

PID
3492
CMD
"C:\Program Files\Fieldston Software\gSyncit\gsyncit.exe"
Path
C:\Program Files\Fieldston Software\gSyncit\gsyncit.exe
Indicators
Parent process
MsiExec.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Fieldston Software
Description
gSyncit
Version
5.3.21.0
Modules
Image
c:\program files\fieldston software\gsyncit\gsyncit.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\mscorlib\225759bb87c854c0fff27b1d84858c21\mscorlib.ni.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system\52cca48930e580e3189eac47158c20be\system.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.drawing\646b4b01cb29986f8e076aa65c9e9753\system.drawing.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.windows.forms\5aac750b35b27770dccb1a43f83cced7\system.windows.forms.ni.dll
c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\uxtheme.dll
c:\windows\microsoft.net\assembly\gac_msil\system.windows.forms\v4.0_4.0.0.0__b77a5c561934e089\system.windows.forms.dll
c:\program files\fieldston software\gsyncit\gsyncit.core.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\microsoft.net\framework\v4.0.30319\nlssorting.dll
c:\windows\system32\shell32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.core\55560c2014611e9119f99923c9ebdeef\system.core.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.configuration\46957030830964165644b52b0696c5d9\system.configuration.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xml\d86b080a37c60a872c82b912a2a63dac\system.xml.ni.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\riched20.dll
c:\windows\system32\mapi32.dll
c:\windows\system32\msi.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\program files\common files\system\msmapi\1033\msmapi32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\progra~1\micros~1\office14\olmapi32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcp90.dll
c:\program files\common files\microsoft shared\office14\mso.dll
c:\program files\common files\microsoft shared\office14\cultures\office.odf
c:\progra~1\micros~1\office14\1033\mapir.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\program files\fieldston software\gsyncit\microsoft.office.interop.outlook.dll
c:\program files\fieldston software\gsyncit\office.dll
c:\windows\microsoft.net\framework\v4.0.30319\diasymreader.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.data\032f5fa875be86b577722ddeeee2e51c\system.data.ni.dll
c:\windows\microsoft.net\assembly\gac_32\system.data\v4.0_4.0.0.0__b77a5c561934e089\system.data.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\program files\fieldston software\gsyncit\system.data.sqlite.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.transactions\e7044d177c8e852b85908d2702898ec8\system.transactions.ni.dll
c:\windows\microsoft.net\assembly\gac_32\system.transactions\v4.0_4.0.0.0__b77a5c561934e089\system.transactions.dll
c:\program files\fieldston software\gsyncit\webdavlib.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.ente96d83b35#\0b139f45e599394f70beccec6e1fc39c\system.enterpriseservices.ni.dll
c:\windows\microsoft.net\assembly\gac_32\system.enterpriseservices\v4.0_4.0.0.0__b03f5f7f11d50a3a\system.enterpriseservices.wrapper.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.ente96d83b35#\0b139f45e599394f70beccec6e1fc39c\system.enterpriseservices.wrapper.dll

PID
3200
CMD
"C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE"
Path
C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE
Indicators
Parent process
MsiExec.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Microsoft Outlook
Version
14.0.6025.1000
Modules
Image
c:\program files\microsoft office\office14\outlook.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcp90.dll
c:\windows\system32\apphelp.dll
c:\program files\common files\microsoft shared\office14\mso.dll
c:\program files\common files\microsoft shared\office14\cultures\office.odf
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\program files\microsoft office\office14\addins\umoutlookaddin.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msimtf.dll
c:\program files\microsoft office\office14\1033\outllibr.dll
c:\program files\common files\microsoft shared\office14\msores.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\program files\common files\microsoft shared\office14\1033\msointl.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll
c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\osppc.dll
c:\program files\common files\microsoft shared\office14\riched20.dll
c:\progra~1\micros~1\office14\olmapi32.dll
c:\progra~1\micros~1\office14\1033\mapir.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\msasn1.dll
c:\program files\microsoft office\office14\wwlib.dll
c:\program files\microsoft office\office14\gfx.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\msimg32.dll
c:\program files\microsoft office\office14\oart.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\sxs.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\progra~1\micros~1\office14\contab32.dll
c:\progra~1\micros~1\office14\omsxp32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\progra~1\micros~1\office14\mspst32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\mlang.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\actxprxy.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\program files\microsoft office\office14\addins\colleagueimport.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\program files\fieldston software\gsyncit\gsyncit.addinshim.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\mscorlib\225759bb87c854c0fff27b1d84858c21\mscorlib.ni.dll
c:\windows\microsoft.net\framework\v4.0.30319\nlssorting.dll
c:\program files\fieldston software\gsyncit\gsyncit.addin.dll
c:\program files\fieldston software\gsyncit\gsyncit.core.dll
c:\program files\fieldston software\gsyncit\microsoft.office.interop.outlook.dll
c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system\52cca48930e580e3189eac47158c20be\system.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.drawing\646b4b01cb29986f8e076aa65c9e9753\system.drawing.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.windows.forms\5aac750b35b27770dccb1a43f83cced7\system.windows.forms.ni.dll
c:\windows\microsoft.net\assembly\gac_msil\system.windows.forms\v4.0_4.0.0.0__b77a5c561934e089\system.windows.forms.dll
c:\program files\fieldston software\gsyncit\office.dll
c:\windows\assembly\gac_msil\microsoft.office.interop.outlook\14.0.0.0__71e9bce111e9429c\microsoft.office.interop.outlook.dll
c:\windows\assembly\gac\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll
c:\windows\assembly\gac_msil\office\14.0.0.0__71e9bce111e9429c\office.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.core\55560c2014611e9119f99923c9ebdeef\system.core.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.configuration\46957030830964165644b52b0696c5d9\system.configuration.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xml\d86b080a37c60a872c82b912a2a63dac\system.xml.ni.dll
c:\windows\system32\tquery.dll
c:\windows\microsoft.net\framework\v4.0.30319\diasymreader.dll
c:\windows\system32\structuredquery.dll
c:\windows\system32\secur32.dll
c:\windows\system32\propsys.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.data\032f5fa875be86b577722ddeeee2e51c\system.data.ni.dll
c:\windows\microsoft.net\assembly\gac_32\system.data\v4.0_4.0.0.0__b77a5c561934e089\system.data.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\fieldston software\gsyncit\system.data.sqlite.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.transactions\e7044d177c8e852b85908d2702898ec8\system.transactions.ni.dll
c:\windows\microsoft.net\assembly\gac_32\system.transactions\v4.0_4.0.0.0__b77a5c561934e089\system.transactions.dll
c:\program files\fieldston software\gsyncit\webdavlib.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.ente96d83b35#\0b139f45e599394f70beccec6e1fc39c\system.enterpriseservices.ni.dll
c:\windows\microsoft.net\assembly\gac_32\system.enterpriseservices\v4.0_4.0.0.0__b03f5f7f11d50a3a\system.enterpriseservices.wrapper.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.ente96d83b35#\0b139f45e599394f70beccec6e1fc39c\system.enterpriseservices.wrapper.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\credssp.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\profapi.dll
c:\progra~1\micros~1\office14\outlctl.dll
c:\windows\system32\jscript.dll
c:\program files\common files\system\ole db\oledb32.dll
c:\windows\system32\msdart.dll
c:\windows\system32\bcrypt.dll
c:\program files\common files\system\ole db\oledb32r.dll
c:\windows\system32\msiltcfg.dll
c:\program files\microsoft office\office14\onbttnol.dll
c:\program files\microsoft office\office14\socialconnector.dll
c:\windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.6161_none_4bf7e3e2bf9ada4c\mfc90u.dll
c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.6161_none_49768ef57548175e\mfc90enu.dll
c:\windows\system32\mapi32.dll
c:\program files\microsoft office\office14\1033\umoutlookstrings.dll
c:\windows\system32\msxml6.dll
c:\windows\system32\schannel.dll
c:\program files\microsoft office\office14\sharepointprovider.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\progra~1\micros~1\office14\outlacct.dll
c:\windows\system32\msident.dll
c:\windows\system32\pstorec.dll
c:\windows\system32\atl.dll
c:\windows\system32\tzres.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\userenv.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\p2pcollab.dll
c:\windows\system32\qagentrt.dll
c:\windows\system32\fveui.dll
c:\windows\system32\msoeacct.dll
c:\windows\system32\msoert2.dll
c:\windows\system32\inetcomm.dll
c:\windows\system32\inetres.dll
c:\windows\system32\acctres.dll
c:\program files\microsoft office\office14\omsmain.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msxml3.dll

Registry activity

Total events
2023
Read events
1374
Write events
628
Delete events
21

Modification events

PID
Process
Operation
Key
Name
Value
3300
msiexec.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
3300
msiexec.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\Certificates\F5AD0BCC1AD56CD150725B1C866C30AD92EF21B0
Blob
030000000100000014000000F5AD0BCC1AD56CD150725B1C866C30AD92EF21B0140000000100000014000000BBAF7E023DFAA6F13C848EADEE3898ECD93232D40400000001000000100000001EDAF9AE99CE2920667D0E9A8B3F8C9C0F00000001000000300000007CE102D63C57CB48F80A65D1A5E9B350A7A618482AA5A36775323CA933DDFCB00DEF83796A6340DEC5EBF7596CFD8E5D19000000010000001000000082218FFB91733E64136BE5719F57C3A118000000010000001000000045ED9BBC5E43D3B9ECD63C060DB78E5C200000000100000078050000308205743082045CA00302010202102766EE56EB49F38EABD770A2FC84DE22300D06092A864886F70D01010C0500306F310B300906035504061302534531143012060355040A130B416464547275737420414231263024060355040B131D41646454727573742045787465726E616C20545450204E6574776F726B312230200603550403131941646454727573742045787465726E616C20434120526F6F74301E170D3030303533303130343833385A170D3230303533303130343833385A308185310B3009060355040613024742311B30190603550408131247726561746572204D616E636865737465723110300E0603550407130753616C666F7264311A3018060355040A1311434F4D4F444F204341204C696D69746564312B302906035504031322434F4D4F444F205253412043657274696669636174696F6E20417574686F7269747930820222300D06092A864886F70D01010105000382020F003082020A028202010091E85492D20A56B1AC0D24DDC5CF446774992B37A37D23700071BC53DFC4FA2A128F4B7F1056BD9F7072B7617FC94B0F17A73DE3B00461EEFF1197C7F4863E0AFA3E5CF993E6347AD9146BE79CB385A0827A76AF7190D7ECFD0DFA9C6CFADFB082F4147EF9BEC4A62F4F7F997FB5FC674372BD0C00D689EB6B2CD3ED8F981C14AB7EE5E36EFCD8A8E49224DA436B62B855FDEAC1BC6CB68BF30E8D9AE49B6C6999F878483045D5ADE10D3C4560FC32965127BC67C3CA2EB66BEA46C7C720A0B11F65DE4808BAA44EA9F283463784EBE8CC814843674E722A9B5CBD4C1B288A5C227BB4AB98D9EEE05183C309464E6D3E99FA9517DA7C3357413C8D51ED0BB65CAF2C631ADF57C83FBCE95DC49BAF4599E2A35A24B4BAA9563DCF6FAAFF4958BEF0A8FFF4B8ADE937FBBAB8F40B3AF9E843421E89D884CB13F1D9BBE18960B88C2856AC141D9C0AE771EBCF0EDD3DA996A148BD3CF7AFB50D224CC01181EC563BF6D3A2E25BB7B204225295809369E88E4C65F191032D707402EA8B671529695202BBD7DF506A5546BFA0A328617F70D0C3A2AA2C21AA47CE289C064576BF821827B4D5AEB4CB50E66BF44C867130E9A6DF1686E0D8FF40DDFBD042887FA3333A2E5C1E41118163CE18716B2BECA68AB7315C3A6A47E0C37959D6201AAFF26A98AA72BC574AD24B9DBB10FCB04C41E5ED1D3D5E289D9CCCBFB351DAA747E584530203010001A381F43081F1301F0603551D23041830168014ADBD987A34B426F7FAC42654EF03BDE024CB541A301D0603551D0E04160414BBAF7E023DFAA6F13C848EADEE3898ECD93232D4300E0603551D0F0101FF040403020186300F0603551D130101FF040530030101FF30110603551D20040A300830060604551D200030440603551D1F043D303B3039A037A0358633687474703A2F2F63726C2E7573657274727573742E636F6D2F416464547275737445787465726E616C4341526F6F742E63726C303506082B0601050507010104293027302506082B060105050730018619687474703A2F2F6F6373702E7573657274727573742E636F6D300D06092A864886F70D01010C0500038201010064BF83F15F9A85D0CDB8A129570DE85AF7D1E93EF276046EF15270BB1E3CFF4D0D746ACC818225D3C3A02A5D4CF5BA8BA16DC4540975C7E3270E5D847937401377F5B4AC1CD03BAB1712D6EF34187E2BE979D3AB57450CAF28FAD0DBE5509588BBDF8557697D92D852CA7381BF1CF3E6B86E661105B31E942D7F91959259F14CCEA391714C7C470C3B0B19F6A1B16C863E5CAAC42E82CBF90796BA484D90F294C8A973A2EB067B239DDEA2F34D559F7A6145981868C75E406B23F5797AEF8CB56B8BB76F46F47BF13D4B04D89380595AE041241DB28F15605847DBEF6E46FD15F5D95F9AB3DBD8B8E440B3CD9739AE85BB1D8EBCDC879BD1A6EFF13B6F10386F
2192
msiexec.exe
delete key
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\5F\52C64B7E
2192
msiexec.exe
delete key
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\5F
2192
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
2192
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback
2192
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
SrCreateRp (Enter)
4000000000000000741956E291A9D40190080000C80E0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppCreate (Enter)
4000000000000000CE7B58E291A9D40190080000C80E0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
LastIndex
20
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppGatherWriterMetadata (Enter)
40000000000000004663C1E291A9D40190080000C80E0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
IDENTIFY (Enter)
4000000000000000A0C5C3E291A9D401900800009C0D0000E80300000100000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
IDENTIFY (Leave)
4000000000000000DE06E9E391A9D401900800009C0D0000E80300000000000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppGatherWriterMetadata (Leave)
40000000000000000653CDEA91A9D40190080000C80E0000D3070000010000000000000000000000000000000000000000000000000000000000000000000000
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppAddInterestingComponents (Enter)
40000000000000000653CDEA91A9D40190080000C80E0000D4070000000000000000000000000000000000000000000000000000000000000000000000000000
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppAddInterestingComponents (Leave)
40000000000000003EEFE9EA91A9D40190080000C80E0000D4070000010000000000000000000000000000000000000000000000000000000000000000000000
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
PREPAREBACKUP (Enter)
4000000000000000C2C601EB91A9D40190080000AC090000E90300000100000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
PREPAREBACKUP (Leave)
4000000000000000BC4E2AEB91A9D40190080000AC090000E90300000000000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
GETSTATE (Enter)
4000000000000000BC4E2AEB91A9D40190080000F8090000F90300000100000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
GETSTATE (Leave)
40000000000000007E3A36EB91A9D40190080000F8090000F90300000000000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
DOSNAPSHOT (Enter)
40000000000000008C613DEB91A9D40190080000C80E00000A0400000100000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
DOSNAPSHOT (Leave)
4000000000000000F41778EC91A9D40190080000440A00000A0400000000000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppCreate (Leave)
4000000000000000F41778EC91A9D40190080000C80E0000D0070000010000000000000000000000000000000000000000000000000000000000000000000000
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
SrCreateRp (Leave)
4000000000000000F41778EC91A9D40190080000C80E0000D5070000010000000000000000000000000000000000000000000000000000000000000000000000
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
FirstRun
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
LastIndex
20
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\Volatile
NestingLevel
1
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\Volatile
StartNesting
741956E291A9D401
2192
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000_CLASSES\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress
C:\Windows\Installer\1a33d4.ipi
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\1a33d5.rbs
30714257
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\1a33d5.rbsLow
4033910928
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AFFFD324B2BB381BD695D59B2ACB3C9C
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Newtonsoft.Json.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1AE141C3DFB2D647F18FB968CB57A911
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\WunderlistLib.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FF6A74E7124E52C4CFFEBBE2554C5104
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\extensibility.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\88FD2C9EBD4E03D2BA0A65D1513A6088
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\System.Net.Http.Extensions.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F9D72C5D527BBFD84A7F3B462425EDED
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\System.Threading.Tasks.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\15F713DB5953B07A9BEFAE54EC97C65F
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\System.Net.Http.WebRequest.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B9820F6500DC557A1AE9FCAA5D30FEB1
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\XPExplorerBar.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F18363FDA8D808BBF7AA8E1556202FA
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\HtmlAgilityPack.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\856C7DDC6DA51409AF8A6C59B0B4EAAF
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Microsoft.Threading.Tasks.Extensions.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\59BB167100EA5CF28BE3D4F078394410
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\gSyncit.core.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\606738FF201229B64BF4C79A44FE2DA1
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Google.Apis.Calendar.v3.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\87C77086560577083E06ABFB30CB22B5
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\GoogleLib2.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D5F72CC34342421482E95C224C9E1F9F
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\InstallHelper3.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8FAE7754B44D7F9E06DF0CBE4EA66CB7
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\System.Data.SQLite.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9B6892472D89FF4788B86B033F9858CA
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\S22.Imap.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F7BB63572EF77F967E3C98951FD32283
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\SqliteCache.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0159DF27E7A858AF702D7855D35616CB
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\SharpNoteLib.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\55BD552659F35EAA5DCA69FD06869DEF
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\gsyncit.addin.pdb
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\99DF8F3794C5F71FB9269568BBFE06B3
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Google.Apis.Drive.v2.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\314ECDF17ADDDCDB936753D7F5C613DC
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\ICSharpCode.SharpZipLib.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA96B48FA4995A384E81AE2AB607AAAF
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Microsoft.Office.Interop.Outlook.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\99B9A2AC0626DCBADD71E601F3665507
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\OFFICE.DLL
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\197562A436F67BCA04984C8A018D92A0
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Google.GData.Extensions.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE951A6F600FF4B8C7A26836D780D891
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\WebDavLib.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2177126CF56C94ABA28D5D730EA5597C
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\FileCache.Signed.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\68D265FCCB63251831AB1EA3880D5B55
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\DropBoxLib.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\438A3A136D5574761A117716B76DA4C1
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Zlib.Portable.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB32F9D71504C620811F9AF22C13F1C9
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\WizardLib.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\85B916834E00FC48C88BEE167E248993
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Google.GData.Contacts.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\776EC93F2BFF0D9E8B36B1AD40AA2D0D
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\TodoistLib.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\28B3B07B17EE39B0B5251DF2500B7B38
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\agreement.rtf
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EBE8735BF54855F943219594B18D5539
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Microsoft.Threading.Tasks.Extensions.Desktop.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\87EC3B0032E8BF0D713AA5DF8E2E65A1
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Google.Apis.Auth.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F735124D3C464EE1294779B1599206D5
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Google.Apis.Core.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1E3F7A90D29D3A4BB4AA47994DD46D2A
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Dropbox.Api.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3C28D00C69486ABE24C61BBCD984CF5A
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\NozbeLib.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7FFEF3BBAFEE24829ADAED8D52B7AA5E
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Google.GData.Client.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F6720157C4F30EAD2834E7D18D27A676
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\gSyncit.core.pdb
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6C85B6E6DF70028335514A17AC520220
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\System.Net.Http.Primitives.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\346076CAD79991FFF93B07A1A46FFBF4
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Thrift.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\571F01E4A2DB9401BE63630A4BBBAA0F
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\System.Runtime.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\657AFC56D13A8C0F133302CA323DB7A6
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\PocketInformantLib2.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2A971F02470AB9F12555CB9BA292E0B2
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\ObjectCache.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5A584D68A500D0BA1F3015C6D802C53
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\System.IO.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F538A584C553392D7D1761D4AA8C8FEC
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Evernote.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A150088CB548DC56882EB29B62AADA0C
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\EvernoteLib.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0387F09CE14F414A5F7B79FEF434CCBC
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Google.Apis.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EFCBA39E512C628422F0B8E3B5EC4943
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\ToodledoLib3.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\514653124EC099CCF1E4DC249C666718
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\stdole.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\48AD87A73C39C81F39FC080B767DCC3D
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Microsoft.Threading.Tasks.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7A3E0EC387E0CBDE832C28DBB89F10F5
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Google.Apis.Tasks.v1.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BF728FC8597978F64C9ADBA861AC9332
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\RestSharp.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FD36D22D2F148325597B225FE9691BD5
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Newtonsoft.Json.Net35.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\165DD245767A3A261889365205A0ABB2
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\System.Net.Http.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\01292C8DB1ADF15ABB2ECFD87739A35F
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Google.Apis.PeopleService.v1.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7F9522B6D56A85AEFE0E9660D7EC57E4
21B564291C5433C4DB167B691941E793
01:\Software\Fieldston Software\gSyncit\{6B2259F7-A65D-EA58-EFE0-69067DCE754E}\_06A9F472DFA3441F8C8677EE5AAEE44F
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C1F15D7F2C5FBF57ACA75953A493B375
21B564291C5433C4DB167B691941E793
00:\CLSID\{AC9F1F13-0C3E-46E1-B493-0F8D0763672F}\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0EFB5147AE82C784DAE508C7C4673D51
21B564291C5433C4DB167B691941E793
00:\CLSID\{AC9F1F13-0C3E-46E1-B493-0F8D0763672F}\VersionIndependentProgID\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D4B288F9C94F7F323A02C7CAA584EFA4
21B564291C5433C4DB167B691941E793
00:\CLSID\{AC9F1F13-0C3E-46E1-B493-0F8D0763672F}\TypeLib\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4A3B203A7B3B285C034D4B3381742EB8
21B564291C5433C4DB167B691941E793
00:\CLSID\{AC9F1F13-0C3E-46E1-B493-0F8D0763672F}\ProgID\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4334EB4E67233AA883B21DC5D4422C14
21B564291C5433C4DB167B691941E793
00:\CLSID\{AC9F1F13-0C3E-46E1-B493-0F8D0763672F}\InprocServer32\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\440C4904A1C5F855CA130811573018E4
21B564291C5433C4DB167B691941E793
00:\CLSID\{AC9F1F13-0C3E-46E1-B493-0F8D0763672F}\InprocServer32\ThreadingModel
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\92985FBE2E5C44E37F8752E34AEBD5F1
21B564291C5433C4DB167B691941E793
00:\CLSID\{AC9F1F13-0C3E-46E1-B493-0F8D0763672F}\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CA30A37DCA8425B6EBF5E693713DBB01
21B564291C5433C4DB167B691941E793
00:\TypeLib\{085FFF9D-CE6C-490C-8A88-9CA82D39898E}\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\15419066B9F11E1FDA0FDBE5648B5FA8
21B564291C5433C4DB167B691941E793
00:\TypeLib\{085FFF9D-CE6C-490C-8A88-9CA82D39898E}\1.0\FLAGS\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E2109FB6DB239009A17739917B514BC
21B564291C5433C4DB167B691941E793
00:\TypeLib\{085FFF9D-CE6C-490C-8A88-9CA82D39898E}\1.0\HELPDIR\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AE58AB777D75140B514581A93527ABA6
21B564291C5433C4DB167B691941E793
00:\TypeLib\{085FFF9D-CE6C-490C-8A88-9CA82D39898E}\1.0\0\win32\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7A5D2E183A11E124942472F6F455A158
21B564291C5433C4DB167B691941E793
00:\TypeLib\{085FFF9D-CE6C-490C-8A88-9CA82D39898E}\1.0\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2FAEBCF647A5BA858D3D1C28DEC56D6D
21B564291C5433C4DB167B691941E793
00:\gSyncit.Connect.1\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FBF275AFF3A3E69FC9547FC76B629CDE
21B564291C5433C4DB167B691941E793
00:\gSyncit.Connect.1\CLSID\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9C57ECA2CEE19493E95A7259BBD37458
21B564291C5433C4DB167B691941E793
00:\gSyncit.Connect.1\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EA91F56BDFCE0A5E95A240FAFC1DA818
21B564291C5433C4DB167B691941E793
00:\gSyncit.Connect\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B54F4275F34271F7A6194A913D9B0BD3
21B564291C5433C4DB167B691941E793
00:\gSyncit.Connect\CurVer\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BBD0F35C4C8C4DAAF54640337AF7BC15
21B564291C5433C4DB167B691941E793
00:\gSyncit.Connect\CLSID\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\072D7E7C3248BD1A6D63C66D5952E7AB
21B564291C5433C4DB167B691941E793
00:\gSyncit.Connect\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\815E42A1AF86F2E9017021DE564906F9
21B564291C5433C4DB167B691941E793
01:\Software\Microsoft\Windows\CurrentVersion\Run\gSyncit
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B2CE84294FB087C81FEE41AD39DC9679
21B564291C5433C4DB167B691941E793
02:\Software\Microsoft\Office\Outlook\AddIns\gSyncit.Connect\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E237B18B2B55F8DF8F6155E63DDD09A4
21B564291C5433C4DB167B691941E793
02:\Software\Microsoft\Office\Outlook\AddIns\gSyncit.Connect\LoadBehavior
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4F534E415563406CE6BB7ABC27F5D32A
21B564291C5433C4DB167B691941E793
02:\Software\Microsoft\Office\Outlook\AddIns\gSyncit.Connect\CommandLineSafe
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\04E365274A1E5E2E5C5BC29E0A4804D6
21B564291C5433C4DB167B691941E793
02:\Software\Microsoft\Office\Outlook\AddIns\gSyncit.Connect\FriendlyName
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D18622CC8E73640C4F6554374BCAD6E6
21B564291C5433C4DB167B691941E793
02:\Software\Microsoft\Office\Outlook\AddIns\gSyncit.Connect\Description
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\71214F24B8FA4D33C93BFFF596B6CEBB
21B564291C5433C4DB167B691941E793
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\vcruntime140.dll
2
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B3D93E8E53F48D638B29B48233F60E14
21B564291C5433C4DB167B691941E793
C?\Windows\system32\vcruntime140.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\msvcp140.dll
2
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C069AA2AC3DFD6A3DBF641390311FA3B
21B564291C5433C4DB167B691941E793
C?\Windows\system32\msvcp140.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\msvcp140_1.dll
2
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F3027E2A2C06E7D3A864BDD383A1C26E
21B564291C5433C4DB167B691941E793
C?\Windows\system32\msvcp140_1.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\msvcp140_2.dll
2
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE9930CBD9E5C7C3FB5FE5A9599CD6FA
21B564291C5433C4DB167B691941E793
C?\Windows\system32\msvcp140_2.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\concrt140.dll
2
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F139CF91DE936230A1FA8ED33D0E0EC
21B564291C5433C4DB167B691941E793
C?\Windows\system32\concrt140.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\vccorlib140.dll
2
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97FC00201A9B4EB359A592AFD9B4A1C5
21B564291C5433C4DB167B691941E793
C?\Windows\system32\vccorlib140.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A678ABB91935492F880D08B2C9B84CC9
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\gsyncit.ext.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6D439C3D6A22B05FBFEE11636E8BA721
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\gsyncit.addin.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\34D9134963E5D1D59ACC7D533229BA2A
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\gsyncit.addin.dll.config
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6154CF2A4A119293CB79F665EAEB1CF6
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\gsyncit.exe.config
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C77C628777E10C03F29AD477C06F8E3C
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\gsyncit.exe
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FDD58F3EC258D52D61318E4F67AAB677
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\gsyncit.updater.exe.config
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6A222974F514635A2EFAE0566046595D
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\gsyncit.updater.exe
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5A9166A33599A923323692914F4629BC
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\gsyncit.addinshim.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\gSyncit\
1
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\Fieldston Software\gSyncit\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\Fieldston Software\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE9930CBD9E5C7C3FB5FE5A9599CD6FA\21B564291C5433C4DB167B691941E793
PatchGUID
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE9930CBD9E5C7C3FB5FE5A9599CD6FA\21B564291C5433C4DB167B691941E793
MediaCabinet
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE9930CBD9E5C7C3FB5FE5A9599CD6FA\21B564291C5433C4DB167B691941E793
File
msvcp140_2.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE9930CBD9E5C7C3FB5FE5A9599CD6FA\21B564291C5433C4DB167B691941E793
ComponentVersion
14.15.26706.0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE9930CBD9E5C7C3FB5FE5A9599CD6FA\21B564291C5433C4DB167B691941E793
ProductVersion
5.3.21
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE9930CBD9E5C7C3FB5FE5A9599CD6FA\21B564291C5433C4DB167B691941E793
PatchSize
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE9930CBD9E5C7C3FB5FE5A9599CD6FA\21B564291C5433C4DB167B691941E793
PatchAttributes
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE9930CBD9E5C7C3FB5FE5A9599CD6FA\21B564291C5433C4DB167B691941E793
PatchSequence
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE9930CBD9E5C7C3FB5FE5A9599CD6FA\21B564291C5433C4DB167B691941E793
SharedComponent
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE9930CBD9E5C7C3FB5FE5A9599CD6FA\21B564291C5433C4DB167B691941E793
IsFullFile
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C069AA2AC3DFD6A3DBF641390311FA3B\21B564291C5433C4DB167B691941E793
PatchGUID
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C069AA2AC3DFD6A3DBF641390311FA3B\21B564291C5433C4DB167B691941E793
MediaCabinet
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C069AA2AC3DFD6A3DBF641390311FA3B\21B564291C5433C4DB167B691941E793
File
msvcp140.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C069AA2AC3DFD6A3DBF641390311FA3B\21B564291C5433C4DB167B691941E793
ComponentVersion
14.15.26706.0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C069AA2AC3DFD6A3DBF641390311FA3B\21B564291C5433C4DB167B691941E793
ProductVersion
5.3.21
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C069AA2AC3DFD6A3DBF641390311FA3B\21B564291C5433C4DB167B691941E793
PatchSize
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C069AA2AC3DFD6A3DBF641390311FA3B\21B564291C5433C4DB167B691941E793
PatchAttributes
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C069AA2AC3DFD6A3DBF641390311FA3B\21B564291C5433C4DB167B691941E793
PatchSequence
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C069AA2AC3DFD6A3DBF641390311FA3B\21B564291C5433C4DB167B691941E793
SharedComponent
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C069AA2AC3DFD6A3DBF641390311FA3B\21B564291C5433C4DB167B691941E793
IsFullFile
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B3D93E8E53F48D638B29B48233F60E14\21B564291C5433C4DB167B691941E793
PatchGUID
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B3D93E8E53F48D638B29B48233F60E14\21B564291C5433C4DB167B691941E793
MediaCabinet
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B3D93E8E53F48D638B29B48233F60E14\21B564291C5433C4DB167B691941E793
File
vcruntime140.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B3D93E8E53F48D638B29B48233F60E14\21B564291C5433C4DB167B691941E793
ComponentVersion
14.15.26706.0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B3D93E8E53F48D638B29B48233F60E14\21B564291C5433C4DB167B691941E793
ProductVersion
5.3.21
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B3D93E8E53F48D638B29B48233F60E14\21B564291C5433C4DB167B691941E793
PatchSize
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B3D93E8E53F48D638B29B48233F60E14\21B564291C5433C4DB167B691941E793
PatchAttributes
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B3D93E8E53F48D638B29B48233F60E14\21B564291C5433C4DB167B691941E793
PatchSequence
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B3D93E8E53F48D638B29B48233F60E14\21B564291C5433C4DB167B691941E793
SharedComponent
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B3D93E8E53F48D638B29B48233F60E14\21B564291C5433C4DB167B691941E793
IsFullFile
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97FC00201A9B4EB359A592AFD9B4A1C5\21B564291C5433C4DB167B691941E793
PatchGUID
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97FC00201A9B4EB359A592AFD9B4A1C5\21B564291C5433C4DB167B691941E793
MediaCabinet
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97FC00201A9B4EB359A592AFD9B4A1C5\21B564291C5433C4DB167B691941E793
File
vccorlib140.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97FC00201A9B4EB359A592AFD9B4A1C5\21B564291C5433C4DB167B691941E793
ComponentVersion
14.15.26706.0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97FC00201A9B4EB359A592AFD9B4A1C5\21B564291C5433C4DB167B691941E793
ProductVersion
5.3.21
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97FC00201A9B4EB359A592AFD9B4A1C5\21B564291C5433C4DB167B691941E793
PatchSize
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97FC00201A9B4EB359A592AFD9B4A1C5\21B564291C5433C4DB167B691941E793
PatchAttributes
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97FC00201A9B4EB359A592AFD9B4A1C5\21B564291C5433C4DB167B691941E793
PatchSequence
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97FC00201A9B4EB359A592AFD9B4A1C5\21B564291C5433C4DB167B691941E793
SharedComponent
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97FC00201A9B4EB359A592AFD9B4A1C5\21B564291C5433C4DB167B691941E793
IsFullFile
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F3027E2A2C06E7D3A864BDD383A1C26E\21B564291C5433C4DB167B691941E793
PatchGUID
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F3027E2A2C06E7D3A864BDD383A1C26E\21B564291C5433C4DB167B691941E793
MediaCabinet
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F3027E2A2C06E7D3A864BDD383A1C26E\21B564291C5433C4DB167B691941E793
File
msvcp140_1.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F3027E2A2C06E7D3A864BDD383A1C26E\21B564291C5433C4DB167B691941E793
ComponentVersion
14.15.26706.0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F3027E2A2C06E7D3A864BDD383A1C26E\21B564291C5433C4DB167B691941E793
ProductVersion
5.3.21
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F3027E2A2C06E7D3A864BDD383A1C26E\21B564291C5433C4DB167B691941E793
PatchSize
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F3027E2A2C06E7D3A864BDD383A1C26E\21B564291C5433C4DB167B691941E793
PatchAttributes
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F3027E2A2C06E7D3A864BDD383A1C26E\21B564291C5433C4DB167B691941E793
PatchSequence
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F3027E2A2C06E7D3A864BDD383A1C26E\21B564291C5433C4DB167B691941E793
SharedComponent
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F3027E2A2C06E7D3A864BDD383A1C26E\21B564291C5433C4DB167B691941E793
IsFullFile
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F139CF91DE936230A1FA8ED33D0E0EC\21B564291C5433C4DB167B691941E793
PatchGUID
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F139CF91DE936230A1FA8ED33D0E0EC\21B564291C5433C4DB167B691941E793
MediaCabinet
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F139CF91DE936230A1FA8ED33D0E0EC\21B564291C5433C4DB167B691941E793
File
concrt140.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F139CF91DE936230A1FA8ED33D0E0EC\21B564291C5433C4DB167B691941E793
ComponentVersion
14.15.26706.0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F139CF91DE936230A1FA8ED33D0E0EC\21B564291C5433C4DB167B691941E793
ProductVersion
5.3.21
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F139CF91DE936230A1FA8ED33D0E0EC\21B564291C5433C4DB167B691941E793
PatchSize
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F139CF91DE936230A1FA8ED33D0E0EC\21B564291C5433C4DB167B691941E793
PatchAttributes
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F139CF91DE936230A1FA8ED33D0E0EC\21B564291C5433C4DB167B691941E793
PatchSequence
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F139CF91DE936230A1FA8ED33D0E0EC\21B564291C5433C4DB167B691941E793
SharedComponent
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F139CF91DE936230A1FA8ED33D0E0EC\21B564291C5433C4DB167B691941E793
IsFullFile
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Windows\Installer\{92465B12-45C1-4C33-BD61-B79691147E39}\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AC9F1F13-0C3E-46E1-B493-0F8D0763672F}
Connect Class
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\gSyncit.Connect
Connect Class
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AC9F1F13-0C3E-46E1-B493-0F8D0763672F}\VersionIndependentProgID
gSyncit.Connect
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AC9F1F13-0C3E-46E1-B493-0F8D0763672F}\TypeLib
{085FFF9D-CE6C-490C-8A88-9CA82D39898E}
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\gSyncit.Connect.1
Connect Class
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AC9F1F13-0C3E-46E1-B493-0F8D0763672F}\ProgID
gSyncit.Connect.1
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AC9F1F13-0C3E-46E1-B493-0F8D0763672F}\InprocServer32
C:\Program Files\Fieldston Software\gSyncit\gsyncit.addinshim.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AC9F1F13-0C3E-46E1-B493-0F8D0763672F}\InprocServer32
ThreadingModel
Apartment
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{085FFF9D-CE6C-490C-8A88-9CA82D39898E}\1.0\FLAGS
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{085FFF9D-CE6C-490C-8A88-9CA82D39898E}\1.0\HELPDIR
C:\Program Files\Fieldston Software\gSyncit
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{085FFF9D-CE6C-490C-8A88-9CA82D39898E}\1.0\0\win32
C:\Program Files\Fieldston Software\gSyncit\gsyncit.addinshim.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{085FFF9D-CE6C-490C-8A88-9CA82D39898E}\1.0
gSyncitConnectAddin 1.0 Type Library
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\gSyncit.Connect.1\CLSID
{AC9F1F13-0C3E-46E1-B493-0F8D0763672F}
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\gSyncit.Connect\CurVer
gSyncit.Connect.1
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\gSyncit.Connect\CLSID
{AC9F1F13-0C3E-46E1-B493-0F8D0763672F}
2192
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Fieldston Software\gSyncit\{6B2259F7-A65D-EA58-EFE0-69067DCE754E}
_06A9F472DFA3441F8C8677EE5AAEE44F
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\gSyncit\
2192
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Windows\CurrentVersion\Run
gSyncit
C:\Program Files\Fieldston Software\gSyncit\gsyncit.exe
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\gSyncit.Connect
LoadBehavior
3
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\gSyncit.Connect
CommandLineSafe
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\gSyncit.Connect
FriendlyName
gSyncit Outlook Add-In
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\gSyncit.Connect
Description
gSyncit Outlook Add-In
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
LocalPackage
C:\Windows\Installer\1a33d6.msi
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
AuthorizedCDFPrefix
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
Comments
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
Contact
Fieldston Software
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
DisplayVersion
5.3.21
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
HelpLink
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
HelpTelephone
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
InstallDate
20190111
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
InstallLocation
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
InstallSource
C:\Users\admin\Downloads\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
ModifyPath
MsiExec.exe /I{92465B12-45C1-4C33-BD61-B79691147E39}
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
Publisher
Fieldston Software
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
Readme
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
Size
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
EstimatedSize
20522
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
UninstallString
MsiExec.exe /I{92465B12-45C1-4C33-BD61-B79691147E39}
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
URLInfoAbout
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
URLUpdateInfo
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
VersionMajor
5
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
VersionMinor
3
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
WindowsInstaller
1
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
Version
84082709
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
Language
1033
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
AuthorizedCDFPrefix
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
Comments
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
Contact
Fieldston Software
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
DisplayVersion
5.3.21
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
HelpLink
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
HelpTelephone
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
InstallDate
20190111
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
InstallLocation
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
InstallSource
C:\Users\admin\Downloads\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
ModifyPath
MsiExec.exe /I{92465B12-45C1-4C33-BD61-B79691147E39}
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
Publisher
Fieldston Software
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
Readme
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
Size
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
EstimatedSize
20522
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
UninstallString
MsiExec.exe /I{92465B12-45C1-4C33-BD61-B79691147E39}
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
URLInfoAbout
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
URLUpdateInfo
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
VersionMajor
5
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
VersionMinor
3
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
WindowsInstaller
1
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
Version
84082709
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
Language
1033
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\AD1D8ED4159C0374B9595700163D6677
21B564291C5433C4DB167B691941E793
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
DisplayName
gSyncit
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
DisplayName
gSyncit
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Newtonsoft.Json.dll
Newtonsoft.Json,Version="10.0.0.0",Culture="neutral",PublicKeyToken="30AD4FE6B2A6AEED",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>[email protected]'b[FzXdkk}pi
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|WunderlistLib.dll
WunderlistLib,Version="1.51.0.0",Culture="neutral",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>4r?B7.X_KMczG=S[ru`(
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|extensibility.dll
Extensibility,Version="7.0.3300.0",Culture="neutral",PublicKeyToken="B03F5F7F11D50A3A",ProcessorArchitecture="MSIL"
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|System.Net.Http.Extensions.dll
System.Net.Http.Extensions,Version="2.2.29.0",Culture="neutral",PublicKeyToken="B03F5F7F11D50A3A",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>9E+.tF?XT29qQL,p])fS
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|System.Threading.Tasks.dll
System.Threading.Tasks,Version="2.6.10.0",Culture="neutral",PublicKeyToken="B03F5F7F11D50A3A",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>.ibdm54o^U-&+GH{0T^p
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|System.Net.Http.WebRequest.dll
System.Net.Http.WebRequest,Version="2.2.29.0",Culture="neutral",PublicKeyToken="B03F5F7F11D50A3A",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>9$WmePHNc^gt)P=!xdsw
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|XPExplorerBar.dll
XPExplorerBar,Version="3.6.0.0",Culture="neutral",PublicKeyToken="26272737B5F33015",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>.U'yCH}Jk^[email protected]_bu,}+
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|HtmlAgilityPack.dll
HtmlAgilityPack,Version="1.6.17.0",Culture="neutral",PublicKeyToken="BD319B19EAF3B43A",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>HG,7wph]0dutFn,[email protected]
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Microsoft.Threading.Tasks.Extensions.dll
Microsoft.Threading.Tasks.Extensions,Version="1.0.12.0",Culture="neutral",PublicKeyToken="B03F5F7F11D50A3A",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>B{I1k&*uFV!le.X!PCXy
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|gSyncit.core.dll
gSyncit.core,Version="5.3.21.0",Culture="neutral",ProcessorArchitecture="x86"
o`([email protected]@BJMX+c^P6>GyiS*w)*F3}9%w'.0_J!
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Google.Apis.Calendar.v3.dll
Google.Apis.Calendar.v3,Version="1.36.1.1391",Culture="neutral",PublicKeyToken="4B01FA6E34DB77AB",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>!QE-{IpeXJRS1P_I*m]+
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|GoogleLib2.dll
GoogleLib2,Version="3.108.0.0",Culture="neutral",ProcessorArchitecture="MSIL"
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|System.Data.SQLite.dll
System.Data.SQLite,Version="1.0.105.2",Culture="neutral",PublicKeyToken="DB937BC2D44FF139",ProcessorArchitecture="x86"
o`([email protected]@BJMX+c^P6>t'mC=%dh4t.PUjteoIkO
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|S22.Imap.dll
S22.Imap,Version="3.45.0.0",Culture="neutral",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>[{KDM^h=[Myuk`3(U+N`
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|SqliteCache.dll
SqliteCache,Version="2.91.0.0",Culture="neutral",PublicKeyToken="D8831E73FE340B79",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>er0bMA.u'Jb(*kD]US&6
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|SharpNoteLib.dll
SharpNoteLib,Version="2.4.0.0",Culture="neutral",PublicKeyToken="EED502AD33CCF34B",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>==KzL]n{Sy0![QC=HEVe
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Google.Apis.Drive.v2.dll
Google.Apis.Drive.v2,Version="1.36.1.1390",Culture="neutral",PublicKeyToken="4B01FA6E34DB77AB",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>'f8?M?mM]v[~=3SpU1*7
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|ICSharpCode.SharpZipLib.dll
ICSharpCode.SharpZipLib,Version="0.86.0.518",Culture="neutral",PublicKeyToken="1B03E6ACF1164F73",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>rwN8-5I8!f14X8PH&`yj
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Microsoft.Office.Interop.Outlook.dll
Microsoft.Office.Interop.Outlook,Version="15.0.0.0",Culture="neutral",PublicKeyToken="71E9BCE111E9429C",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>+E.mx1~MBR^[_F]TSvWy
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|OFFICE.DLL
office,Version="15.0.0.0",Culture="neutral",PublicKeyToken="71E9BCE111E9429C",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>Ruz{ie,N6`FCq?(=So+L
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Google.GData.Extensions.dll
Google.GData.Extensions,Version="2.2.0.0",Culture="neutral",PublicKeyToken="0B4C5DF2EBF20876",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>'_co?`-LS``UV8_D]`=&
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|WebDavLib.dll
WebDavLib,Version="2.143.0.0",Culture="neutral",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>``a=xOoqjTdPt}GTw$6+
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|FileCache.Signed.dll
FileCache.Signed,Version="2.0.1.0",Culture="neutral",PublicKeyToken="7542C4E7F6A4D381",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>DVebhRv3sd4WFy5lqI0i
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|DropBoxLib.dll
DropBoxLib,Version="3.0.0.0",Culture="neutral",PublicKeyToken="CC628EB0558D221A",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>W_5_kDKvWQh`Yw635SVC
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Zlib.Portable.dll
Zlib.Portable,Version="1.11.0.0",Culture="neutral",PublicKeyToken="431CBA815F6A8B5B",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>*c*z3X}N4I_C_CG2mv*,
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|WizardLib.dll
WizardLib,Version="1.1.0.0",Culture="neutral",PublicKeyToken="B90E4D61E0685435",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>}ipGP!.4k!aP-C3(R)3Z
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Google.GData.Contacts.dll
Google.GData.Contacts,Version="2.2.0.0",Culture="neutral",PublicKeyToken="7E065189DD4B982F",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>aA?-6ba3cRi`JPGz1LS6
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|TodoistLib.dll
TodoistLib,Version="1.36.0.0",Culture="neutral",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>[email protected][0t6WM+o{wm,l
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Microsoft.Threading.Tasks.Extensions.Desktop.dll
Microsoft.Threading.Tasks.Extensions.Desktop,Version="1.0.168.0",Culture="neutral",PublicKeyToken="B03F5F7F11D50A3A",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>c.`8cVWo5[gbkX?Z9&FW
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Google.Apis.Auth.dll
Google.Apis.Auth,Version="1.10.0.25333",Culture="neutral",PublicKeyToken="4B01FA6E34DB77AB",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>y{37!Qp22l7{ELzesWO+
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Google.Apis.Core.dll
Google.Apis.Core,Version="1.10.0.25331",Culture="neutral",PublicKeyToken="4B01FA6E34DB77AB",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>Fj13mSsxw,3bjr+O-w!F
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Dropbox.Api.dll
Dropbox.Api,Version="4.0.0.0",Culture="neutral",PublicKeyToken="310F0E82FBB45D01",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>YJl+&-Bt'c'O8CYo(UD]
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|NozbeLib.dll
NozbeLib,Version="2.5.0.0",Culture="neutral",PublicKeyToken="5BB3D9AB63D9604A",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>8vaff&FegtTsaOj[tUE^
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Google.GData.Client.dll
Google.GData.Client,Version="2.2.0.0",Culture="neutral",PublicKeyToken="04A59CA9B0273830",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>akN3e~Gux03i_dnYa6nr
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|System.Net.Http.Primitives.dll
System.Net.Http.Primitives,Version="2.2.29.0",Culture="neutral",PublicKeyToken="B03F5F7F11D50A3A",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>wGUQK+Q?&6QDVTL6n(c!
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Thrift.dll
Thrift,Version="2.4.0.0",Culture="neutral",PublicKeyToken="3603712D927D1C1D",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>+hpJ`X8'~z[&CR+y[b^A
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|System.Runtime.dll
System.Runtime,Version="2.6.10.0",Culture="neutral",PublicKeyToken="B03F5F7F11D50A3A",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>Czb*AjW{7(wfmQ[0-iEv
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|PocketInformantLib2.dll
PocketInformantLib2,Version="3.15.0.0",Culture="neutral",PublicKeyToken="13C29041AF3CAA0A",ProcessorArchitecture="MSIL"
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|ObjectCache.dll
ObjectCache,Version="2.91.0.0",Culture="neutral",PublicKeyToken="311826E6D5378127",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>Vh{Y-MxQ1-Fx*dd`!7p1
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|System.IO.dll
System.IO,Version="2.6.10.0",Culture="neutral",PublicKeyToken="B03F5F7F11D50A3A",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>9qP-KWXCoaW9WDhT`[?5
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Evernote.dll
Evernote,Version="2.5.0.0",Culture="neutral",PublicKeyToken="47F5F7499D7AD128",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>X`]9?vVbbl%[email protected]
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|EvernoteLib.dll
EvernoteLib,Version="2.12.0.0",Culture="neutral",PublicKeyToken="ED54753DBF115322",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>7MMMi7u.fHybbSdh]iwf
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Google.Apis.dll
Google.Apis,Version="1.10.0.25332",Culture="neutral",PublicKeyToken="4B01FA6E34DB77AB",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>T^h]iINUg]^UJ!vSDURj
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|ToodledoLib3.dll
ToodledoLib3,Version="2.115.0.0",Culture="neutral",PublicKeyToken="A728245C1C1B2F9F",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>^RXzso4+4?yx[[email protected]
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|stdole.dll
stdole,Version="7.0.3300.0",Culture="neutral",PublicKeyToken="B03F5F7F11D50A3A",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>Ml6b-%vHijP=zO9Paj[Q
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Microsoft.Threading.Tasks.dll
Microsoft.Threading.Tasks,Version="1.0.12.0",Culture="neutral",PublicKeyToken="B03F5F7F11D50A3A",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>{1mFOScq^vh(sfa^L0)m
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Google.Apis.Tasks.v1.dll
Google.Apis.Tasks.v1,Version="1.36.1.0",Culture="neutral",PublicKeyToken="4B01FA6E34DB77AB",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>}=.X7Yx_Jud,7ved}RUF
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|RestSharp.dll
RestSharp,Version="101.3.0.0",Culture="neutral",PublicKeyToken="984CD78A38ED2B7D",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>}l-BULcrpK0$9ZTfuCC.
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Newtonsoft.Json.Net35.dll
Newtonsoft.Json.Net35,Version="4.0.2.0",Culture="neutral",PublicKeyToken="30AD4FE6B2A6AEED",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>l}mVl8~0LB4tokwme[,F
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|System.Net.Http.dll
System.Net.Http,Version="2.2.29.0",Culture="neutral",PublicKeyToken="B03F5F7F11D50A3A",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>2`b'C9qedGvCL$0i)X'2
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Google.Apis.PeopleService.v1.dll
Google.Apis.PeopleService.v1,Version="1.36.1.1397",Culture="neutral",PublicKeyToken="4B01FA6E34DB77AB",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>gl_an4K$)^Qmy^UdAHnw
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|gsyncit.addin.dll
gsyncit.addin,Version="5.3.21.0",Culture="neutral",ProcessorArchitecture="x86"
o`([email protected]@BJMX+c^P6>}Ni(mG}BiwZI.H5T*px(
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|gsyncit.exe
gsyncit,Version="5.3.21.0",Culture="neutral",ProcessorArchitecture="x86"
o`([email protected]@BJMX+c^P6>aPJ]NYhma3q'8EN(m&{g
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|gsyncit.updater.exe
gsyncit.updater,Version="5.3.21.0",Culture="neutral",PublicKeyToken="906CE6B0AE8E6383",ProcessorArchitecture="MSIL"
o`([email protected]@BJMX+c^P6>v)8!?O^J+^)xjPHSar_m
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\21B564291C5433C4DB167B691941E793
DefaultFeature
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\Features
DefaultFeature
[email protected]'b[FzXdkk}pi4r?B7.X_KMczG=S[ru`([email protected][f$3B7gZ89E+.tF?XT29qQL,p])fS.ibdm54o^U-&+GH{0T^p9$WmePHNc^gt)P=!xdsw.U'yCH}Jk^[email protected]_bu,}+HG,7wph]0dutFn,[email protected]@9DaR'b[FzXdkk}piB{I1k&*uFV!le.X!PCXyGyiS*w)*F3}9%w'.0_J!!QE-{IpeXJRS1P_I*m]+3xzLI&[email protected]][email protected]'0x2.nf6Dyt'mC=%dh4t.PUjteoIkO[{KDM^h=[Myuk`3(U+N`er0bMA.u'Jb(*kD]US&6==KzL]n{Sy0![QC=HEVeHG,7wph]0dutFn,[email protected][G4Pbw_wG4rpu{4vz'f8?M?mM]v[~=3SpU1*7rwN8-5I8!f14X8PH&`yj+E.mx1~MBR^[_F]TSvWyRuz{ie,N6`FCq?(=So+L'_co?`-LS``UV8_D]`=&``a=xOoqjTdPt}GTw$6+DVebhRv3sd4WFy5lqI0iW_5_kDKvWQh`Yw635SVC*c*z3X}N4I_C_CG2mv*,}ipGP!.4k!aP-C3(R)3ZaA?-6ba3cRi`JPGz1LS6t'mC=%[email protected][0t6WM+o{wm,[email protected]~!Af&'cCG3o(HDRc.`8cVWo5[gbkX?Z9&FWy{37!Qp22l7{ELzesWO+Fj13mSsxw,3bjr+O-w!FYJl+&-Bt'c'O8CYo(UD]8vaff&FegtTsaOj[tUE^er0bMA.u'Jb(*kD]US&6akN3e~Gux03i_dnYa6nrDx%^Mp4NEo0HfP,EQ58IwGUQK+Q?&6QDVTL6n(c!+hpJ`X8'~z[&CR+y[b^ACzb*AjW{7(wfmQ[0-iEv[[email protected]`ZK$7JVh{Y-MxQ1-Fx*dd`!7p19qP-KWXCoaW9WDhT`[?5X`]9?vVbbl%[email protected]]iwf*c*z3X}N4I_C_CG2mv*,T^h]iINUg]^UJ!vSDURj^RXzso4+4?yx[[email protected]%vHijP=zO9Paj[Q{1mFOScq^vh(sfa^L0)m}=.X7Yx_Jud,7ved}RUF}l-BULcrpK0$9ZTfuCC.l}mVl8~0LB4tokwme[,F2`b'C9qedGvCL$0i)X'2gl_an4K$)^Qmy^UdAHnw]xkLJpw)Cti%6(%4rM6A,FS`xRr4wM4Sq65=L(&DRYBBMUq5A?,W8$P$E=$*t!8?[%q]W.k1+M`[email protected]}k=I],NjPhk`W]4K8PzTC~!TrTyKWTe(aoEHuM.9W(@i8)IJRCB]+^(qS_7Ah+0ptSI,$8QPj{7^]t)-?%i2n+fuQJC6zN60J0H([email protected]!j.e8YWFeCjvSqPNIG+`aD!eTYiMdAJ`7EhQ9h999JsYfKmz6kRAN1xKP^ERDox.%Rv,-'njE%Oy`822y$*x1Phe&Lua4Li1aA}J6$LhxWCB$pR[w3]cD~4mr`D99a&sy^QILc!DxG{[email protected]$]y=lvmrzjxdeK7J+YlMpZ?`R4uxu!7[qxD$W(iN0UM~h*o1fMaXHR[2di{{QzPQ1OK`t'{?K1ge)$5Z_hq{^Nj*s50]pGWhLx0[wqe9)ysPk_,KGff[[email protected]'1)'MfQkQK.u*T9l]z`4(PYqFPCrIey6?qsgmA^58hny0Bbb29nSr?]`o7k6Rz'?Wxzihbh`CF]]mxi7hNqs74L'}rrZDLe-QJM7'c8]YOJTHagp2F[)xX44zq]TpEA47ktWf_!Nz6978].Jy-?0[EqHD'Z?*!{v(!O}1]EfHZ}Ni(mG}BiwZI.H5T*px(zfQ^W39lwEV)xA5'N{?]yMYH]@XWG6BEDkCr2)wKaPJ]NYhma3q'8EN(m&{gBxt=r`Wy[l*zXew'7MHNv)8!?O^J+^)xjPHSar_m-?Ij63^M=4F(I*+1LFLj
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\Patches
AllPatches
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\21B564291C5433C4DB167B691941E793
ProductName
gSyncit
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\21B564291C5433C4DB167B691941E793
PackageCode
E64C6E571C29867489BE895FD8421F52
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\21B564291C5433C4DB167B691941E793
Language
1033
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\21B564291C5433C4DB167B691941E793
Version
84082709
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\21B564291C5433C4DB167B691941E793
Assignment
1
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\21B564291C5433C4DB167B691941E793
AdvertiseFlags
388
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\21B564291C5433C4DB167B691941E793
ProductIcon
C:\Windows\Installer\{92465B12-45C1-4C33-BD61-B79691147E39}\_853F67D554F05449430E7E.exe
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\21B564291C5433C4DB167B691941E793
InstanceType
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\21B564291C5433C4DB167B691941E793
AuthorizedLUAApp
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\21B564291C5433C4DB167B691941E793
DeploymentFlags
2
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\AD1D8ED4159C0374B9595700163D6677
21B564291C5433C4DB167B691941E793
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\21B564291C5433C4DB167B691941E793\SourceList
PackageName
gSyncit_5_3_21.msi
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\21B564291C5433C4DB167B691941E793\SourceList\Net
1
C:\Users\admin\Downloads\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\21B564291C5433C4DB167B691941E793\SourceList\Media
1
;
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\21B564291C5433C4DB167B691941E793
Clients
:
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\21B564291C5433C4DB167B691941E793\SourceList
LastUsedSource
n;1;C:\Users\admin\Downloads\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings
StringCacheGeneration
96
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\Volatile
NestingLevel
0
3948
MsiExec.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3948
MsiExec.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
IDENTIFY (Enter)
4000000000000000249DDBE291A9D4018C0F0000200E0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
IDENTIFY (Enter)
4000000000000000249DDBE291A9D4018C0F0000E4090000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
IDENTIFY (Enter)
4000000000000000249DDBE291A9D4018C0F0000E8090000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
IDENTIFY (Enter)
4000000000000000249DDBE291A9D4018C0F00000C0E0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
IDENTIFY (Leave)
400000000000000032C4E2E291A9D4018C0F0000E8090000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
IDENTIFY (Leave)
40000000000000008C26E5E291A9D4018C0F0000200E0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
IDENTIFY (Leave)
4000000000000000E688E7E291A9D4018C0F0000E4090000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
IDENTIFY (Leave)
40000000000000009A4DECE291A9D4018C0F00000C0E0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_BEGINPREPARE (Enter)
4000000000000000C2C601EB91A9D4018C0F00000C0E0000010400000100000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_BEGINPREPARE (Leave)
4000000000000000C2C601EB91A9D4018C0F00000C0E0000010400000000000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPAREBACKUP (Enter)
4000000000000000DE1410EB91A9D4018C0F00000C0E0000E90300000100000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPAREBACKUP (Enter)
4000000000000000DE1410EB91A9D4018C0F0000E4090000E90300000100000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPAREBACKUP (Enter)
4000000000000000DE1410EB91A9D4018C0F0000200E0000E90300000100000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPAREBACKUP (Leave)
400000000000000092D914EB91A9D4018C0F00000C0E0000E90300000000000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_STABLE (SetCurrentState)
400000000000000092D914EB91A9D4018C0F00000C0E0000010000000100000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPAREBACKUP (Leave)
400000000000000092D914EB91A9D4018C0F0000200E0000E90300000000000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_STABLE (SetCurrentState)
400000000000000092D914EB91A9D4018C0F0000200E0000010000000100000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPAREBACKUP (Leave)
400000000000000092D914EB91A9D4018C0F0000E4090000E90300000000000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_STABLE (SetCurrentState)
400000000000000092D914EB91A9D4018C0F0000E4090000010000000100000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
GETSTATE (Enter)
40000000000000007E3A36EB91A9D4018C0F0000E4090000F90300000100000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
GETSTATE (Enter)
40000000000000007E3A36EB91A9D4018C0F0000200E0000F90300000100000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
GETSTATE (Enter)
40000000000000007E3A36EB91A9D4018C0F00000C0E0000F90300000100000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
GETSTATE (Leave)
40000000000000007E3A36EB91A9D4018C0F00000C0E0000F90300000000000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
GETSTATE (Leave)
40000000000000007E3A36EB91A9D4018C0F0000200E0000F90300000000000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
GETSTATE (Leave)
40000000000000007E3A36EB91A9D4018C0F0000E4090000F90300000000000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_ENDPREPARE (Enter)
40000000000000008C613DEB91A9D4018C0F0000400A0000020400000100000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_ENDPREPARE (Leave)
4000000000000000C0BCDAEB91A9D4018C0F0000400A0000020400000000000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
PREPARESNAPSHOT (Enter)
4000000000000000C0BCDAEB91A9D4018C0F0000400A0000EA0300000100000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPARESNAPSHOT (Enter)
4000000000000000366DEBEB91A9D4018C0F0000040A0000EA0300000100000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPARESNAPSHOT (Enter)
4000000000000000366DEBEB91A9D4018C0F00000C0A0000EA0300000100000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPARESNAPSHOT (Enter)
4000000000000000366DEBEB91A9D4018C0F0000EC090000EA0300000100000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPARESNAPSHOT (Leave)
400000000000000060E200EC91A9D4018C0F00000C0A0000EA0300000000000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)
400000000000000060E200EC91A9D4018C0F00000C0A0000020000000100000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPARESNAPSHOT (Leave)
400000000000000014A705EC91A9D4018C0F0000040A0000EA0300000000000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)
400000000000000014A705EC91A9D4018C0F0000040A0000020000000100000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPARESNAPSHOT (Leave)
400000000000000014A705EC91A9D4018C0F0000EC090000EA0300000000000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)
400000000000000014A705EC91A9D4018C0F0000EC090000020000000100000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
PREPARESNAPSHOT (Leave)
400000000000000084DF3EEC91A9D4018C0F0000400A0000EA0300000000000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE (Enter)
400000000000000084DF3EEC91A9D4018C0F0000400A0000EB0300000100000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_FRONT (Enter)
400000000000000084DF3EEC91A9D4018C0F0000400A0000EC0300000100000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
FREEZE (Enter)
4000000000000000920646EC91A9D4018C0F0000080A0000EB0300000100000002000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
FREEZE (Leave)
4000000000000000920646EC91A9D4018C0F0000080A0000EB0300000000000002000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_WAITING_FOR_THAW (SetCurrentState)
4000000000000000920646EC91A9D4018C0F0000080A0000030000000100000002000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
BKGND_FREEZE_THREAD (Enter)
4000000000000000920646EC91A9D4018C0F0000200B0000FC0300000100000003000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_FRONT (Leave)
4000000000000000920646EC91A9D4018C0F0000400A0000EC0300000000000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_BACK (Enter)
4000000000000000920646EC91A9D4018C0F0000400A0000ED0300000100000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_BACK (Leave)
4000000000000000A02D4DEC91A9D4018C0F0000400A0000ED0300000000000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_SYSTEM (Enter)
4000000000000000A02D4DEC91A9D4018C0F0000400A0000EE0300000100000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
FREEZE (Enter)
400000000000000054F251EC91A9D4018C0F0000040A0000EB0300000100000002000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
FREEZE (Leave)
400000000000000054F251EC91A9D4018C0F0000040A0000EB0300000000000002000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_WAITING_FOR_THAW (SetCurrentState)
400000000000000054F251EC91A9D4018C0F0000040A0000030000000100000002000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
BKGND_FREEZE_THREAD (Enter)
400000000000000054F251EC91A9D4018C0F0000E80A0000FC0300000100000003000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_SYSTEM (Leave)
400000000000000008B756EC91A9D4018C0F0000400A0000EE0300000000000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_KTM (Enter)
400000000000000008B756EC91A9D4018C0F0000400A0000F00300000100000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_KTM (Leave)
400000000000000008B756EC91A9D4018C0F0000400A0000F00300000000000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_RM (Enter)
400000000000000008B756EC91A9D4018C0F0000400A0000EF0300000100000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
FREEZE (Enter)
4000000000000000BC7B5BEC91A9D4018C0F0000080A0000EB0300000100000002000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
FREEZE (Leave)
4000000000000000CAA262EC91A9D4018C0F0000080A0000EB0300000000000002000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_WAITING_FOR_THAW (SetCurrentState)
4000000000000000CAA262EC91A9D4018C0F0000080A0000030000000100000002000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
BKGND_FREEZE_THREAD (Enter)
4000000000000000CAA262EC91A9D4018C0F00008C0C0000FC0300000100000003000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_RM (Leave)
4000000000000000CAA262EC91A9D4018C0F0000400A0000EF0300000000000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE (Leave)
4000000000000000CAA262EC91A9D4018C0F0000400A0000EB0300000000000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_PRECOMMIT (Enter)
4000000000000000CAA262EC91A9D4018C0F0000400A0000030400000100000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_PRECOMMIT (Leave)
4000000000000000CAA262EC91A9D4018C0F0000400A0000030400000000000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
OPEN_VOLUME_HANDLE (Enter)
4000000000000000CAA262EC91A9D4018C0F0000400A0000FD0300000100000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
OPEN_VOLUME_HANDLE (Enter)
4000000000000000CAA262EC91A9D4018C0F0000840C0000FD0300000100000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
OPEN_VOLUME_HANDLE (Leave)
4000000000000000322C6CEC91A9D4018C0F0000840C0000FD0300000000000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
OPEN_VOLUME_HANDLE (Leave)
4000000000000000322C6CEC91A9D4018C0F0000400A0000FD0300000000000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
IOCTL_FLUSH_AND_HOLD (Enter)
4000000000000000322C6CEC91A9D4018C0F0000840C0000FE0300000100000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
IOCTL_FLUSH_AND_HOLD (Leave)
4000000000000000405373EC91A9D4018C0F0000840C0000FE0300000000000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
IOCTL_RELEASE (Enter)
4000000000000000405373EC91A9D4018C0F0000840C0000FF0300000100000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
IOCTL_RELEASE (Leave)
4000000000000000405373EC91A9D4018C0F0000840C0000FF0300000000000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
IOCTL_FLUSH_AND_HOLD (Enter)
4000000000000000322C6CEC91A9D4018C0F0000400A0000FE0300000100000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
IOCTL_FLUSH_AND_HOLD (Leave)
4000000000000000405373EC91A9D4018C0F0000400A0000FE0300000000000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
IOCTL_RELEASE (Enter)
4000000000000000405373EC91A9D4018C0F0000400A0000FF030000010000000000000000000000000000000000000000000000000000000000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
IOCTL_RELEASE (Leave)
4000000000000000405373EC91A9D4018C0F0000400A0000FF030000000000000000000000000000000000000000000000000000000000000000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_COMMIT (Enter)
4000000000000000405373EC91A9D4018C0F0000800C0000040400000100000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_COMMIT (Leave)
4000000000000000405373EC91A9D4018C0F0000800C0000040400000000000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_POSTCOMMIT (Enter)
4000000000000000405373EC91A9D4018C0F0000400A0000050400000100000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_POSTCOMMIT (Leave)
4000000000000000F41778EC91A9D4018C0F0000400A0000050400000000000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
THAW_KTM (Enter)
4000000000000000F41778EC91A9D4018C0F0000400A0000F40300000100000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
THAW_KTM (Leave)
4000000000000000F41778EC91A9D4018C0F0000400A0000F40300000000000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
THAW (Enter)
4000000000000000F41778EC91A9D4018C0F0000400A0000F20300000100000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
THAW (Enter)
40000000000000005CA181EC91A9D4018C0F0000040A0000F20300000100000003000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
BKGND_FREEZE_THREAD (Leave)
40000000000000005CA181EC91A9D4018C0F00008C0C0000FC0300000000000003000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
THAW (Leave)
40000000000000005CA181EC91A9D4018C0F0000040A0000F20300000000000003000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_WAITING_FOR_POST_SNAPSHOT (SetCurrentState)
40000000000000005CA181EC91A9D4018C0F0000040A0000040000000100000003000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
THAW (Enter)
40000000000000005CA181EC91A9D4018C0F0000080A0000F20300000100000003000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
BKGND_FREEZE_THREAD (Leave)
40000000000000005CA181EC91A9D4018C0F0000200B0000FC0300000000000003000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
THAW (Enter)
40000000000000005CA181EC91A9D4018C0F0000EC090000F20300000100000003000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
BKGND_FREEZE_THREAD (Leave)
40000000000000005CA181EC91A9D4018C0F0000E80A0000FC0300000000000003000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
THAW (Leave)
40000000000000005CA181EC91A9D4018C0F0000080A0000F20300000000000003000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_WAITING_FOR_POST_SNAPSHOT (SetCurrentState)
40000000000000005CA181EC91A9D4018C0F0000080A0000040000000100000003000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
THAW (Leave)
40000000000000005CA181EC91A9D4018C0F0000EC090000F20300000000000003000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_WAITING_FOR_POST_SNAPSHOT (SetCurrentState)
40000000000000005CA181EC91A9D4018C0F0000EC090000040000000100000003000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
THAW (Leave)
40000000000000005CA181EC91A9D4018C0F0000400A0000F20300000000000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_PREFINALCOMMIT (Enter)
40000000000000005CA181EC91A9D4018C0F0000400A0000060400000100000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_PREFINALCOMMIT (Leave)
40000000000000002EEBECEC91A9D4018C0F0000400A0000060400000000000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
POSTSNAPSHOT (Enter)
40000000000000002EEBECEC91A9D4018C0F0000400A0000F50300000100000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
POSTSNAPSHOT (Enter)
4000000000000000F0D6F8EC91A9D4018C0F0000EC090000F50300000100000004000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
POSTSNAPSHOT (Enter)
4000000000000000F0D6F8EC91A9D4018C0F00000C0A0000F50300000100000004000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
POSTSNAPSHOT (Enter)
4000000000000000F0D6F8EC91A9D4018C0F0000080A0000F50300000100000004000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
POSTSNAPSHOT (Leave)
4000000000000000F0D6F8EC91A9D4018C0F0000080A0000F50300000000000004000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_WAITING_FOR_BACKUP_COMPLETE (SetCurrentState)
4000000000000000F0D6F8EC91A9D4018C0F0000080A0000050000000100000004000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
POSTSNAPSHOT (Leave)
4000000000000000F0D6F8EC91A9D4018C0F00000C0A0000F50300000000000004000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_WAITING_FOR_BACKUP_COMPLETE (SetCurrentState)
4000000000000000F0D6F8EC91A9D4018C0F00000C0A0000050000000100000004000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
POSTSNAPSHOT (Leave)
4000000000000000491ECFED91A9D4018C0F0000EC090000F50300000000000004000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_WAITING_FOR_BACKUP_COMPLETE (SetCurrentState)
4000000000000000491ECFED91A9D4018C0F0000EC090000050000000100000004000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
POSTSNAPSHOT (Leave)
4000000000000000491ECFED91A9D4018C0F0000400A0000F50300000000000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_POSTFINALCOMMIT (Enter)
4000000000000000491ECFED91A9D4018C0F0000400A0000070400000100000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_POSTFINALCOMMIT (Leave)
40000000000000001137E6ED91A9D4018C0F0000400A0000070400000000000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
BACKUPSHUTDOWN (Enter)
4000000000000000E943F5ED91A9D4018C0F0000400A0000FB0300000100000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
BACKUPSHUTDOWN (Enter)
40000000000000000770F9ED91A9D4018C0F0000EC090000FB0300000100000005000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
BACKUPSHUTDOWN (Leave)
40000000000000000770F9ED91A9D4018C0F0000EC090000FB0300000000000005000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
BACKUPSHUTDOWN (Enter)
40000000000000000770F9ED91A9D4018C0F0000040A0000FB0300000100000005000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
BACKUPSHUTDOWN (Enter)
40000000000000000770F9ED91A9D4018C0F00000C0A0000FB0300000100000005000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
BACKUPSHUTDOWN (Leave)
40000000000000000770F9ED91A9D4018C0F0000040A0000FB0300000000000005000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
BACKUPSHUTDOWN (Leave)
40000000000000000770F9ED91A9D4018C0F00000C0A0000FB0300000000000005000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
BACKUPSHUTDOWN (Leave)
400000000000000052BCF9ED91A9D4018C0F0000400A0000FB0300000000000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
2640
DrvInst.exe
write
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
3492
gsyncit.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109A10090400000000000F01FEC\Usage
OutlookMAPI2Intl_1033
1311440917
3492
gsyncit.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
Off
3492
gsyncit.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
On
3200
OUTLOOK.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems
3200
OUTLOOK.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018082720180903
3200
OUTLOOK.EXE
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018090920180910
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
Off
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
1033
On
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems
$;$
243B2400800C0000010000000000000000000000
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook
MTTT
800C000048A762F591A9D40100000000
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\SQM
SQMSessionNumber
0
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\SQM
SQMSessionDate
219860640
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\NoMail\0a0d020000000000c000000000000046
00030429
03000000
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\NoMail\9375CFF0413111d3B88A00104B2A6676
{ED475418-B0D6-11D2-8C3B-00104B2A6676}
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\NoMail\9375CFF0413111d3B88A00104B2A6676
LastChangeVer
1200000000000000
3200
OUTLOOK.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109A10090400000000000F01FEC\Usage
OutlookMAPI2Intl_1033
1311440918
3200
OUTLOOK.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
OUTLOOKFiles
1311440942
3200
OUTLOOK.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
ProductFiles
1311441040
3200
OUTLOOK.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109A10090400000000000F01FEC\Usage
OUTLOOKFilesIntl_1033
1311440919
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Display Types\Balloons
HWND64ForOrphanedNotIcon
F0000500
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems
j"$
6A222400800C0000020000000000000000010000010000008C0000006800000063003A005C00700072006F006700720061006D002000660069006C00650073005C006D006900630072006F0073006F006600740020006F00660066006900630065005C006F0066006600690063006500310034005C0061006400640069006E0073005C0063006F006C006C006500610067007500650069006D0070006F00720074002E0064006C006C0000006D006900630072006F0073006F006600740020007300680061007200650070006F0069006E0074002000730065007200760065007200200063006F006C006C0065006100670075006500200069006D0070006F007200740020006100640064002D0069006E000000
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems
8"$
38222400800C00000200000000000000BE00000001000000840000002E00000063003A005C00700072006F006700720061006D002000660069006C00650073005C006600690065006C006400730074006F006E00200073006F006600740077006100720065005C006700730079006E006300690074005C006700730079006E006300690074002E0061006400640069006E007300680069006D002E0064006C006C0000006700730079006E0063006900740020006F00750074006C006F006F006B0020006100640064002D0069006E000000
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0468C085-CA5B-11D0-AF08-00609797F0E0}\iexplore
Type
1
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0468C085-CA5B-11D0-AF08-00609797F0E0}\iexplore
Count
4
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0468C085-CA5B-11D0-AF08-00609797F0E0}\iexplore
Time
E307010005000B0009002A001C000402
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0468C085-CA5B-11D0-AF08-00609797F0E0}\iexplore
Count
5
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0468C085-CA5B-11D0-AF08-00609797F0E0}\iexplore
Count
6
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019011120190112
CachePath
%USERPROFILE%\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019011120190112
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019011120190112
CachePrefix
:2019011120190112:
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019011120190112
CacheLimit
8192
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019011120190112
CacheOptions
11
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019011120190112
CacheRepair
0
3200
OUTLOOK.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage
OUTLOOKNonBootFiles
1311440900
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Search
C:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst
3664425
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems
yz$
797A2400800C00000200000000000000C000000001000000700000004400000063003A005C00700072006F006700720061006D002000660069006C00650073005C006D006900630072006F0073006F006600740020006F00660066006900630065005C006F0066006600690063006500310034005C006F006E006200740074006E006F006C002E0064006C006C0000006F006E0065006E006F007400650020006E006F007400650073002000610062006F007500740020006F00750074006C006F006F006B0020006900740065006D0073000000
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems
({$
287B2400800C00000200000000000000D0000000010000007E0000004600000063003A005C00700072006F006700720061006D002000660069006C00650073005C006D006900630072006F0073006F006600740020006F00660066006900630065005C006F0066006600690063006500310034005C0073006F006300690061006C0063006F006E006E006500630074006F0072002E0064006C006C0000006D006900630072006F0073006F006600740020006F00750074006C006F006F006B00200073006F006300690061006C00200063006F006E006E006500630074006F0072000000
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems
e{$
657B2400800C00000200000000000000CA000000010000008A0000003400000063003A005C00700072006F006700720061006D002000660069006C00650073005C006D006900630072006F0073006F006600740020006F00660066006900630065005C006F0066006600690063006500310034005C0061006400640069006E0073005C0075006D006F00750074006C006F006F006B0061006400640069006E002E0064006C006C0000006D006900630072006F0073006F00660074002000650078006300680061006E006700650020006100640064002D0069006E000000
3200
OUTLOOK.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109A10090400000000000F01FEC\Usage
OUTLOOKFilesIntl_1033
1311440920
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems
b|$
627C2400800C00000200000000000000BE00000001000000840000002E00000063003A005C00700072006F006700720061006D002000660069006C00650073005C006600690065006C006400730074006F006E00200073006F006600740077006100720065005C006700730079006E006300690074005C006700730079006E006300690074002E0061006400640069006E007300680069006D002E0064006C006C0000006700730079006E0063006900740020006F00750074006C006F006F006B0020006100640064002D0069006E000000
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\CustomUIValidationCache
gSyncit.Connect.Microsoft.Outlook.Explorer
3254034470
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems
0|$
307C2400800C00000200000000000000C000000001000000700000004400000063003A005C00700072006F006700720061006D002000660069006C00650073005C006D006900630072006F0073006F006600740020006F00660066006900630065005C006F0066006600690063006500310034005C006F006E006200740074006E006F006C002E0064006C006C0000006F006E0065006E006F007400650020006E006F007400650073002000610062006F007500740020006F00750074006C006F006F006B0020006900740065006D0073000000
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems
?|$
3F7C2400800C00000200000000000000D0000000010000007E0000004600000063003A005C00700072006F006700720061006D002000660069006C00650073005C006D006900630072006F0073006F006600740020006F00660066006900630065005C006F0066006600690063006500310034005C0073006F006300690061006C0063006F006E006E006500630074006F0072002E0064006C006C0000006D006900630072006F0073006F006600740020006F00750074006C006F006F006B00200073006F006300690061006C00200063006F006E006E006500630074006F0072000000
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems
?|$
3F7C2400800C00000200000000000000CA000000010000008A0000003400000063003A005C00700072006F006700720061006D002000660069006C00650073005C006D006900630072006F0073006F006600740020006F00660066006900630065005C006F0066006600690063006500310034005C0061006400640069006E0073005C0075006D006F00750074006C006F006F006B0061006400640069006E002E0064006C006C0000006D006900630072006F0073006F00660074002000650078006300680061006E006700650020006100640064002D0069006E000000
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems
n|$
6E7C2400800C00000200000000000000CA000000010000008A0000003400000063003A005C00700072006F006700720061006D002000660069006C00650073005C006D006900630072006F0073006F006600740020006F00660066006900630065005C006F0066006600690063006500310034005C0061006400640069006E0073005C0075006D006F00750074006C006F006F006B0061006400640069006E002E0064006C006C0000006D006900630072006F0073006F00660074002000650078006300680061006E006700650020006100640064002D0069006E000000
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Resiliency\StartupItems
,}$
2C7D2400800C00000200000000000000CA000000010000008A0000003400000063003A005C00700072006F006700720061006D002000660069006C00650073005C006D006900630072006F0073006F006600740020006F00660066006900630065005C006F0066006600690063006500310034005C0061006400640069006E0073005C0075006D006F00750074006C006F006F006B0061006400640069006E002E0064006C006C0000006D006900630072006F0073006F00660074002000650078006300680061006E006700650020006100640064002D0069006E000000
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\SocialConnector
CleanupFolder
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\{982D0F34-1476-4313-A67A-7555DB74D4FD}
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\SocialConnector
AlertTypes
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\SocialConnector
RestartsSinceAlerts
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\Outlook\SocialConnector
AlertInsertStrings
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\F4817C20F6BD6C4D99A01DEF0B65CE4A
WriterId
4744375
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\F4817C20F6BD6C4D99A01DEF0B65CE4A
LastModification
D0BEC2805A48D401
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\F4817C20F6BD6C4D99A01DEF0B65CE4A
MsgEID
00000000EE353A6753D116479D0919B95E8B889A88001000
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Identities
Identity Ordinal
2
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\31059442FE01C744942DBC0CDDDB7A67
WriterId
4744390
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\31059442FE01C744942DBC0CDDDB7A67
LastModification
D02FC5805A48D401
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\31059442FE01C744942DBC0CDDDB7A67
MsgEID
00000000EE353A6753D116479D0919B95E8B889AA8001000
3200
OUTLOOK.EXE
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\60\52C64B7E
LanguageList
en-US
3200
OUTLOOK.EXE
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\60\52C64B7E
C:\Windows\system32,@tzres.dll,-260
(UTC) Dublin, Edinburgh, Lisbon, London
3200
OUTLOOK.EXE
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\60\52C64B7E
C:\Windows\system32,@tzres.dll,-262
GMT Standard Time
3200
OUTLOOK.EXE
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\60\52C64B7E
C:\Windows\system32,@tzres.dll,-261
GMT Daylight Time
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\D20A85EB446A1E4AB3943F2B4D62965D
WriterId
4744390
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\D20A85EB446A1E4AB3943F2B4D62965D
LastModification
D02FC5805A48D401
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\D20A85EB446A1E4AB3943F2B4D62965D
MsgEID
00000000EE353A6753D116479D0919B95E8B889AC8001000
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\NoMail\0a0d020000000000c000000000000046
00030487
E6D01A0D
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\AEC17F941BFB1341862D093DBB3EB3F0
WriterId
4744390
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\AEC17F941BFB1341862D093DBB3EB3F0
LastModification
D02FC5805A48D401
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\AEC17F941BFB1341862D093DBB3EB3F0
MsgEID
00000000EE353A6753D116479D0919B95E8B889AE8001000
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\4057A1311F1907429AB7A94F59A0AC9C
WriterId
4744390
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\4057A1311F1907429AB7A94F59A0AC9C
LastModification
D02FC5805A48D401
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\4057A1311F1907429AB7A94F59A0AC9C
MsgEID
00000000EE353A6753D116479D0919B95E8B889A08011000
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\7D2A03813A81DB4BB8B46484C13DE924
WriterId
4744390
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\7D2A03813A81DB4BB8B46484C13DE924
LastModification
D02FC5805A48D401
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\7D2A03813A81DB4BB8B46484C13DE924
MsgEID
00000000EE353A6753D116479D0919B95E8B889A28011000
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\0543AF41E0C5004CA49FA9A07A80C502
WriterId
4744390
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\0543AF41E0C5004CA49FA9A07A80C502
LastModification
D02FC5805A48D401
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Outlook\Perf\RoamingStreamsCache\0543AF41E0C5004CA49FA9A07A80C502
MsgEID
00000000EE353A6753D116479D0919B95E8B889A48011000
3200
OUTLOOK.EXE
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\60\52C64B7E
@%SystemRoot%\system32\p2pcollab.dll,-8042
Peer to Peer Trust
3200
OUTLOOK.EXE
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\60\52C64B7E
@%SystemRoot%\system32\qagentrt.dll,-10
System Health Authentication
3200
OUTLOOK.EXE
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\60\52C64B7E
@%SystemRoot%\system32\dnsapi.dll,-103
Domain Name System (DNS) Server Trust
3200
OUTLOOK.EXE
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\60\52C64B7E
@%SystemRoot%\System32\fveui.dll,-843
BitLocker Drive Encryption
3200
OUTLOOK.EXE
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\60\52C64B7E
@%SystemRoot%\System32\fveui.dll,-844
BitLocker Data Recovery Agent
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\Licensing
CFF13DD86EF249EBB265E3BFC6501C1D
01000000270000007B39303134303030302D303033442D303030302D303030302D3030303030303046463143457D005A0000004F00660066006900630065002000310034002C0020004F0066006600690063006500500072006F00660065007300730069006F006E0061006C002D00520065007400610069006C002000650064006900740069006F006E000000
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\NoMail\9375CFF0413111d3B88A00104B2A6676
LastChangeVer
1300000000000000
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\NoMail\9375CFF0413111d3B88A00104B2A6676
LastChangeVer
1400000000000000
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\IAM
Server ID
2
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\NoMail\3517490d76624c419a828607e2a54604
001f6000
4E006F004D00610069006C000000
3200
OUTLOOK.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\NoMail\0a0d020000000000c000000000000046
000b0340
0100

Files activity

Executable files
57
Suspicious files
7
Text files
95
Unknown types
7

Dropped files

PID
Process
Filename
Type
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\TodoistLib.dll
executable
MD5: 89a7a968dea20b0b08b380fed487d48c
SHA256: bba5c76e156969bdd2f86d64dde2e523a3d358d6cd4e5d5c30b5c813aeea0c14
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\S22.Imap.dll
executable
MD5: 1363f9709f26ab1dd98057eeea1b47d6
SHA256: ec052d4f2867ec9613d4f8b3b09925e1e14001b2d912764430bbeeb3a40c84e3
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\Thrift.dll
executable
MD5: da5f66346a3ce30dce5f7c6b5119e523
SHA256: 85a42447f1d9058e60759d92c2dabfe973220fb29d604d0f3be8bb015591e725
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\System.Data.SQLite.dll
executable
MD5: cc61e16038560d9da60a31d265112ad9
SHA256: 401c2fe440554b12f70aff6eca8142b3dd0a5d074fb6d522e047a26e838f8e3d
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\ObjectCache.dll
executable
MD5: 803b02fcff2408cbcfc5ad7e3d30ca29
SHA256: 32dac98fa677636679ea279b7fc47ed671f5d690b87bed656b961350771ff8fa
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\System.Net.Http.Primitives.dll
executable
MD5: 018841345cfbf45eda4cd1adb74fd68b
SHA256: acf0e0555afed095cf12f719a3cd0e745435ced2575840a46a40ec61ed632265
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\PocketInformantLib2.dll
executable
MD5: 3f0632ba361b57de798d7fb2e597d5b8
SHA256: 49f363569b12b3f008782cba6c487e9877c471d41f1a390eded2108d31bf8fe1
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\GoogleLib2.dll
executable
MD5: 8dde77a9f383760e657fade899e30a7e
SHA256: 219f733a074b3de0b17af516c884f8db331f1c89d94d29442478073f35c66eba
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\System.IO.dll
executable
MD5: d552de7d39179b914db7cc2dbdd005c2
SHA256: 24bd076d31dc9d363eb2adb8b27a7d45d9f975aeec565132d27901537e31f239
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\Google.Apis.Calendar.v3.dll
executable
MD5: 9c8cc5dc665831f7d6d1971fa1ce4cd2
SHA256: fa96b46f0124758cf2a4272ac8ffdbf432f503ebcd3b72c423f22d99a0798f92
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\EvernoteLib.dll
executable
MD5: b779aaa962b044912b93a1437f11a9cd
SHA256: 0f9d8ecb087b3e153225298a1831efa437232b4f3bfeb4038fdcb6b4a596bb71
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\gsyncit.ext.dll
executable
MD5: 56195fd111e2896ffc5a3a9476753d63
SHA256: e1f5c234c2b531b1fb368ae64900494e9621a6634972c0850980d49123a7f992
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\gSyncit.core.dll
executable
MD5: 384386cf45eed1d15c090c634c7ed23e
SHA256: 2b365cbb33fb5c64722ba966996ad63706036fac5e9e8c79dd14f611c6473dd5
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\System.Runtime.dll
executable
MD5: 8e4e0ea396b5452bed54e6888cb07ca1
SHA256: dfeab83e6a9555a6c18070c611d868e117fa2fef6f815da26e622feb2e610254
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\Evernote.dll
executable
MD5: 010a65a9695658d5f7a59f9ca3aff7e8
SHA256: 3baee2c9b8aa8e46c17dc8d218153a44d5f247506dc83abead3e3edad8da2109
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\SqliteCache.dll
executable
MD5: 0cb3d1611c19457d7522c4bd7cb14b14
SHA256: 9633eab63f1a62aed42ad061cf3d2baceea81180e6469d8c864424183a0e754a
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\Microsoft.Threading.Tasks.Extensions.dll
executable
MD5: 6aa2393ff1fde1a61d0cf51730428f74
SHA256: 92f1d0d6ccfb0d030789f3c5c636fcdd08f6d0541a5a54f185e8ecd85592e3f9
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\Google.GData.Client.dll
executable
MD5: 90acb5704a420bec20065d64be397b3e
SHA256: 676be8920da74d6f28c62677d8ab1059e5cb0a97e785563e7b303f691ebcb3c8
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\Google.Apis.dll
executable
MD5: 24536d108d707474c717eb6c96b54926
SHA256: 145d6b3232dd1c93578c254d5479d65466cefe394ff67bd4075127b6f5d8d63f
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\SharpNoteLib.dll
executable
MD5: 8d91d98525d102950f63eb00dfc51636
SHA256: b5c168d76faef7224da1d9bac6d56f9c868ac9a32c955e2ca67fa7ee12b33c43
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\HtmlAgilityPack.dll
executable
MD5: 019adee3b07bd613f78b0d81cb281202
SHA256: 2e2288bf3c4766e6c733fbf4f756c4d7fd223cb9e96ee91bc76880021995640a
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\NozbeLib.dll
executable
MD5: a369b399f3e92b86d17478025984047c
SHA256: 122aa6b0e2c1e159eb27da390642256cd3fcbbc7bc834b7ceafaf88d31548765
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\ToodledoLib3.dll
executable
MD5: 7fd3b326f287db213c19655a3af5d201
SHA256: 35da919faa53dbc44f0055cd9619a5b1803efb665082396b1b47cb3304c6d90e
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\gsyncit.exe
executable
MD5: 7ccf6b2e75fb4d6bef53e8465d2024f6
SHA256: f9ece89bc6a9a4843a8cda954e2fd91d1ed37049076d5b9f8836e20adc6e824e
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\XPExplorerBar.dll
executable
MD5: c54ce0b46141489facff89e955f51614
SHA256: b78ac44a8af8b7f72b6ae89b7b121593bae04e69464c601c83e1c87fd0608cae
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\Dropbox.Api.dll
executable
MD5: b0fb61e3f0acb98f03a6470806ee57d8
SHA256: 482a9736d9f91cca0528cef11cce11e565249737c8367f216104dc781f94cc00
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\stdole.dll
executable
MD5: 91394cc83a621bdc9d5a1f80a923ad18
SHA256: c3db5e560da50d837dff08afad591530855d9e33898228dbd5fa675187f20678
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\Google.Apis.Drive.v2.dll
executable
MD5: 08faf115aaa601f97e353dea32ea1c7c
SHA256: d8b4d8cd88bbedeaa06dce85efd3f1d21e9ddd292df4f46279bdc95325a277e1
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\System.Net.Http.WebRequest.dll
executable
MD5: 1925e1654510ee0914ff3360c6c94765
SHA256: 6e599d81a2b8d803ca794c25111fea54c34356c4ed853b926c9ab42a4b0d6454
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\Google.Apis.Core.dll
executable
MD5: 5ef7a3aece5f249c87662f716114ce51
SHA256: f1adca60130e52f763f0abfeec4e62d68115b8fc4ab8f1074fec4766a1456ca3
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\Microsoft.Threading.Tasks.dll
executable
MD5: d01819bfe03222dfa9e35a36555b6b6c
SHA256: 5f29e16edff5379e93d5be9bee4cddf98132b84326027688511ac0f3157aaf94
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\ICSharpCode.SharpZipLib.dll
executable
MD5: c8164876b6f66616d68387443621510c
SHA256: 40b3d590f95191f3e33e5d00e534fa40f823d9b1bb2a9afe05f139c4e0a3af8d
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\System.Net.Http.Extensions.dll
executable
MD5: 7f86a47acd4d810ad673af81369f2f26
SHA256: 9c8b87e9a950deb7f28752f875ea82f1b55a70996ac8c12073fcea33664b2048
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\Google.Apis.Auth.dll
executable
MD5: d3de0f000088713370a09d82343a23c4
SHA256: 215c073cc90d8a19d02ce7e807c54733310eb252097e4d732c557addc345bd09
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\Google.Apis.Tasks.v1.dll
executable
MD5: 4feaafd36c1907b91baa3a90280591e5
SHA256: 14a912d3ecaf43e1f17232a68408c2a4db2e7fb97f158bf887825b4a565b3ae9
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\OFFICE.DLL
executable
MD5: 819a773f2e255e8d653174b5994f5454
SHA256: dc1c9337435fa37201dbb8c012e0397e0a1bae7273305ca397feed566ba0f9e9
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\gsyncit.addinshim.dll
executable
MD5: 2cdfc91a2141c91a1ed3889c333d6c76
SHA256: 04d4a3a7b8dcfda371c8813755f6d6495148db12e6c5a028a39326870715dac5
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\Microsoft.Threading.Tasks.Extensions.Desktop.dll
executable
MD5: e548a93d16964e52868c47cef1c98f2e
SHA256: f71621c47c610e0886846cf53d955fd0e7448951f99ecc22facd47493ef97a87
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\RestSharp.dll
executable
MD5: deb0db97122655bd95b517af4fe67ecd
SHA256: f43b637a21937636204ae2c5bcedef97d4b9a1cf52a7f1543e5d761150ce6b30
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\Microsoft.Office.Interop.Outlook.dll
executable
MD5: c65a9e0525052f0cb83f58d96f65825d
SHA256: 60a8df9af895e51c9c99e8f8367149d7f08af1b78710c0800ac1165009419dfd
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\System.Threading.Tasks.dll
executable
MD5: 85f6f590b5c4b8c7253e9c403c9be607
SHA256: d20552fd5c8c8c9759608a84db1e216da738f5e9f46de9e8a3f39a0d6265cb8b
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\gsyncit.updater.exe
executable
MD5: dc0eabe0c74a9292ca32551f8d2fec9d
SHA256: bfe5d0c811721fe52ca6df8d040d0a4ed07a830ec4a7972b1e2e5dcfd47df907
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\Newtonsoft.Json.Net35.dll
executable
MD5: 5f0efae6b0af31782ed0e8916259ff37
SHA256: 5d036af040bd317eadfee2d54bcd2129cf988db4a46f13687fc2861f9757daa0
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\DropBoxLib.dll
executable
MD5: 7dedfd761ef4a214867714353aa963ec
SHA256: 6e0b7466824022348f7bfd97796a37f1d90f3a29f0e18dd369177c3eddc1df5f
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\WunderlistLib.dll
executable
MD5: 3fbaded6a3e37a85bbcfd794f092fce1
SHA256: 27f0b7d6390757f0104a4e72e90b1d9f7bd107c934bee901b6480e2fae05d53b
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\FileCache.Signed.dll
executable
MD5: 401608c75d3375dcba1242e9b205b5a4
SHA256: 65b3c17a4dc3e83f235e9c563b9dce340a4057fb479477b2627e13f64a0f51bb
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\System.Net.Http.dll
executable
MD5: 3002e884c5c15a15b68eaef3c62ff254
SHA256: 3e71eb02ae8d01cb8159cc5f9ff3ff1976aec5872298ed45310b58f18708eac0
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\Google.GData.Extensions.dll
executable
MD5: 3212356427eaa5c5845990bb650d363c
SHA256: 085558a906e20446cc98bef05e14d163d8dcef4cacd62eb9b078c0eb2ee771bd
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\extensibility.dll
executable
MD5: 00072c0e4f6fde81b6ca310f7a762ee1
SHA256: 4fc35abacf3e39906e2d60ac358a28a9d4e4e1952495c851ace42a7ad41e18e7
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\gsyncit.addin.dll
executable
MD5: cdd26b78b95877f5d82a3edc7294e853
SHA256: e20979aeb272c44cc18c82c2341f1d05d2b3ead904bcc7e8cd94894d53d09906
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\Google.Apis.PeopleService.v1.dll
executable
MD5: 1d52e38ec05277577230347002cef235
SHA256: 5af25394d8b65f619eef4cf52df5256a1b10adde154f7cb81142f870d957aa19
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\Google.GData.Contacts.dll
executable
MD5: 6aacc8d5273f02553b52148a56fb7512
SHA256: 1aa2cc802794fd4be6f386cb922a53f9ecab8c5ceb64ac1c4343ac3c4d7b3650
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\Newtonsoft.Json.dll
executable
MD5: 505a541a82ab519e991c895a30a99852
SHA256: 072f358c2a0a4f6f15620baf4661536c977e92add2d06b6f5e520f294feca467
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\Zlib.Portable.dll
executable
MD5: 0068f1cf5939866a00e649cf169eff20
SHA256: 121751c1d8d8cbc5270c0a606dbca5d714d42e18ab3e6b577fbb8d2a4a5569c5
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\WizardLib.dll
executable
MD5: d7e1ff21e27a477bcc4c1bbc8f31bf48
SHA256: 35b7f4d4f22659db9a9992c6e2096beae9a06a844746baf083026b162efe155e
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\InstallHelper3.dll
executable
MD5: eea1a43c8c8e77ab56c8561f0ebbe4a6
SHA256: 373d6ea74e7c1be7b58a817583c1f5485011731d7440b5c83d73e1626c553b1c
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\WebDavLib.dll
executable
MD5: ef7e96a36615470f43e0ab36404e9276
SHA256: a9df870ad498e4642922e15fd9bcce8e0376df93d41deadc53e77aa4f3528364
3200
OUTLOOK.EXE
C:\Users\admin\AppData\Local\Microsoft\Outlook\mapisvc.inf
text
MD5: 48dd6cae43ce26b992c35799fcd76898
SHA256: 7bfe1f3691e2b4fb4d61fbf5e9f7782fbe49da1342dbd32201c2cc8e540dbd1a
2192
msiexec.exe
C:\Windows\Installer\1a33d6.msi
––
MD5:  ––
SHA256:  ––
2412
MsiExec.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\gSyncit\gSyncit.lnk
lnk
MD5: 300f9620f875e5f81cb350d1826ec7c1
SHA256: 6da244f62de0a5bd50d0595500f78a437f65d212b362ade2de248c397aab9a46
2192
msiexec.exe
C:\Windows\Installer\{92465B12-45C1-4C33-BD61-B79691147E39}\_853F67D554F05449430E7E.exe
image
MD5: aadea045ba992bbc761ab4352a5939d3
SHA256: a40028d7c53e90fd05f0d00c0112fa0d5340a69120feb9d2de78315ee57726e7
3200
OUTLOOK.EXE
C:\Users\admin\AppData\Roaming\gSyncit\settings5.dat.bak
text
MD5: 5b956bc533ecab3ddcc558a473179f66
SHA256: 875160dd9616c05dd4d8690c27e131825cabfbfc0a05e417a476db496c1f2023
3200
OUTLOOK.EXE
C:\Users\admin\AppData\Local\Microsoft\Outlook\RoamCache\Stream_TCPrefs_2_0543AF41E0C5004CA49FA9A07A80C502.dat
xml
MD5: f194b1fa12f9b6f46a47391fae8beec2
SHA256: fcd8d7e030be6ea7588e5c6cb568e3f1bdfc263942074b693942a27df9521a74
3200
OUTLOOK.EXE
C:\Users\admin\AppData\Local\Microsoft\Outlook\RoamCache\Stream_RssRule_2_AEC17F941BFB1341862D093DBB3EB3F0.dat
xml
MD5: d8b37ed0410fb241c283f72b76987f18
SHA256: 31e68049f6b7f21511e70cd7f2d95b9cf1354cf54603e8f47c1fc40f40b7a114
3200
OUTLOOK.EXE
C:\Users\admin\AppData\Local\Microsoft\Outlook\RoamCache\Stream_ContactPrefs_2_4057A1311F1907429AB7A94F59A0AC9C.dat
xml
MD5: bbcf400bd7ae536eb03054021d6a6398
SHA256: 383020065c1f31f4fb09f448599a6d5e532c390af4e5b8af0771fe17a23222ad
3200
OUTLOOK.EXE
C:\Users\admin\AppData\Local\Microsoft\Outlook\RoamCache\Stream_ConversationPrefs_2_7D2A03813A81DB4BB8B46484C13DE924.dat
xml
MD5: 57f30b1bca811c2fcb81f4c13f6a927b
SHA256: 612bad93621991cb09c347ff01ec600b46617247d5c041311ff459e247d8c2d3
3200
OUTLOOK.EXE
C:\Users\admin\AppData\Local\Microsoft\Outlook\RoamCache\Stream_WorkHours_1_D20A85EB446A1E4AB3943F2B4D62965D.dat
xml
MD5: 807ef0fc900feb3da82927990083d6e7
SHA256: 4411e7dc978011222764943081500fff0e43cbf7ccd44264bd1ab6306ca68913
3200
OUTLOOK.EXE
C:\Users\admin\AppData\Local\Microsoft\Outlook\RoamCache\Stream_AvailabilityOptions_2_31059442FE01C744942DBC0CDDDB7A67.dat
xml
MD5: eeaa832c12f20de6aaaa9c7b77626e72
SHA256: c4c9a90f2c961d9ee79cf08fbee647ed7de0202288e876c7baad00f4ca29ca16
3200
OUTLOOK.EXE
C:\Users\admin\AppData\Local\Microsoft\Outlook\RoamCache\Stream_Calendar_2_F4817C20F6BD6C4D99A01DEF0B65CE4A.dat
xml
MD5: b21ed3bd946332ff6ebc41a87776c6bb
SHA256: b1aac4e817cd10670b785ef8e5523c4a883f44138e50486987dc73054a46f6f4
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\gsyncit.exe.config
xml
MD5: 6424ff7b1d38a51956ac46daa5da153d
SHA256: 11f7261cff8f77fe2c1b16bcb8491f53ad29336b4a30441796b992ca72434b74
3200
OUTLOOK.EXE
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\{982D0F34-1476-4313-A67A-7555DB74D4FD}\{1C306CB1-771E-4B4B-A902-86E897877F5B}.png
image
MD5: 7d80c0a7e3849818695eaf4989186a3c
SHA256: 72dc527d78a8e99331409803811cc2d287e812c008a1c869a6aea69d7a44b597
3200
OUTLOOK.EXE
C:\Users\admin\AppData\Roaming\gSyncit\settings5.dat
text
MD5: 5b956bc533ecab3ddcc558a473179f66
SHA256: 875160dd9616c05dd4d8690c27e131825cabfbfc0a05e417a476db496c1f2023
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\gsyncit.addin.pdb
pdb
MD5: 4fd4f6acafe05c42f3125ac4712f2bec
SHA256: 67733e84e883d6f8399afdde5da0656d6c6cc9073d344caaefd7a4bf868638ca
3200
OUTLOOK.EXE
C:\Users\admin\AppData\Roaming\gSyncit\settings5.dat.tmp
––
MD5:  ––
SHA256:  ––
3200
OUTLOOK.EXE
C:\Users\admin\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019011120190112\index.dat
dat
MD5: 9a1534a003ece522c66f4d481d7c31ca
SHA256: 77effcfafab8e952f61a5ae2f8acadb20609df1ee65d934ed105b20ce89516bb
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\gsyncit.updater.exe.config
xml
MD5: f5616ea1ee20bf64d2562795f2d98813
SHA256: ea52330fd77c41105e9f205a5d9eaa029596c07dcea5878e71d404ef945fcbdc
3200
OUTLOOK.EXE
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\gap[1]
image
MD5: 96c4c871750d7ca05dfa18ce6a85d369
SHA256: 74441313bb1fb62500484443c4937e90d4e335351a4fcd12a9ac48448500e33e
3200
OUTLOOK.EXE
C:\Users\admin\AppData\Roaming\gSyncit\syncdata8.db-shm
––
MD5:  ––
SHA256:  ––
3200
OUTLOOK.EXE
C:\Users\admin\AppData\Local\Temp\mso74F4.tmp
html
MD5: a8934077843220a8e31367c7bbe15e6c
SHA256: a2db0201d36f07f3f99d1adf8b8eafb9cf9bb803d024fcc9327b77af56346861
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\gSyncit.core.pdb
pdb
MD5: 0af396e429ab67d13cda5a30d396d789
SHA256: 67f75f54c35a45a3bcb03b5be51ec7e03b8d1199b495bf7c530e7352460fe47f
3492
gsyncit.exe
C:\Users\admin\AppData\Roaming\gSyncit\syncdata8.db-shm
––
MD5:  ––
SHA256:  ––
3492
gsyncit.exe
C:\Users\admin\AppData\Roaming\gSyncit\syncdata8.db
sqlite
MD5: 3cd9d6ac8af4bd31c1f0187ea2c55a18
SHA256: 1a89bec5614e21593d0429c046cd3b0e8fc954636a9dc48b44793396befde1dc
3492
gsyncit.exe
C:\Users\admin\AppData\Roaming\gSyncit\syncdata8.db-wal
––
MD5:  ––
SHA256:  ––
3492
gsyncit.exe
C:\Users\admin\AppData\Roaming\gSyncit\syncdata8.db-journal
––
MD5:  ––
SHA256:  ––
2412
MsiExec.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\gSyncit\Uninstall.lnk
lnk
MD5: beaf75aa8f60c259b18ca220d9607460
SHA256: 9ca4815716d055bc835201a119e7e765f8d56257aa091713449e18288a8eceba
3200
OUTLOOK.EXE
C:\Users\admin\AppData\Local\Temp\CVR6F84.tmp.cvr
––
MD5:  ––
SHA256:  ––
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\gsyncit.addin.dll.config
xml
MD5: 04e9e206918d97a7cb3a46959d5337a3
SHA256: b338d992196a02889828dd77759b475e547ac3670d5d0f08e7f0ecc3d026642d
2192
msiexec.exe
C:\Windows\Installer\1a33d4.ipi
––
MD5:  ––
SHA256:  ––
2192
msiexec.exe
C:\Users\admin\AppData\Local\Temp\~DF564CEACA6AAAB992.TMP
––
MD5:  ––
SHA256:  ––
2192
msiexec.exe
C:\Config.Msi\1a33d5.rbs
––
MD5:  ––
SHA256:  ––
2192
msiexec.exe
C:\Program Files\Fieldston Software\gSyncit\agreement.rtf
text
MD5: f06f2dc88cdd2149ca7cde56758b6553
SHA256: ae4ff8a19d4ee0f01599be1a8f28c1c1b5e23dae9ddcd1a5aa466ba297fb7f8e
3492
gsyncit.exe
C:\Users\admin\AppData\Roaming\gSyncit\settings5.dat.bak
text
MD5: 5b956bc533ecab3ddcc558a473179f66
SHA256: 875160dd9616c05dd4d8690c27e131825cabfbfc0a05e417a476db496c1f2023
2192
msiexec.exe
C:\Windows\Installer\MSI4C3F.tmp
binary
MD5: 870076993d822d7e9c83f56f29bd7629
SHA256: 18bb5d5b1ea3783687e3890b15484c471f2ff5554c06e2c3c6bc750ef7656844
2192
msiexec.exe
C:\Windows\Installer\1a33d4.ipi
binary
MD5: 4de3b9c8dbabf7426b41249b9998109f
SHA256: b659babe4a76df150ffda7de25046281c36f3346856ad2564c712813d976827d
2192
msiexec.exe
C:\Users\admin\AppData\Local\Temp\~DF43DA15C5E683C39C.TMP
––
MD5:  ––
SHA256:  ––
2092
MsiExec.exe
C:\Users\admin\AppData\Local\Temp\CFG4A68.tmp
xml
MD5: 20244937356423bd634209fa8d98ed3f
SHA256: f1f95e23d1bee18ad4e77efe70f5f36cc5be2b60688f5e99714f7910869e3c65
2192
msiexec.exe
C:\Windows\Installer\MSI4A79.tmp
––
MD5:  ––
SHA256:  ––
2192
msiexec.exe
C:\Windows\Installer\MSI4893.tmp
––
MD5:  ––
SHA256:  ––
3980
vssvc.exe
C:
––
MD5:  ––
SHA256:  ––
2192
msiexec.exe
C:\Windows\Installer\1a33d3.msi
––
MD5:  ––
SHA256:  ––
2640
DrvInst.exe
C:\Windows\INF\setupapi.dev.log
ini
MD5: bc08194ba2626c6382ab0020b868a08d
SHA256: 3ed1564ab393a95bd3203afd8e6e8be17d2a70feaba7364673daa7ecc7e80e8c
2640
DrvInst.exe
C:\Windows\INF\setupapi.dev.log
ini
MD5: 5f5110db8297940de0cf692f694d5bc2
SHA256: 9d10c637e956b218e24226d09f3d6cd043632f872631a3a25c0979e5b056fb33
2640
DrvInst.exe
C:\Windows\INF\setupapi.ev3
binary
MD5: 76dcc60f78b3dff1ae3627619074f465
SHA256: 18541ac1875315c4f9eff75050c574faff83717c029dae6b366f9c6c3f0c19e0
2640
DrvInst.exe
C:\Windows\INF\setupapi.ev1
binary
MD5: 405dcfd6cd4dfb5a35cbcf9a62f996f1
SHA256: d0c972e20cdf3a4b4eda06e10ebb0182f127e6f4efcda1cfb1cf1118042451f4
2192
msiexec.exe
C:\System Volume Information\SPP\metadata-2
––
MD5:  ––
SHA256:  ––
2192
msiexec.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{6677040d-550d-4230-9e01-934b7aee5b26}_OnDiskSnapshotProp
binary
MD5: 52102e3521e369fca72d0c6185c38a71
SHA256: 6c779646dc1f3542547c87449dd5944ec8efd7dc7964a5b1ea8810e6decac621
2192
msiexec.exe
C:\System Volume Information\SPP\snapshot-2
binary
MD5: 52102e3521e369fca72d0c6185c38a71
SHA256: 6c779646dc1f3542547c87449dd5944ec8efd7dc7964a5b1ea8810e6decac621
3300
msiexec.exe
C:\Users\admin\AppData\Local\Temp\MSID529.tmp
––
MD5:  ––
SHA256:  ––
3948
MsiExec.exe
C:\Users\admin\AppData\Local\Temp\CFGD519.tmp
xml
MD5: 20244937356423bd634209fa8d98ed3f
SHA256: f1f95e23d1bee18ad4e77efe70f5f36cc5be2b60688f5e99714f7910869e3c65
3300
msiexec.exe
C:\Users\admin\AppData\Local\Temp\MSID45D.tmp
––
MD5:  ––
SHA256:  ––
3300
msiexec.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\74FBF93595CFC8459196065CE54AD928
der
MD5: 1edaf9ae99ce2920667d0e9a8b3f8c9c
SHA256: 4f32d5dc00f715250abcc486511e37f501a899deb3bf7ea8adbbd3aef1c412da
3300
msiexec.exe
C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\74FBF93595CFC8459196065CE54AD928
binary
MD5: f72da13435dc5c22f26fd77989e5f3ea
SHA256: 019c995dad07eee12216dae1aea042669609bec3e1780031e73834c9ae43c155

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
2
TCP/UDP connections
3
DNS requests
3
Threats
0

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
3300 msiexec.exe GET 200 91.199.212.52:80 http://crt.comodoca.com/COMODORSAAddTrustCA.crt GB
der
whitelisted
3200 OUTLOOK.EXE GET –– 64.4.26.155:80 http://config.messenger.msn.com/config/msgrconfig.asmx?op=GetOlcConfig US
––
––
whitelisted

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
3300 msiexec.exe 91.199.212.52:80 Comodo CA Ltd GB unknown
3200 OUTLOOK.EXE 69.16.215.76:443 Liquid Web, L.L.C US unknown
3200 OUTLOOK.EXE 64.4.26.155:80 Microsoft Corporation US whitelisted

DNS requests

Domain IP Reputation
crt.comodoca.com 91.199.212.52
whitelisted
www.fieldstonsoftware.com 69.16.215.76
unknown
config.messenger.msn.com 64.4.26.155
whitelisted

Threats

No threats detected.

Debug output strings

Process Message
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]
OUTLOOK.EXE gSync: SYNC_ONSTARTUP = [False]