General Info Watch the FULL Interactive Analysis at ANY.RUN!

File name

gSyncit_5_3_21.msi

Verdict
Malicious activity
Analysis date
1/11/2019, 10:41:03
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-msi
File info:
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Create Time/Date: Mon Jun 21 08:00:00 1999, Name of Creating Application: Windows Installer, Security: 1, Code page: 1252, Template: Intel;1033, Number of Pages: 200, Revision Number: {75E6C46E-92C1-4768-98EB-98F58D24F125}, Title: gSyncit for Microsoft Outlook, Author: Fieldston Software, Number of Words: 2, Last Saved Time/Date: Wed Jan 9 19:17:04 2019, Last Printed: Wed Jan 9 19:17:04 2019
MD5

08fafee91a1182e1217abb03bed16f43

SHA1

fb19b3c6ca81db4b2228cc15fe7137536eb595f9

SHA256

0594d14667c3df494dba92f4a71e284d8e45baff1c8547cc08efae6877412fc8

SSDEEP

196608:UF/lgvM4+47WjFGBvj0HlfPk8sJlmTmjXBRNaMqA4oLq:w/lSMCIsBoFfPkPiTmP8tA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
120 seconds
Additional time used
60 seconds
Fakenet option
off
Heavy Evaision option
on
MITM proxy
off
Route via Tor
on
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
off

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads dropped or rewritten executable
  • OUTLOOK.EXE (PID: 3200)
  • gsyncit.exe (PID: 3492)
Application was dropped or rewritten from another process
  • gsyncit.exe (PID: 3492)
Changes settings of System certificates
  • msiexec.exe (PID: 3300)
Reads Internet Cache Settings
  • OUTLOOK.EXE (PID: 3200)
Starts Microsoft Office Application
  • MsiExec.exe (PID: 3948)
Creates files in the user directory
  • gsyncit.exe (PID: 3492)
  • OUTLOOK.EXE (PID: 3200)
Reads internet explorer settings
  • OUTLOOK.EXE (PID: 3200)
Reads Environment values
  • OUTLOOK.EXE (PID: 3200)
Creates COM task schedule object
  • msiexec.exe (PID: 2192)
Changes the autorun value in the registry
  • msiexec.exe (PID: 2192)
Executable content was dropped or overwritten
  • msiexec.exe (PID: 2192)
Reads Microsoft Office registry keys
  • gsyncit.exe (PID: 3492)
  • OUTLOOK.EXE (PID: 3200)
Creates files in the program directory
  • MsiExec.exe (PID: 2412)
  • msiexec.exe (PID: 2192)
Low-level read access rights to disk partition
  • vssvc.exe (PID: 3980)
Creates a software uninstall entry
  • msiexec.exe (PID: 2192)
Loads dropped or rewritten executable
  • MsiExec.exe (PID: 3948)
  • msiexec.exe (PID: 2192)
  • MsiExec.exe (PID: 2412)
Searches for installed software
  • msiexec.exe (PID: 2192)
Application launched itself
  • msiexec.exe (PID: 2192)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.msi
|   Microsoft Windows Installer (90.2%)
.msp
|   Windows Installer Patch (8.4%)
.msi
|   Microsoft Installer (100%)
EXIF
FlashPix
CreateDate:
1999:06:21 07:00:00
Software:
Windows Installer
Security:
Password protected
CodePage:
Windows Latin 1 (Western European)
Template:
Intel;1033
Pages:
200
RevisionNumber:
{75E6C46E-92C1-4768-98EB-98F58D24F125}
Title:
gSyncit for Microsoft Outlook
Subject:
null
Author:
Fieldston Software
Keywords:
null
Comments:
null
Words:
2
ModifyDate:
2019:01:09 19:17:04
LastPrinted:
2019:01:09 19:17:04

Screenshots

Processes

Total processes
43
Monitored processes
9
Malicious processes
4
Suspicious processes
0

Behavior graph

+
start msiexec.exe msiexec.exe msiexec.exe no specs vssvc.exe no specs drvinst.exe no specs msiexec.exe no specs msiexec.exe no specs gsyncit.exe outlook.exe
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
3300
CMD
"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\Downloads\gSyncit_5_3_21.msi"
Path
C:\Windows\System32\msiexec.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\msimsg.dll
c:\windows\system32\propsys.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msisip.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\credssp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshqos.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\microsoft.net\framework\v4.0.30319\fusion.dll
c:\windows\system32\msihnd.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\vccorlib140.dll
c:\windows\system32\concrt140.dll
c:\windows\system32\msvcp140_2.dll
c:\windows\system32\msvcp140_1.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\riched20.dll

PID
2192
CMD
C:\Windows\system32\msiexec.exe /V
Path
C:\Windows\system32\msiexec.exe
Indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\msimsg.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\srclient.dll
c:\windows\system32\spp.dll
c:\windows\system32\vssapi.dll
c:\windows\system32\atl.dll
c:\windows\system32\vsstrace.dll
c:\windows\system32\vss_ps.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\es.dll
c:\windows\system32\sxs.dll
c:\windows\system32\propsys.dll
c:\windows\system32\samlib.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msisip.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\winsta.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\microsoft.net\framework\v4.0.30319\fusion.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\vccorlib140.dll
c:\windows\system32\concrt140.dll
c:\windows\system32\msvcp140_2.dll
c:\windows\system32\msvcp140_1.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\cabinet.dll
c:\program files\fieldston software\gsyncit\newtonsoft.json.dll
c:\program files\fieldston software\gsyncit\htmlagilitypack.dll
c:\program files\fieldston software\gsyncit\system.data.sqlite.dll
c:\program files\fieldston software\gsyncit\sqlitecache.dll
c:\program files\fieldston software\gsyncit\zlib.portable.dll

PID
3948
CMD
C:\Windows\system32\MsiExec.exe -Embedding 81F4FC124851856B53DD4D0327D8C052 C
Path
C:\Windows\system32\MsiExec.exe
Indicators
No indicators
Parent process
msiexec.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\users\admin\appdata\local\temp\msid45d.tmp
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\users\admin\appdata\local\temp\msid529.tmp
c:\program files\fieldston software\gsyncit\installhelper3.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\devrtl.dll
c:\program files\fieldston software\gsyncit\gsyncit.exe
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\program files\microsoft office\office14\outlook.exe

PID
3980
CMD
C:\Windows\system32\vssvc.exe
Path
C:\Windows\system32\vssvc.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Microsoft® Volume Shadow Copy Service
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\vssvc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\atl.dll
c:\windows\system32\ole32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\vssapi.dll
c:\windows\system32\vsstrace.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\clusapi.dll
c:\windows\system32\cryptdll.dll
c:\windows\system32\xolehlp.dll
c:\windows\system32\version.dll
c:\windows\system32\resutils.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\authz.dll
c:\windows\system32\virtdisk.dll
c:\windows\system32\fltlib.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\vss_ps.dll
c:\windows\system32\samlib.dll
c:\windows\system32\es.dll
c:\windows\system32\propsys.dll
c:\windows\system32\catsrvut.dll
c:\windows\system32\mfcsubs.dll
c:\windows\system32\sxs.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll

PID
2640
CMD
DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot18" "" "" "6792c44eb" "00000000" "000003A8" "00000540"
Path
C:\Windows\system32\DrvInst.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Driver Installation Module
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\spinf.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\spfileq.dll

PID
2092
CMD
C:\Windows\system32\MsiExec.exe -Embedding D9430351A4B1C733B2A9DC6EF1C9560E
Path
C:\Windows\system32\MsiExec.exe
Indicators
No indicators
Parent process
msiexec.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\devobj.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\installer\msi4893.tmp
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\installer\msi4a79.tmp

PID
2412
CMD
C:\Windows\system32\MsiExec.exe -Embedding 81D6DE2EAAF36FFCC2E722170E05A3B7 M Global\MSI0000
Path
C:\Windows\system32\MsiExec.exe
Indicators
No indicators
Parent process
msiexec.exe
User
SYSTEM
Integrity Level
SYSTEM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\fieldston software\gsyncit\installhelper3.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\program files\fieldston software\gsyncit\gsyncit.exe
c:\windows\system32\netutils.dll

PID
3492
CMD
"C:\Program Files\Fieldston Software\gSyncit\gsyncit.exe"
Path
C:\Program Files\Fieldston Software\gSyncit\gsyncit.exe
Indicators
Parent process
MsiExec.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Fieldston Software
Description
gSyncit
Version
5.3.21.0
Modules
Image
c:\program files\fieldston software\gsyncit\gsyncit.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\mscorlib\225759bb87c854c0fff27b1d84858c21\mscorlib.ni.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system\52cca48930e580e3189eac47158c20be\system.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.drawing\646b4b01cb29986f8e076aa65c9e9753\system.drawing.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.windows.forms\5aac750b35b27770dccb1a43f83cced7\system.windows.forms.ni.dll
c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\uxtheme.dll
c:\windows\microsoft.net\assembly\gac_msil\system.windows.forms\v4.0_4.0.0.0__b77a5c561934e089\system.windows.forms.dll
c:\program files\fieldston software\gsyncit\gsyncit.core.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\microsoft.net\framework\v4.0.30319\nlssorting.dll
c:\windows\system32\shell32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.core\55560c2014611e9119f99923c9ebdeef\system.core.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.configuration\46957030830964165644b52b0696c5d9\system.configuration.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xml\d86b080a37c60a872c82b912a2a63dac\system.xml.ni.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\riched20.dll
c:\windows\system32\mapi32.dll
c:\windows\system32\msi.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\program files\common files\system\msmapi\1033\msmapi32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\progra~1\micros~1\office14\olmapi32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcp90.dll
c:\program files\common files\microsoft shared\office14\mso.dll
c:\program files\common files\microsoft shared\office14\cultures\office.odf
c:\progra~1\micros~1\office14\1033\mapir.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\program files\fieldston software\gsyncit\microsoft.office.interop.outlook.dll
c:\program files\fieldston software\gsyncit\office.dll
c:\windows\microsoft.net\framework\v4.0.30319\diasymreader.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.data\032f5fa875be86b577722ddeeee2e51c\system.data.ni.dll
c:\windows\microsoft.net\assembly\gac_32\system.data\v4.0_4.0.0.0__b77a5c561934e089\system.data.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\program files\fieldston software\gsyncit\system.data.sqlite.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.transactions\e7044d177c8e852b85908d2702898ec8\system.transactions.ni.dll
c:\windows\microsoft.net\assembly\gac_32\system.transactions\v4.0_4.0.0.0__b77a5c561934e089\system.transactions.dll
c:\program files\fieldston software\gsyncit\webdavlib.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.ente96d83b35#\0b139f45e599394f70beccec6e1fc39c\system.enterpriseservices.ni.dll
c:\windows\microsoft.net\assembly\gac_32\system.enterpriseservices\v4.0_4.0.0.0__b03f5f7f11d50a3a\system.enterpriseservices.wrapper.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.ente96d83b35#\0b139f45e599394f70beccec6e1fc39c\system.enterpriseservices.wrapper.dll

PID
3200
CMD
"C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE"
Path
C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE
Indicators
Parent process
MsiExec.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Microsoft Outlook
Version
14.0.6025.1000
Modules
Image
c:\program files\microsoft office\office14\outlook.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcp90.dll
c:\windows\system32\apphelp.dll
c:\program files\common files\microsoft shared\office14\mso.dll
c:\program files\common files\microsoft shared\office14\cultures\office.odf
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\program files\microsoft office\office14\addins\umoutlookaddin.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msimtf.dll
c:\program files\microsoft office\office14\1033\outllibr.dll
c:\program files\common files\microsoft shared\office14\msores.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\program files\common files\microsoft shared\office14\1033\msointl.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll
c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\osppc.dll
c:\program files\common files\microsoft shared\office14\riched20.dll
c:\progra~1\micros~1\office14\olmapi32.dll
c:\progra~1\micros~1\office14\1033\mapir.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\msasn1.dll
c:\program files\microsoft office\office14\wwlib.dll
c:\program files\microsoft office\office14\gfx.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\msimg32.dll
c:\program files\microsoft office\office14\oart.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\sxs.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\progra~1\micros~1\office14\contab32.dll
c:\progra~1\micros~1\office14\omsxp32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\progra~1\micros~1\office14\mspst32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\mlang.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\actxprxy.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\program files\microsoft office\office14\addins\colleagueimport.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\program files\fieldston software\gsyncit\gsyncit.addinshim.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\mscorlib\225759bb87c854c0fff27b1d84858c21\mscorlib.ni.dll
c:\windows\microsoft.net\framework\v4.0.30319\nlssorting.dll
c:\program files\fieldston software\gsyncit\gsyncit.addin.dll
c:\program files\fieldston software\gsyncit\gsyncit.core.dll
c:\program files\fieldston software\gsyncit\microsoft.office.interop.outlook.dll
c:\windows\microsoft.net\framework\v4.0.30319\clrjit.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system\52cca48930e580e3189eac47158c20be\system.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.drawing\646b4b01cb29986f8e076aa65c9e9753\system.drawing.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.windows.forms\5aac750b35b27770dccb1a43f83cced7\system.windows.forms.ni.dll
c:\windows\microsoft.net\assembly\gac_msil\system.windows.forms\v4.0_4.0.0.0__b77a5c561934e089\system.windows.forms.dll
c:\program files\fieldston software\gsyncit\office.dll
c:\windows\assembly\gac_msil\microsoft.office.interop.outlook\14.0.0.0__71e9bce111e9429c\microsoft.office.interop.outlook.dll
c:\windows\assembly\gac\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll
c:\windows\assembly\gac_msil\office\14.0.0.0__71e9bce111e9429c\office.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.core\55560c2014611e9119f99923c9ebdeef\system.core.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.configuration\46957030830964165644b52b0696c5d9\system.configuration.ni.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.xml\d86b080a37c60a872c82b912a2a63dac\system.xml.ni.dll
c:\windows\system32\tquery.dll
c:\windows\microsoft.net\framework\v4.0.30319\diasymreader.dll
c:\windows\system32\structuredquery.dll
c:\windows\system32\secur32.dll
c:\windows\system32\propsys.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.data\032f5fa875be86b577722ddeeee2e51c\system.data.ni.dll
c:\windows\microsoft.net\assembly\gac_32\system.data\v4.0_4.0.0.0__b77a5c561934e089\system.data.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\fieldston software\gsyncit\system.data.sqlite.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.transactions\e7044d177c8e852b85908d2702898ec8\system.transactions.ni.dll
c:\windows\microsoft.net\assembly\gac_32\system.transactions\v4.0_4.0.0.0__b77a5c561934e089\system.transactions.dll
c:\program files\fieldston software\gsyncit\webdavlib.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.ente96d83b35#\0b139f45e599394f70beccec6e1fc39c\system.enterpriseservices.ni.dll
c:\windows\microsoft.net\assembly\gac_32\system.enterpriseservices\v4.0_4.0.0.0__b03f5f7f11d50a3a\system.enterpriseservices.wrapper.dll
c:\windows\assembly\nativeimages_v4.0.30319_32\system.ente96d83b35#\0b139f45e599394f70beccec6e1fc39c\system.enterpriseservices.wrapper.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\credssp.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\profapi.dll
c:\progra~1\micros~1\office14\outlctl.dll
c:\windows\system32\jscript.dll
c:\program files\common files\system\ole db\oledb32.dll
c:\windows\system32\msdart.dll
c:\windows\system32\bcrypt.dll
c:\program files\common files\system\ole db\oledb32r.dll
c:\windows\system32\msiltcfg.dll
c:\program files\microsoft office\office14\onbttnol.dll
c:\program files\microsoft office\office14\socialconnector.dll
c:\windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.6161_none_4bf7e3e2bf9ada4c\mfc90u.dll
c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.6161_none_49768ef57548175e\mfc90enu.dll
c:\windows\system32\mapi32.dll
c:\program files\microsoft office\office14\1033\umoutlookstrings.dll
c:\windows\system32\msxml6.dll
c:\windows\system32\schannel.dll
c:\program files\microsoft office\office14\sharepointprovider.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\progra~1\micros~1\office14\outlacct.dll
c:\windows\system32\msident.dll
c:\windows\system32\pstorec.dll
c:\windows\system32\atl.dll
c:\windows\system32\tzres.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\userenv.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\p2pcollab.dll
c:\windows\system32\qagentrt.dll
c:\windows\system32\fveui.dll
c:\windows\system32\msoeacct.dll
c:\windows\system32\msoert2.dll
c:\windows\system32\inetcomm.dll
c:\windows\system32\inetres.dll
c:\windows\system32\acctres.dll
c:\program files\microsoft office\office14\omsmain.dll
c:\windows\system32\winmm.dll
c:\windows\system32\msxml3.dll

Registry activity

Total events
2023
Read events
1374
Write events
628
Delete events
21

Modification events

PID
Process
Operation
Key
Name
Value
3300
msiexec.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
3300
msiexec.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\Certificates\F5AD0BCC1AD56CD150725B1C866C30AD92EF21B0
Blob
030000000100000014000000F5AD0BCC1AD56CD150725B1C866C30AD92EF21B0140000000100000014000000BBAF7E023DFAA6F13C848EADEE3898ECD93232D40400000001000000100000001EDAF9AE99CE2920667D0E9A8B3F8C9C0F00000001000000300000007CE102D63C57CB48F80A65D1A5E9B350A7A618482AA5A36775323CA933DDFCB00DEF83796A6340DEC5EBF7596CFD8E5D19000000010000001000000082218FFB91733E64136BE5719F57C3A118000000010000001000000045ED9BBC5E43D3B9ECD63C060DB78E5C200000000100000078050000308205743082045CA00302010202102766EE56EB49F38EABD770A2FC84DE22300D06092A864886F70D01010C0500306F310B300906035504061302534531143012060355040A130B416464547275737420414231263024060355040B131D41646454727573742045787465726E616C20545450204E6574776F726B312230200603550403131941646454727573742045787465726E616C20434120526F6F74301E170D3030303533303130343833385A170D3230303533303130343833385A308185310B3009060355040613024742311B30190603550408131247726561746572204D616E636865737465723110300E0603550407130753616C666F7264311A3018060355040A1311434F4D4F444F204341204C696D69746564312B302906035504031322434F4D4F444F205253412043657274696669636174696F6E20417574686F7269747930820222300D06092A864886F70D01010105000382020F003082020A028202010091E85492D20A56B1AC0D24DDC5CF446774992B37A37D23700071BC53DFC4FA2A128F4B7F1056BD9F7072B7617FC94B0F17A73DE3B00461EEFF1197C7F4863E0AFA3E5CF993E6347AD9146BE79CB385A0827A76AF7190D7ECFD0DFA9C6CFADFB082F4147EF9BEC4A62F4F7F997FB5FC674372BD0C00D689EB6B2CD3ED8F981C14AB7EE5E36EFCD8A8E49224DA436B62B855FDEAC1BC6CB68BF30E8D9AE49B6C6999F878483045D5ADE10D3C4560FC32965127BC67C3CA2EB66BEA46C7C720A0B11F65DE4808BAA44EA9F283463784EBE8CC814843674E722A9B5CBD4C1B288A5C227BB4AB98D9EEE05183C309464E6D3E99FA9517DA7C3357413C8D51ED0BB65CAF2C631ADF57C83FBCE95DC49BAF4599E2A35A24B4BAA9563DCF6FAAFF4958BEF0A8FFF4B8ADE937FBBAB8F40B3AF9E843421E89D884CB13F1D9BBE18960B88C2856AC141D9C0AE771EBCF0EDD3DA996A148BD3CF7AFB50D224CC01181EC563BF6D3A2E25BB7B204225295809369E88E4C65F191032D707402EA8B671529695202BBD7DF506A5546BFA0A328617F70D0C3A2AA2C21AA47CE289C064576BF821827B4D5AEB4CB50E66BF44C867130E9A6DF1686E0D8FF40DDFBD042887FA3333A2E5C1E41118163CE18716B2BECA68AB7315C3A6A47E0C37959D6201AAFF26A98AA72BC574AD24B9DBB10FCB04C41E5ED1D3D5E289D9CCCBFB351DAA747E584530203010001A381F43081F1301F0603551D23041830168014ADBD987A34B426F7FAC42654EF03BDE024CB541A301D0603551D0E04160414BBAF7E023DFAA6F13C848EADEE3898ECD93232D4300E0603551D0F0101FF040403020186300F0603551D130101FF040530030101FF30110603551D20040A300830060604551D200030440603551D1F043D303B3039A037A0358633687474703A2F2F63726C2E7573657274727573742E636F6D2F416464547275737445787465726E616C4341526F6F742E63726C303506082B0601050507010104293027302506082B060105050730018619687474703A2F2F6F6373702E7573657274727573742E636F6D300D06092A864886F70D01010C0500038201010064BF83F15F9A85D0CDB8A129570DE85AF7D1E93EF276046EF15270BB1E3CFF4D0D746ACC818225D3C3A02A5D4CF5BA8BA16DC4540975C7E3270E5D847937401377F5B4AC1CD03BAB1712D6EF34187E2BE979D3AB57450CAF28FAD0DBE5509588BBDF8557697D92D852CA7381BF1CF3E6B86E661105B31E942D7F91959259F14CCEA391714C7C470C3B0B19F6A1B16C863E5CAAC42E82CBF90796BA484D90F294C8A973A2EB067B239DDEA2F34D559F7A6145981868C75E406B23F5797AEF8CB56B8BB76F46F47BF13D4B04D89380595AE041241DB28F15605847DBEF6E46FD15F5D95F9AB3DBD8B8E440B3CD9739AE85BB1D8EBCDC879BD1A6EFF13B6F10386F
2192
msiexec.exe
delete key
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\5F\52C64B7E
2192
msiexec.exe
delete key
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\5F
2192
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
2192
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback
2192
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
SrCreateRp (Enter)
4000000000000000741956E291A9D40190080000C80E0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppCreate (Enter)
4000000000000000CE7B58E291A9D40190080000C80E0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
LastIndex
20
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppGatherWriterMetadata (Enter)
40000000000000004663C1E291A9D40190080000C80E0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
IDENTIFY (Enter)
4000000000000000A0C5C3E291A9D401900800009C0D0000E80300000100000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
IDENTIFY (Leave)
4000000000000000DE06E9E391A9D401900800009C0D0000E80300000000000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppGatherWriterMetadata (Leave)
40000000000000000653CDEA91A9D40190080000C80E0000D3070000010000000000000000000000000000000000000000000000000000000000000000000000
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppAddInterestingComponents (Enter)
40000000000000000653CDEA91A9D40190080000C80E0000D4070000000000000000000000000000000000000000000000000000000000000000000000000000
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppAddInterestingComponents (Leave)
40000000000000003EEFE9EA91A9D40190080000C80E0000D4070000010000000000000000000000000000000000000000000000000000000000000000000000
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
PREPAREBACKUP (Enter)
4000000000000000C2C601EB91A9D40190080000AC090000E90300000100000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
PREPAREBACKUP (Leave)
4000000000000000BC4E2AEB91A9D40190080000AC090000E90300000000000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
GETSTATE (Enter)
4000000000000000BC4E2AEB91A9D40190080000F8090000F90300000100000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
GETSTATE (Leave)
40000000000000007E3A36EB91A9D40190080000F8090000F90300000000000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
DOSNAPSHOT (Enter)
40000000000000008C613DEB91A9D40190080000C80E00000A0400000100000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
DOSNAPSHOT (Leave)
4000000000000000F41778EC91A9D40190080000440A00000A0400000000000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppCreate (Leave)
4000000000000000F41778EC91A9D40190080000C80E0000D0070000010000000000000000000000000000000000000000000000000000000000000000000000
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
SrCreateRp (Leave)
4000000000000000F41778EC91A9D40190080000C80E0000D5070000010000000000000000000000000000000000000000000000000000000000000000000000
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
FirstRun
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
LastIndex
20
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\Volatile
NestingLevel
1
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\Volatile
StartNesting
741956E291A9D401
2192
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000_CLASSES\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress
C:\Windows\Installer\1a33d4.ipi
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\1a33d5.rbs
30714257
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\1a33d5.rbsLow
4033910928
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AFFFD324B2BB381BD695D59B2ACB3C9C
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Newtonsoft.Json.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1AE141C3DFB2D647F18FB968CB57A911
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\WunderlistLib.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FF6A74E7124E52C4CFFEBBE2554C5104
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\extensibility.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\88FD2C9EBD4E03D2BA0A65D1513A6088
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\System.Net.Http.Extensions.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F9D72C5D527BBFD84A7F3B462425EDED
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\System.Threading.Tasks.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\15F713DB5953B07A9BEFAE54EC97C65F
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\System.Net.Http.WebRequest.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B9820F6500DC557A1AE9FCAA5D30FEB1
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\XPExplorerBar.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F18363FDA8D808BBF7AA8E1556202FA
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\HtmlAgilityPack.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\856C7DDC6DA51409AF8A6C59B0B4EAAF
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Microsoft.Threading.Tasks.Extensions.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\59BB167100EA5CF28BE3D4F078394410
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\gSyncit.core.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\606738FF201229B64BF4C79A44FE2DA1
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Google.Apis.Calendar.v3.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\87C77086560577083E06ABFB30CB22B5
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\GoogleLib2.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D5F72CC34342421482E95C224C9E1F9F
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\InstallHelper3.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8FAE7754B44D7F9E06DF0CBE4EA66CB7
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\System.Data.SQLite.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9B6892472D89FF4788B86B033F9858CA
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\S22.Imap.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F7BB63572EF77F967E3C98951FD32283
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\SqliteCache.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0159DF27E7A858AF702D7855D35616CB
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\SharpNoteLib.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\55BD552659F35EAA5DCA69FD06869DEF
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\gsyncit.addin.pdb
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\99DF8F3794C5F71FB9269568BBFE06B3
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Google.Apis.Drive.v2.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\314ECDF17ADDDCDB936753D7F5C613DC
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\ICSharpCode.SharpZipLib.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA96B48FA4995A384E81AE2AB607AAAF
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Microsoft.Office.Interop.Outlook.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\99B9A2AC0626DCBADD71E601F3665507
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\OFFICE.DLL
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\197562A436F67BCA04984C8A018D92A0
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Google.GData.Extensions.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE951A6F600FF4B8C7A26836D780D891
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\WebDavLib.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2177126CF56C94ABA28D5D730EA5597C
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\FileCache.Signed.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\68D265FCCB63251831AB1EA3880D5B55
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\DropBoxLib.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\438A3A136D5574761A117716B76DA4C1
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Zlib.Portable.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB32F9D71504C620811F9AF22C13F1C9
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\WizardLib.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\85B916834E00FC48C88BEE167E248993
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Google.GData.Contacts.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\776EC93F2BFF0D9E8B36B1AD40AA2D0D
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\TodoistLib.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\28B3B07B17EE39B0B5251DF2500B7B38
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\agreement.rtf
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EBE8735BF54855F943219594B18D5539
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Microsoft.Threading.Tasks.Extensions.Desktop.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\87EC3B0032E8BF0D713AA5DF8E2E65A1
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Google.Apis.Auth.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F735124D3C464EE1294779B1599206D5
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Google.Apis.Core.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1E3F7A90D29D3A4BB4AA47994DD46D2A
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Dropbox.Api.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3C28D00C69486ABE24C61BBCD984CF5A
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\NozbeLib.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7FFEF3BBAFEE24829ADAED8D52B7AA5E
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Google.GData.Client.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F6720157C4F30EAD2834E7D18D27A676
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\gSyncit.core.pdb
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6C85B6E6DF70028335514A17AC520220
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\System.Net.Http.Primitives.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\346076CAD79991FFF93B07A1A46FFBF4
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Thrift.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\571F01E4A2DB9401BE63630A4BBBAA0F
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\System.Runtime.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\657AFC56D13A8C0F133302CA323DB7A6
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\PocketInformantLib2.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2A971F02470AB9F12555CB9BA292E0B2
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\ObjectCache.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5A584D68A500D0BA1F3015C6D802C53
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\System.IO.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F538A584C553392D7D1761D4AA8C8FEC
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Evernote.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A150088CB548DC56882EB29B62AADA0C
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\EvernoteLib.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0387F09CE14F414A5F7B79FEF434CCBC
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Google.Apis.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EFCBA39E512C628422F0B8E3B5EC4943
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\ToodledoLib3.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\514653124EC099CCF1E4DC249C666718
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\stdole.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\48AD87A73C39C81F39FC080B767DCC3D
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Microsoft.Threading.Tasks.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7A3E0EC387E0CBDE832C28DBB89F10F5
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Google.Apis.Tasks.v1.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BF728FC8597978F64C9ADBA861AC9332
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\RestSharp.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FD36D22D2F148325597B225FE9691BD5
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Newtonsoft.Json.Net35.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\165DD245767A3A261889365205A0ABB2
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\System.Net.Http.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\01292C8DB1ADF15ABB2ECFD87739A35F
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\Google.Apis.PeopleService.v1.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7F9522B6D56A85AEFE0E9660D7EC57E4
21B564291C5433C4DB167B691941E793
01:\Software\Fieldston Software\gSyncit\{6B2259F7-A65D-EA58-EFE0-69067DCE754E}\_06A9F472DFA3441F8C8677EE5AAEE44F
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C1F15D7F2C5FBF57ACA75953A493B375
21B564291C5433C4DB167B691941E793
00:\CLSID\{AC9F1F13-0C3E-46E1-B493-0F8D0763672F}\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0EFB5147AE82C784DAE508C7C4673D51
21B564291C5433C4DB167B691941E793
00:\CLSID\{AC9F1F13-0C3E-46E1-B493-0F8D0763672F}\VersionIndependentProgID\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D4B288F9C94F7F323A02C7CAA584EFA4
21B564291C5433C4DB167B691941E793
00:\CLSID\{AC9F1F13-0C3E-46E1-B493-0F8D0763672F}\TypeLib\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4A3B203A7B3B285C034D4B3381742EB8
21B564291C5433C4DB167B691941E793
00:\CLSID\{AC9F1F13-0C3E-46E1-B493-0F8D0763672F}\ProgID\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4334EB4E67233AA883B21DC5D4422C14
21B564291C5433C4DB167B691941E793
00:\CLSID\{AC9F1F13-0C3E-46E1-B493-0F8D0763672F}\InprocServer32\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\440C4904A1C5F855CA130811573018E4
21B564291C5433C4DB167B691941E793
00:\CLSID\{AC9F1F13-0C3E-46E1-B493-0F8D0763672F}\InprocServer32\ThreadingModel
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\92985FBE2E5C44E37F8752E34AEBD5F1
21B564291C5433C4DB167B691941E793
00:\CLSID\{AC9F1F13-0C3E-46E1-B493-0F8D0763672F}\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CA30A37DCA8425B6EBF5E693713DBB01
21B564291C5433C4DB167B691941E793
00:\TypeLib\{085FFF9D-CE6C-490C-8A88-9CA82D39898E}\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\15419066B9F11E1FDA0FDBE5648B5FA8
21B564291C5433C4DB167B691941E793
00:\TypeLib\{085FFF9D-CE6C-490C-8A88-9CA82D39898E}\1.0\FLAGS\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E2109FB6DB239009A17739917B514BC
21B564291C5433C4DB167B691941E793
00:\TypeLib\{085FFF9D-CE6C-490C-8A88-9CA82D39898E}\1.0\HELPDIR\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AE58AB777D75140B514581A93527ABA6
21B564291C5433C4DB167B691941E793
00:\TypeLib\{085FFF9D-CE6C-490C-8A88-9CA82D39898E}\1.0\0\win32\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7A5D2E183A11E124942472F6F455A158
21B564291C5433C4DB167B691941E793
00:\TypeLib\{085FFF9D-CE6C-490C-8A88-9CA82D39898E}\1.0\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2FAEBCF647A5BA858D3D1C28DEC56D6D
21B564291C5433C4DB167B691941E793
00:\gSyncit.Connect.1\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FBF275AFF3A3E69FC9547FC76B629CDE
21B564291C5433C4DB167B691941E793
00:\gSyncit.Connect.1\CLSID\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9C57ECA2CEE19493E95A7259BBD37458
21B564291C5433C4DB167B691941E793
00:\gSyncit.Connect.1\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EA91F56BDFCE0A5E95A240FAFC1DA818
21B564291C5433C4DB167B691941E793
00:\gSyncit.Connect\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B54F4275F34271F7A6194A913D9B0BD3
21B564291C5433C4DB167B691941E793
00:\gSyncit.Connect\CurVer\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BBD0F35C4C8C4DAAF54640337AF7BC15
21B564291C5433C4DB167B691941E793
00:\gSyncit.Connect\CLSID\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\072D7E7C3248BD1A6D63C66D5952E7AB
21B564291C5433C4DB167B691941E793
00:\gSyncit.Connect\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\815E42A1AF86F2E9017021DE564906F9
21B564291C5433C4DB167B691941E793
01:\Software\Microsoft\Windows\CurrentVersion\Run\gSyncit
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B2CE84294FB087C81FEE41AD39DC9679
21B564291C5433C4DB167B691941E793
02:\Software\Microsoft\Office\Outlook\AddIns\gSyncit.Connect\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E237B18B2B55F8DF8F6155E63DDD09A4
21B564291C5433C4DB167B691941E793
02:\Software\Microsoft\Office\Outlook\AddIns\gSyncit.Connect\LoadBehavior
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4F534E415563406CE6BB7ABC27F5D32A
21B564291C5433C4DB167B691941E793
02:\Software\Microsoft\Office\Outlook\AddIns\gSyncit.Connect\CommandLineSafe
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\04E365274A1E5E2E5C5BC29E0A4804D6
21B564291C5433C4DB167B691941E793
02:\Software\Microsoft\Office\Outlook\AddIns\gSyncit.Connect\FriendlyName
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D18622CC8E73640C4F6554374BCAD6E6
21B564291C5433C4DB167B691941E793
02:\Software\Microsoft\Office\Outlook\AddIns\gSyncit.Connect\Description
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\71214F24B8FA4D33C93BFFF596B6CEBB
21B564291C5433C4DB167B691941E793
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\vcruntime140.dll
2
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B3D93E8E53F48D638B29B48233F60E14
21B564291C5433C4DB167B691941E793
C?\Windows\system32\vcruntime140.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\msvcp140.dll
2
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C069AA2AC3DFD6A3DBF641390311FA3B
21B564291C5433C4DB167B691941E793
C?\Windows\system32\msvcp140.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\msvcp140_1.dll
2
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F3027E2A2C06E7D3A864BDD383A1C26E
21B564291C5433C4DB167B691941E793
C?\Windows\system32\msvcp140_1.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\msvcp140_2.dll
2
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE9930CBD9E5C7C3FB5FE5A9599CD6FA
21B564291C5433C4DB167B691941E793
C?\Windows\system32\msvcp140_2.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\concrt140.dll
2
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F139CF91DE936230A1FA8ED33D0E0EC
21B564291C5433C4DB167B691941E793
C?\Windows\system32\concrt140.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\vccorlib140.dll
2
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97FC00201A9B4EB359A592AFD9B4A1C5
21B564291C5433C4DB167B691941E793
C?\Windows\system32\vccorlib140.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A678ABB91935492F880D08B2C9B84CC9
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\gsyncit.ext.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6D439C3D6A22B05FBFEE11636E8BA721
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\gsyncit.addin.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\34D9134963E5D1D59ACC7D533229BA2A
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\gsyncit.addin.dll.config
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6154CF2A4A119293CB79F665EAEB1CF6
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\gsyncit.exe.config
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C77C628777E10C03F29AD477C06F8E3C
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\gsyncit.exe
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FDD58F3EC258D52D61318E4F67AAB677
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\gsyncit.updater.exe.config
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6A222974F514635A2EFAE0566046595D
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\gsyncit.updater.exe
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5A9166A33599A923323692914F4629BC
21B564291C5433C4DB167B691941E793
C:\Program Files\Fieldston Software\gSyncit\gsyncit.addinshim.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\gSyncit\
1
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\Fieldston Software\gSyncit\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\Fieldston Software\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE9930CBD9E5C7C3FB5FE5A9599CD6FA\21B564291C5433C4DB167B691941E793
PatchGUID
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE9930CBD9E5C7C3FB5FE5A9599CD6FA\21B564291C5433C4DB167B691941E793
MediaCabinet
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE9930CBD9E5C7C3FB5FE5A9599CD6FA\21B564291C5433C4DB167B691941E793
File
msvcp140_2.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE9930CBD9E5C7C3FB5FE5A9599CD6FA\21B564291C5433C4DB167B691941E793
ComponentVersion
14.15.26706.0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE9930CBD9E5C7C3FB5FE5A9599CD6FA\21B564291C5433C4DB167B691941E793
ProductVersion
5.3.21
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE9930CBD9E5C7C3FB5FE5A9599CD6FA\21B564291C5433C4DB167B691941E793
PatchSize
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE9930CBD9E5C7C3FB5FE5A9599CD6FA\21B564291C5433C4DB167B691941E793
PatchAttributes
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE9930CBD9E5C7C3FB5FE5A9599CD6FA\21B564291C5433C4DB167B691941E793
PatchSequence
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE9930CBD9E5C7C3FB5FE5A9599CD6FA\21B564291C5433C4DB167B691941E793
SharedComponent
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE9930CBD9E5C7C3FB5FE5A9599CD6FA\21B564291C5433C4DB167B691941E793
IsFullFile
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C069AA2AC3DFD6A3DBF641390311FA3B\21B564291C5433C4DB167B691941E793
PatchGUID
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C069AA2AC3DFD6A3DBF641390311FA3B\21B564291C5433C4DB167B691941E793
MediaCabinet
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C069AA2AC3DFD6A3DBF641390311FA3B\21B564291C5433C4DB167B691941E793
File
msvcp140.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C069AA2AC3DFD6A3DBF641390311FA3B\21B564291C5433C4DB167B691941E793
ComponentVersion
14.15.26706.0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C069AA2AC3DFD6A3DBF641390311FA3B\21B564291C5433C4DB167B691941E793
ProductVersion
5.3.21
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C069AA2AC3DFD6A3DBF641390311FA3B\21B564291C5433C4DB167B691941E793
PatchSize
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C069AA2AC3DFD6A3DBF641390311FA3B\21B564291C5433C4DB167B691941E793
PatchAttributes
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C069AA2AC3DFD6A3DBF641390311FA3B\21B564291C5433C4DB167B691941E793
PatchSequence
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C069AA2AC3DFD6A3DBF641390311FA3B\21B564291C5433C4DB167B691941E793
SharedComponent
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C069AA2AC3DFD6A3DBF641390311FA3B\21B564291C5433C4DB167B691941E793
IsFullFile
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B3D93E8E53F48D638B29B48233F60E14\21B564291C5433C4DB167B691941E793
PatchGUID
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B3D93E8E53F48D638B29B48233F60E14\21B564291C5433C4DB167B691941E793
MediaCabinet
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B3D93E8E53F48D638B29B48233F60E14\21B564291C5433C4DB167B691941E793
File
vcruntime140.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B3D93E8E53F48D638B29B48233F60E14\21B564291C5433C4DB167B691941E793
ComponentVersion
14.15.26706.0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B3D93E8E53F48D638B29B48233F60E14\21B564291C5433C4DB167B691941E793
ProductVersion
5.3.21
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B3D93E8E53F48D638B29B48233F60E14\21B564291C5433C4DB167B691941E793
PatchSize
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B3D93E8E53F48D638B29B48233F60E14\21B564291C5433C4DB167B691941E793
PatchAttributes
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B3D93E8E53F48D638B29B48233F60E14\21B564291C5433C4DB167B691941E793
PatchSequence
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B3D93E8E53F48D638B29B48233F60E14\21B564291C5433C4DB167B691941E793
SharedComponent
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B3D93E8E53F48D638B29B48233F60E14\21B564291C5433C4DB167B691941E793
IsFullFile
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97FC00201A9B4EB359A592AFD9B4A1C5\21B564291C5433C4DB167B691941E793
PatchGUID
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97FC00201A9B4EB359A592AFD9B4A1C5\21B564291C5433C4DB167B691941E793
MediaCabinet
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97FC00201A9B4EB359A592AFD9B4A1C5\21B564291C5433C4DB167B691941E793
File
vccorlib140.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97FC00201A9B4EB359A592AFD9B4A1C5\21B564291C5433C4DB167B691941E793
ComponentVersion
14.15.26706.0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97FC00201A9B4EB359A592AFD9B4A1C5\21B564291C5433C4DB167B691941E793
ProductVersion
5.3.21
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97FC00201A9B4EB359A592AFD9B4A1C5\21B564291C5433C4DB167B691941E793
PatchSize
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97FC00201A9B4EB359A592AFD9B4A1C5\21B564291C5433C4DB167B691941E793
PatchAttributes
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97FC00201A9B4EB359A592AFD9B4A1C5\21B564291C5433C4DB167B691941E793
PatchSequence
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97FC00201A9B4EB359A592AFD9B4A1C5\21B564291C5433C4DB167B691941E793
SharedComponent
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97FC00201A9B4EB359A592AFD9B4A1C5\21B564291C5433C4DB167B691941E793
IsFullFile
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F3027E2A2C06E7D3A864BDD383A1C26E\21B564291C5433C4DB167B691941E793
PatchGUID
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F3027E2A2C06E7D3A864BDD383A1C26E\21B564291C5433C4DB167B691941E793
MediaCabinet
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F3027E2A2C06E7D3A864BDD383A1C26E\21B564291C5433C4DB167B691941E793
File
msvcp140_1.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F3027E2A2C06E7D3A864BDD383A1C26E\21B564291C5433C4DB167B691941E793
ComponentVersion
14.15.26706.0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F3027E2A2C06E7D3A864BDD383A1C26E\21B564291C5433C4DB167B691941E793
ProductVersion
5.3.21
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F3027E2A2C06E7D3A864BDD383A1C26E\21B564291C5433C4DB167B691941E793
PatchSize
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F3027E2A2C06E7D3A864BDD383A1C26E\21B564291C5433C4DB167B691941E793
PatchAttributes
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F3027E2A2C06E7D3A864BDD383A1C26E\21B564291C5433C4DB167B691941E793
PatchSequence
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F3027E2A2C06E7D3A864BDD383A1C26E\21B564291C5433C4DB167B691941E793
SharedComponent
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F3027E2A2C06E7D3A864BDD383A1C26E\21B564291C5433C4DB167B691941E793
IsFullFile
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F139CF91DE936230A1FA8ED33D0E0EC\21B564291C5433C4DB167B691941E793
PatchGUID
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F139CF91DE936230A1FA8ED33D0E0EC\21B564291C5433C4DB167B691941E793
MediaCabinet
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F139CF91DE936230A1FA8ED33D0E0EC\21B564291C5433C4DB167B691941E793
File
concrt140.dll.4E0C0521_7D4B_3B97_9D4C_5A47A4B7B4B3
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F139CF91DE936230A1FA8ED33D0E0EC\21B564291C5433C4DB167B691941E793
ComponentVersion
14.15.26706.0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F139CF91DE936230A1FA8ED33D0E0EC\21B564291C5433C4DB167B691941E793
ProductVersion
5.3.21
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F139CF91DE936230A1FA8ED33D0E0EC\21B564291C5433C4DB167B691941E793
PatchSize
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F139CF91DE936230A1FA8ED33D0E0EC\21B564291C5433C4DB167B691941E793
PatchAttributes
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F139CF91DE936230A1FA8ED33D0E0EC\21B564291C5433C4DB167B691941E793
PatchSequence
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F139CF91DE936230A1FA8ED33D0E0EC\21B564291C5433C4DB167B691941E793
SharedComponent
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8F139CF91DE936230A1FA8ED33D0E0EC\21B564291C5433C4DB167B691941E793
IsFullFile
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Windows\Installer\{92465B12-45C1-4C33-BD61-B79691147E39}\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AC9F1F13-0C3E-46E1-B493-0F8D0763672F}
Connect Class
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\gSyncit.Connect
Connect Class
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AC9F1F13-0C3E-46E1-B493-0F8D0763672F}\VersionIndependentProgID
gSyncit.Connect
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AC9F1F13-0C3E-46E1-B493-0F8D0763672F}\TypeLib
{085FFF9D-CE6C-490C-8A88-9CA82D39898E}
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\gSyncit.Connect.1
Connect Class
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AC9F1F13-0C3E-46E1-B493-0F8D0763672F}\ProgID
gSyncit.Connect.1
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AC9F1F13-0C3E-46E1-B493-0F8D0763672F}\InprocServer32
C:\Program Files\Fieldston Software\gSyncit\gsyncit.addinshim.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AC9F1F13-0C3E-46E1-B493-0F8D0763672F}\InprocServer32
ThreadingModel
Apartment
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{085FFF9D-CE6C-490C-8A88-9CA82D39898E}\1.0\FLAGS
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{085FFF9D-CE6C-490C-8A88-9CA82D39898E}\1.0\HELPDIR
C:\Program Files\Fieldston Software\gSyncit
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{085FFF9D-CE6C-490C-8A88-9CA82D39898E}\1.0\0\win32
C:\Program Files\Fieldston Software\gSyncit\gsyncit.addinshim.dll
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{085FFF9D-CE6C-490C-8A88-9CA82D39898E}\1.0
gSyncitConnectAddin 1.0 Type Library
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\gSyncit.Connect.1\CLSID
{AC9F1F13-0C3E-46E1-B493-0F8D0763672F}
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\gSyncit.Connect\CurVer
gSyncit.Connect.1
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\gSyncit.Connect\CLSID
{AC9F1F13-0C3E-46E1-B493-0F8D0763672F}
2192
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Fieldston Software\gSyncit\{6B2259F7-A65D-EA58-EFE0-69067DCE754E}
_06A9F472DFA3441F8C8677EE5AAEE44F
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\gSyncit\
2192
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Windows\CurrentVersion\Run
gSyncit
C:\Program Files\Fieldston Software\gSyncit\gsyncit.exe
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\gSyncit.Connect
LoadBehavior
3
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\gSyncit.Connect
CommandLineSafe
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\gSyncit.Connect
FriendlyName
gSyncit Outlook Add-In
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\gSyncit.Connect
Description
gSyncit Outlook Add-In
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
LocalPackage
C:\Windows\Installer\1a33d6.msi
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
AuthorizedCDFPrefix
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
Comments
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
Contact
Fieldston Software
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
DisplayVersion
5.3.21
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
HelpLink
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
HelpTelephone
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
InstallDate
20190111
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
InstallLocation
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
InstallSource
C:\Users\admin\Downloads\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
ModifyPath
MsiExec.exe /I{92465B12-45C1-4C33-BD61-B79691147E39}
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
Publisher
Fieldston Software
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
Readme
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
Size
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
EstimatedSize
20522
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
UninstallString
MsiExec.exe /I{92465B12-45C1-4C33-BD61-B79691147E39}
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
URLInfoAbout
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
URLUpdateInfo
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
VersionMajor
5
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
VersionMinor
3
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
WindowsInstaller
1
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
Version
84082709
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
Language
1033
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
AuthorizedCDFPrefix
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
Comments
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
Contact
Fieldston Software
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
DisplayVersion
5.3.21
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
HelpLink
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
HelpTelephone
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
InstallDate
20190111
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
InstallLocation
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
InstallSource
C:\Users\admin\Downloads\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
ModifyPath
MsiExec.exe /I{92465B12-45C1-4C33-BD61-B79691147E39}
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
Publisher
Fieldston Software
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
Readme
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
Size
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
EstimatedSize
20522
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
UninstallString
MsiExec.exe /I{92465B12-45C1-4C33-BD61-B79691147E39}
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
URLInfoAbout
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
URLUpdateInfo
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
VersionMajor
5
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
VersionMinor
3
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
WindowsInstaller
1
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
Version
84082709
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
Language
1033
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\AD1D8ED4159C0374B9595700163D6677
21B564291C5433C4DB167B691941E793
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\InstallProperties
DisplayName
gSyncit
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{92465B12-45C1-4C33-BD61-B79691147E39}
DisplayName
gSyncit
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Newtonsoft.Json.dll
Newtonsoft.Json,Version="10.0.0.0",Culture="neutral",PublicKeyToken="30AD4FE6B2A6AEED",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>MHa@9DaR'b[FzXdkk}pi
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|WunderlistLib.dll
WunderlistLib,Version="1.51.0.0",Culture="neutral",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>4r?B7.X_KMczG=S[ru`(
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|extensibility.dll
Extensibility,Version="7.0.3300.0",Culture="neutral",PublicKeyToken="B03F5F7F11D50A3A",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>?AoYPJi?P@T[f$3B7gZ8
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|System.Net.Http.Extensions.dll
System.Net.Http.Extensions,Version="2.2.29.0",Culture="neutral",PublicKeyToken="B03F5F7F11D50A3A",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>9E+.tF?XT29qQL,p])fS
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|System.Threading.Tasks.dll
System.Threading.Tasks,Version="2.6.10.0",Culture="neutral",PublicKeyToken="B03F5F7F11D50A3A",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>.ibdm54o^U-&+GH{0T^p
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|System.Net.Http.WebRequest.dll
System.Net.Http.WebRequest,Version="2.2.29.0",Culture="neutral",PublicKeyToken="B03F5F7F11D50A3A",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>9$WmePHNc^gt)P=!xdsw
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|XPExplorerBar.dll
XPExplorerBar,Version="3.6.0.0",Culture="neutral",PublicKeyToken="26272737B5F33015",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>.U'yCH}Jk^4@Gu_bu,}+
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|HtmlAgilityPack.dll
HtmlAgilityPack,Version="1.6.17.0",Culture="neutral",PublicKeyToken="BD319B19EAF3B43A",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>HG,7wph]0dutFn,t28@a
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Microsoft.Threading.Tasks.Extensions.dll
Microsoft.Threading.Tasks.Extensions,Version="1.0.12.0",Culture="neutral",PublicKeyToken="B03F5F7F11D50A3A",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>B{I1k&*uFV!le.X!PCXy
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|gSyncit.core.dll
gSyncit.core,Version="5.3.21.0",Culture="neutral",ProcessorArchitecture="x86"
o`($WY.eQ@@BJMX+c^P6>GyiS*w)*F3}9%w'.0_J!
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Google.Apis.Calendar.v3.dll
Google.Apis.Calendar.v3,Version="1.36.1.1391",Culture="neutral",PublicKeyToken="4B01FA6E34DB77AB",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>!QE-{IpeXJRS1P_I*m]+
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|GoogleLib2.dll
GoogleLib2,Version="3.108.0.0",Culture="neutral",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>3xzLI&pV@Q8pl]ffef@E
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|System.Data.SQLite.dll
System.Data.SQLite,Version="1.0.105.2",Culture="neutral",PublicKeyToken="DB937BC2D44FF139",ProcessorArchitecture="x86"
o`($WY.eQ@@BJMX+c^P6>t'mC=%dh4t.PUjteoIkO
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|S22.Imap.dll
S22.Imap,Version="3.45.0.0",Culture="neutral",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>[{KDM^h=[Myuk`3(U+N`
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|SqliteCache.dll
SqliteCache,Version="2.91.0.0",Culture="neutral",PublicKeyToken="D8831E73FE340B79",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>er0bMA.u'Jb(*kD]US&6
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|SharpNoteLib.dll
SharpNoteLib,Version="2.4.0.0",Culture="neutral",PublicKeyToken="EED502AD33CCF34B",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>==KzL]n{Sy0![QC=HEVe
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Google.Apis.Drive.v2.dll
Google.Apis.Drive.v2,Version="1.36.1.1390",Culture="neutral",PublicKeyToken="4B01FA6E34DB77AB",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>'f8?M?mM]v[~=3SpU1*7
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|ICSharpCode.SharpZipLib.dll
ICSharpCode.SharpZipLib,Version="0.86.0.518",Culture="neutral",PublicKeyToken="1B03E6ACF1164F73",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>rwN8-5I8!f14X8PH&`yj
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Microsoft.Office.Interop.Outlook.dll
Microsoft.Office.Interop.Outlook,Version="15.0.0.0",Culture="neutral",PublicKeyToken="71E9BCE111E9429C",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>+E.mx1~MBR^[_F]TSvWy
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|OFFICE.DLL
office,Version="15.0.0.0",Culture="neutral",PublicKeyToken="71E9BCE111E9429C",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>Ruz{ie,N6`FCq?(=So+L
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Google.GData.Extensions.dll
Google.GData.Extensions,Version="2.2.0.0",Culture="neutral",PublicKeyToken="0B4C5DF2EBF20876",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>'_co?`-LS``UV8_D]`=&
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|WebDavLib.dll
WebDavLib,Version="2.143.0.0",Culture="neutral",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>``a=xOoqjTdPt}GTw$6+
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|FileCache.Signed.dll
FileCache.Signed,Version="2.0.1.0",Culture="neutral",PublicKeyToken="7542C4E7F6A4D381",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>DVebhRv3sd4WFy5lqI0i
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|DropBoxLib.dll
DropBoxLib,Version="3.0.0.0",Culture="neutral",PublicKeyToken="CC628EB0558D221A",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>W_5_kDKvWQh`Yw635SVC
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Zlib.Portable.dll
Zlib.Portable,Version="1.11.0.0",Culture="neutral",PublicKeyToken="431CBA815F6A8B5B",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>*c*z3X}N4I_C_CG2mv*,
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|WizardLib.dll
WizardLib,Version="1.1.0.0",Culture="neutral",PublicKeyToken="B90E4D61E0685435",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>}ipGP!.4k!aP-C3(R)3Z
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Google.GData.Contacts.dll
Google.GData.Contacts,Version="2.2.0.0",Culture="neutral",PublicKeyToken="7E065189DD4B982F",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>aA?-6ba3cRi`JPGz1LS6
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|TodoistLib.dll
TodoistLib,Version="1.36.0.0",Culture="neutral",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>mz7Aw@P[0t6WM+o{wm,l
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Microsoft.Threading.Tasks.Extensions.Desktop.dll
Microsoft.Threading.Tasks.Extensions.Desktop,Version="1.0.168.0",Culture="neutral",PublicKeyToken="B03F5F7F11D50A3A",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>c.`8cVWo5[gbkX?Z9&FW
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Google.Apis.Auth.dll
Google.Apis.Auth,Version="1.10.0.25333",Culture="neutral",PublicKeyToken="4B01FA6E34DB77AB",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>y{37!Qp22l7{ELzesWO+
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Google.Apis.Core.dll
Google.Apis.Core,Version="1.10.0.25331",Culture="neutral",PublicKeyToken="4B01FA6E34DB77AB",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>Fj13mSsxw,3bjr+O-w!F
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Dropbox.Api.dll
Dropbox.Api,Version="4.0.0.0",Culture="neutral",PublicKeyToken="310F0E82FBB45D01",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>YJl+&-Bt'c'O8CYo(UD]
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|NozbeLib.dll
NozbeLib,Version="2.5.0.0",Culture="neutral",PublicKeyToken="5BB3D9AB63D9604A",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>8vaff&FegtTsaOj[tUE^
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Google.GData.Client.dll
Google.GData.Client,Version="2.2.0.0",Culture="neutral",PublicKeyToken="04A59CA9B0273830",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>akN3e~Gux03i_dnYa6nr
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|System.Net.Http.Primitives.dll
System.Net.Http.Primitives,Version="2.2.29.0",Culture="neutral",PublicKeyToken="B03F5F7F11D50A3A",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>wGUQK+Q?&6QDVTL6n(c!
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Thrift.dll
Thrift,Version="2.4.0.0",Culture="neutral",PublicKeyToken="3603712D927D1C1D",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>+hpJ`X8'~z[&CR+y[b^A
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|System.Runtime.dll
System.Runtime,Version="2.6.10.0",Culture="neutral",PublicKeyToken="B03F5F7F11D50A3A",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>Czb*AjW{7(wfmQ[0-iEv
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|PocketInformantLib2.dll
PocketInformantLib2,Version="3.15.0.0",Culture="neutral",PublicKeyToken="13C29041AF3CAA0A",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>[?GfHMGyHvYB@C`ZK$7J
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|ObjectCache.dll
ObjectCache,Version="2.91.0.0",Culture="neutral",PublicKeyToken="311826E6D5378127",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>Vh{Y-MxQ1-Fx*dd`!7p1
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|System.IO.dll
System.IO,Version="2.6.10.0",Culture="neutral",PublicKeyToken="B03F5F7F11D50A3A",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>9qP-KWXCoaW9WDhT`[?5
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Evernote.dll
Evernote,Version="2.5.0.0",Culture="neutral",PublicKeyToken="47F5F7499D7AD128",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>X`]9?vVbbl%iyj@dQ8Tk
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|EvernoteLib.dll
EvernoteLib,Version="2.12.0.0",Culture="neutral",PublicKeyToken="ED54753DBF115322",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>7MMMi7u.fHybbSdh]iwf
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Google.Apis.dll
Google.Apis,Version="1.10.0.25332",Culture="neutral",PublicKeyToken="4B01FA6E34DB77AB",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>T^h]iINUg]^UJ!vSDURj
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|ToodledoLib3.dll
ToodledoLib3,Version="2.115.0.0",Culture="neutral",PublicKeyToken="A728245C1C1B2F9F",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>^RXzso4+4?yx[+8q@Ou4
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|stdole.dll
stdole,Version="7.0.3300.0",Culture="neutral",PublicKeyToken="B03F5F7F11D50A3A",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>Ml6b-%vHijP=zO9Paj[Q
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Microsoft.Threading.Tasks.dll
Microsoft.Threading.Tasks,Version="1.0.12.0",Culture="neutral",PublicKeyToken="B03F5F7F11D50A3A",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>{1mFOScq^vh(sfa^L0)m
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Google.Apis.Tasks.v1.dll
Google.Apis.Tasks.v1,Version="1.36.1.0",Culture="neutral",PublicKeyToken="4B01FA6E34DB77AB",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>}=.X7Yx_Jud,7ved}RUF
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|RestSharp.dll
RestSharp,Version="101.3.0.0",Culture="neutral",PublicKeyToken="984CD78A38ED2B7D",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>}l-BULcrpK0$9ZTfuCC.
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Newtonsoft.Json.Net35.dll
Newtonsoft.Json.Net35,Version="4.0.2.0",Culture="neutral",PublicKeyToken="30AD4FE6B2A6AEED",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>l}mVl8~0LB4tokwme[,F
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|System.Net.Http.dll
System.Net.Http,Version="2.2.29.0",Culture="neutral",PublicKeyToken="B03F5F7F11D50A3A",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>2`b'C9qedGvCL$0i)X'2
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|Google.Apis.PeopleService.v1.dll
Google.Apis.PeopleService.v1,Version="1.36.1.1397",Culture="neutral",PublicKeyToken="4B01FA6E34DB77AB",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>gl_an4K$)^Qmy^UdAHnw
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|gsyncit.addin.dll
gsyncit.addin,Version="5.3.21.0",Culture="neutral",ProcessorArchitecture="x86"
o`($WY.eQ@@BJMX+c^P6>}Ni(mG}BiwZI.H5T*px(
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|gsyncit.exe
gsyncit,Version="5.3.21.0",Culture="neutral",ProcessorArchitecture="x86"
o`($WY.eQ@@BJMX+c^P6>aPJ]NYhma3q'8EN(m&{g
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Fieldston Software|gSyncit|gsyncit.updater.exe
gsyncit.updater,Version="5.3.21.0",Culture="neutral",PublicKeyToken="906CE6B0AE8E6383",ProcessorArchitecture="MSIL"
o`($WY.eQ@@BJMX+c^P6>v)8!?O^J+^)xjPHSar_m
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\21B564291C5433C4DB167B691941E793
DefaultFeature
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\Features
DefaultFeature
MHa@9DaR'b[FzXdkk}pi4r?B7.X_KMczG=S[ru`(?AoYPJi?P@T[f$3B7gZ89E+.tF?XT29qQL,p])fS.ibdm54o^U-&+GH{0T^p9$WmePHNc^gt)P=!xdsw.U'yCH}Jk^4@Gu_bu,}+HG,7wph]0dutFn,t28@aMHa@9DaR'b[FzXdkk}piB{I1k&*uFV!le.X!PCXyGyiS*w)*F3}9%w'.0_J!!QE-{IpeXJRS1P_I*m]+3xzLI&pV@Q8pl]ffef@EYZtT77fYx8'0x2.nf6Dyt'mC=%dh4t.PUjteoIkO[{KDM^h=[Myuk`3(U+N`er0bMA.u'Jb(*kD]US&6==KzL]n{Sy0![QC=HEVeHG,7wph]0dutFn,t28@ag2K[G4Pbw_wG4rpu{4vz'f8?M?mM]v[~=3SpU1*7rwN8-5I8!f14X8PH&`yj+E.mx1~MBR^[_F]TSvWyRuz{ie,N6`FCq?(=So+L'_co?`-LS``UV8_D]`=&``a=xOoqjTdPt}GTw$6+DVebhRv3sd4WFy5lqI0iW_5_kDKvWQh`Yw635SVC*c*z3X}N4I_C_CG2mv*,}ipGP!.4k!aP-C3(R)3ZaA?-6ba3cRi`JPGz1LS6t'mC=%dh4t.PUjteoIkOmz7Aw@P[0t6WM+o{wm,lS@Woc~!Af&'cCG3o(HDRc.`8cVWo5[gbkX?Z9&FWy{37!Qp22l7{ELzesWO+Fj13mSsxw,3bjr+O-w!FYJl+&-Bt'c'O8CYo(UD]8vaff&FegtTsaOj[tUE^er0bMA.u'Jb(*kD]US&6akN3e~Gux03i_dnYa6nrDx%^Mp4NEo0HfP,EQ58IwGUQK+Q?&6QDVTL6n(c!+hpJ`X8'~z[&CR+y[b^ACzb*AjW{7(wfmQ[0-iEv[?GfHMGyHvYB@C`ZK$7JVh{Y-MxQ1-Fx*dd`!7p19qP-KWXCoaW9WDhT`[?5X`]9?vVbbl%iyj@dQ8Tk7MMMi7u.fHybbSdh]iwf*c*z3X}N4I_C_CG2mv*,T^h]iINUg]^UJ!vSDURj^RXzso4+4?yx[+8q@Ou4Ml6b-%vHijP=zO9Paj[Q{1mFOScq^vh(sfa^L0)m}=.X7Yx_Jud,7ved}RUF}l-BULcrpK0$9ZTfuCC.l}mVl8~0LB4tokwme[,F2`b'C9qedGvCL$0i)X'2gl_an4K$)^Qmy^UdAHnw]xkLJpw)Cti%6(%4rM6A,FS`xRr4wM4Sq65=L(&DRYBBMUq5A?,W8$P$E=$*t!8?[%q]W.k1+M`jGg+@}k=I],NjPhk`W]4K8PzTC~!TrTyKWTe(aoEHuM.9W(@i8)IJRCB]+^(qS_7Ah+0ptSI,$8QPj{7^]t)-?%i2n+fuQJC6zN60J0H(R2RlHbYsgv4r8NFRQ7aTn+@Xfiyd3!j.e8YWFeCjvSqPNIG+`aD!eTYiMdAJ`7EhQ9h999JsYfKmz6kRAN1xKP^ERDox.%Rv,-'njE%Oy`822y$*x1Phe&Lua4Li1aA}J6$LhxWCB$pR[w3]cD~4mr`D99a&sy^QILc!DxG{pP3JU8+NRBo7KoVIh1.wu_y8gI4mOV@Bqt49iM8j$]y=lvmrzjxdeK7J+YlMpZ?`R4uxu!7[qxD$W(iN0UM~h*o1fMaXHR[2di{{QzPQ1OK`t'{?K1ge)$5Z_hq{^Nj*s50]pGWhLx0[wqe9)ysPk_,KGff[jO@flf'1)'MfQkQK.u*T9l]z`4(PYqFPCrIey6?qsgmA^58hny0Bbb29nSr?]`o7k6Rz'?Wxzihbh`CF]]mxi7hNqs74L'}rrZDLe-QJM7'c8]YOJTHagp2F[)xX44zq]TpEA47ktWf_!Nz6978].Jy-?0[EqHD'Z?*!{v(!O}1]EfHZ}Ni(mG}BiwZI.H5T*px(zfQ^W39lwEV)xA5'N{?]yMYH]@XWG6BEDkCr2)wKaPJ]NYhma3q'8EN(m&{gBxt=r`Wy[l*zXew'7MHNv)8!?O^J+^)xjPHSar_m-?Ij63^M=4F(I*+1LFLj
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\21B564291C5433C4DB167B691941E793\Patches
AllPatches
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\21B564291C5433C4DB167B691941E793
ProductName
gSyncit
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\21B564291C5433C4DB167B691941E793
PackageCode
E64C6E571C29867489BE895FD8421F52
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\21B564291C5433C4DB167B691941E793
Language
1033
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\21B564291C5433C4DB167B691941E793
Version
84082709
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\21B564291C5433C4DB167B691941E793
Assignment
1
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\21B564291C5433C4DB167B691941E793
AdvertiseFlags
388
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\21B564291C5433C4DB167B691941E793
ProductIcon
C:\Windows\Installer\{92465B12-45C1-4C33-BD61-B79691147E39}\_853F67D554F05449430E7E.exe
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\21B564291C5433C4DB167B691941E793
InstanceType
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\21B564291C5433C4DB167B691941E793
AuthorizedLUAApp
0
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\21B564291C5433C4DB167B691941E793
DeploymentFlags
2
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\AD1D8ED4159C0374B9595700163D6677
21B564291C5433C4DB167B691941E793
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\21B564291C5433C4DB167B691941E793\SourceList
PackageName
gSyncit_5_3_21.msi
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\21B564291C5433C4DB167B691941E793\SourceList\Net
1
C:\Users\admin\Downloads\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\21B564291C5433C4DB167B691941E793\SourceList\Media
1
;
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\21B564291C5433C4DB167B691941E793
Clients
:
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\21B564291C5433C4DB167B691941E793\SourceList
LastUsedSource
n;1;C:\Users\admin\Downloads\
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings
StringCacheGeneration
96
2192
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\Volatile
NestingLevel
0
3948
MsiExec.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3948
MsiExec.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
IDENTIFY (Enter)
4000000000000000249DDBE291A9D4018C0F0000200E0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
IDENTIFY (Enter)
4000000000000000249DDBE291A9D4018C0F0000E4090000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
IDENTIFY (Enter)
4000000000000000249DDBE291A9D4018C0F0000E8090000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
IDENTIFY (Enter)
4000000000000000249DDBE291A9D4018C0F00000C0E0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
IDENTIFY (Leave)
400000000000000032C4E2E291A9D4018C0F0000E8090000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
IDENTIFY (Leave)
40000000000000008C26E5E291A9D4018C0F0000200E0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
IDENTIFY (Leave)
4000000000000000E688E7E291A9D4018C0F0000E4090000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
IDENTIFY (Leave)
40000000000000009A4DECE291A9D4018C0F00000C0E0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_BEGINPREPARE (Enter)
4000000000000000C2C601EB91A9D4018C0F00000C0E0000010400000100000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_BEGINPREPARE (Leave)
4000000000000000C2C601EB91A9D4018C0F00000C0E0000010400000000000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPAREBACKUP (Enter)
4000000000000000DE1410EB91A9D4018C0F00000C0E0000E90300000100000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPAREBACKUP (Enter)
4000000000000000DE1410EB91A9D4018C0F0000E4090000E90300000100000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPAREBACKUP (Enter)
4000000000000000DE1410EB91A9D4018C0F0000200E0000E90300000100000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPAREBACKUP (Leave)
400000000000000092D914EB91A9D4018C0F00000C0E0000E90300000000000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_STABLE (SetCurrentState)
400000000000000092D914EB91A9D4018C0F00000C0E0000010000000100000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPAREBACKUP (Leave)
400000000000000092D914EB91A9D4018C0F0000200E0000E90300000000000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_STABLE (SetCurrentState)
400000000000000092D914EB91A9D4018C0F0000200E0000010000000100000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPAREBACKUP (Leave)
400000000000000092D914EB91A9D4018C0F0000E4090000E90300000000000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_STABLE (SetCurrentState)
400000000000000092D914EB91A9D4018C0F0000E4090000010000000100000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
GETSTATE (Enter)
40000000000000007E3A36EB91A9D4018C0F0000E4090000F90300000100000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
GETSTATE (Enter)
40000000000000007E3A36EB91A9D4018C0F0000200E0000F90300000100000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
GETSTATE (Enter)
40000000000000007E3A36EB91A9D4018C0F00000C0E0000F90300000100000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
GETSTATE (Leave)
40000000000000007E3A36EB91A9D4018C0F00000C0E0000F90300000000000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
GETSTATE (Leave)
40000000000000007E3A36EB91A9D4018C0F0000200E0000F90300000000000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
GETSTATE (Leave)
40000000000000007E3A36EB91A9D4018C0F0000E4090000F90300000000000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_ENDPREPARE (Enter)
40000000000000008C613DEB91A9D4018C0F0000400A0000020400000100000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_ENDPREPARE (Leave)
4000000000000000C0BCDAEB91A9D4018C0F0000400A0000020400000000000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
PREPARESNAPSHOT (Enter)
4000000000000000C0BCDAEB91A9D4018C0F0000400A0000EA0300000100000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPARESNAPSHOT (Enter)
4000000000000000366DEBEB91A9D4018C0F0000040A0000EA0300000100000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPARESNAPSHOT (Enter)
4000000000000000366DEBEB91A9D4018C0F00000C0A0000EA0300000100000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPARESNAPSHOT (Enter)
4000000000000000366DEBEB91A9D4018C0F0000EC090000EA0300000100000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPARESNAPSHOT (Leave)
400000000000000060E200EC91A9D4018C0F00000C0A0000EA0300000000000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)
400000000000000060E200EC91A9D4018C0F00000C0A0000020000000100000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPARESNAPSHOT (Leave)
400000000000000014A705EC91A9D4018C0F0000040A0000EA0300000000000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)
400000000000000014A705EC91A9D4018C0F0000040A0000020000000100000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPARESNAPSHOT (Leave)
400000000000000014A705EC91A9D4018C0F0000EC090000EA0300000000000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)
400000000000000014A705EC91A9D4018C0F0000EC090000020000000100000001000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
PREPARESNAPSHOT (Leave)
400000000000000084DF3EEC91A9D4018C0F0000400A0000EA0300000000000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE (Enter)
400000000000000084DF3EEC91A9D4018C0F0000400A0000EB0300000100000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_FRONT (Enter)
400000000000000084DF3EEC91A9D4018C0F0000400A0000EC0300000100000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
FREEZE (Enter)
4000000000000000920646EC91A9D4018C0F0000080A0000EB0300000100000002000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
FREEZE (Leave)
4000000000000000920646EC91A9D4018C0F0000080A0000EB0300000000000002000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_WAITING_FOR_THAW (SetCurrentState)
4000000000000000920646EC91A9D4018C0F0000080A0000030000000100000002000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
BKGND_FREEZE_THREAD (Enter)
4000000000000000920646EC91A9D4018C0F0000200B0000FC0300000100000003000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_FRONT (Leave)
4000000000000000920646EC91A9D4018C0F0000400A0000EC0300000000000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_BACK (Enter)
4000000000000000920646EC91A9D4018C0F0000400A0000ED0300000100000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_BACK (Leave)
4000000000000000A02D4DEC91A9D4018C0F0000400A0000ED0300000000000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_SYSTEM (Enter)
4000000000000000A02D4DEC91A9D4018C0F0000400A0000EE0300000100000000000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
FREEZE (Enter)
400000000000000054F251EC91A9D4018C0F0000040A0000EB0300000100000002000000000000000D0477660D5530429E01934B7AEE5B260000000000000000
3980
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
FREEZE (Leave)
400000000000000054F251EC91A9D4018C0F0000040A0000EB0300000000000002000000000000000D0477660D5530429E01934B7AEE5B260000000000000000