General Info

URL

http://down.easeus.com/product/mobimover_free

Full analysis
https://app.any.run/tasks/e8fa5bd3-87d4-4928-ab88-59492edffa5d
Verdict
Malicious activity
Analysis date
1/10/2019, 15:44:28
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:

opendir

loader

Indicators:

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
300 seconds
Additional time used
240 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads dropped or rewritten executable
  • uexperice.exe (PID: 3812)
  • uexperice.exe (PID: 3328)
  • uexperice.exe (PID: 3760)
  • MobiMoverUI.exe (PID: 3368)
  • uexperice.exe (PID: 3772)
  • AppleMobileDeviceService.exe (PID: 3440)
  • uexperice.exe (PID: 3304)
  • uexperice.exe (PID: 692)
Application was dropped or rewritten from another process
  • EDownloader.exe (PID: 3608)
  • FixFFmpeg.exe (PID: 1476)
  • FixFFmpeg.exe (PID: 2392)
  • FixFFmpeg.exe (PID: 1888)
  • FixFFmpeg.exe (PID: 1644)
  • AppleMobileDeviceService.exe (PID: 3440)
  • FixFFmpeg.exe (PID: 2804)
  • FixFFmpeg.exe (PID: 4092)
  • MobiMoverUI.exe (PID: 3368)
  • FixFFmpeg.exe (PID: 936)
  • FixFFmpeg.exe (PID: 4076)
  • FixFFmpeg.exe (PID: 3832)
  • uexperice.exe (PID: 3760)
  • uexperice.exe (PID: 3328)
  • uexperice.exe (PID: 3772)
  • uexperice.exe (PID: 3812)
  • uexperice.exe (PID: 692)
  • FixFFmpeg.exe (PID: 2704)
  • uexperice.exe (PID: 3304)
  • EDownloader.exe (PID: 2648)
  • downloader.exe (PID: 2856)
  • InstallPreProc.exe (PID: 4000)
  • AppStoreProc.exe (PID: 4016)
  • test[1].exe (PID: 3340)
  • test[1].exe (PID: 2620)
Downloads executable files from the Internet
  • iexplore.exe (PID: 3632)
  • EDownloader.exe (PID: 2648)
Application launched itself
  • EDownloader.exe (PID: 2648)
  • cmd.exe (PID: 2416)
Executable content was dropped or overwritten
  • FixFFmpeg.exe (PID: 2392)
  • FixFFmpeg.exe (PID: 1888)
  • FixFFmpeg.exe (PID: 936)
  • FixFFmpeg.exe (PID: 2704)
  • FixFFmpeg.exe (PID: 1476)
  • MsiExec.exe (PID: 3468)
  • test[1].exe (PID: 3340)
  • mover_free_easeus.exe (PID: 3100)
  • mover_free_easeus.tmp (PID: 3044)
  • iexplore.exe (PID: 3128)
  • iexplore.exe (PID: 3016)
  • iexplore.exe (PID: 3632)
  • msiexec.exe (PID: 2892)
Starts CMD.EXE for commands execution
  • mover_free_easeus.tmp (PID: 3044)
  • cmd.exe (PID: 2416)
Creates files in the user directory
  • MobiMoverUI.exe (PID: 3368)
  • uexperice.exe (PID: 3760)
  • uexperice.exe (PID: 3304)
  • mover_free_easeus.tmp (PID: 3044)
Creates files in the driver directory
  • DrvInst.exe (PID: 2508)
  • DrvInst.exe (PID: 3248)
Searches for installed software
  • MobiMoverUI.exe (PID: 3368)
Removes files from Windows directory
  • DrvInst.exe (PID: 3248)
  • msiexec.exe (PID: 2892)
  • DrvInst.exe (PID: 2508)
Creates files in the Windows directory
  • DrvInst.exe (PID: 2508)
  • DrvInst.exe (PID: 3248)
  • msiexec.exe (PID: 2892)
Creates COM task schedule object
  • msiexec.exe (PID: 2892)
Creates files in the program directory
  • MobiMoverUI.exe (PID: 3368)
Reads the Windows organization settings
  • mover_free_easeus.tmp (PID: 3044)
Reads Windows owner or organization settings
  • mover_free_easeus.tmp (PID: 3044)
Reads internet explorer settings
  • EDownloader.exe (PID: 2648)
Starts Microsoft Installer
  • downloader.exe (PID: 2856)
Loads dropped or rewritten executable
  • mover_free_easeus.tmp (PID: 3044)
  • msiexec.exe (PID: 2892)
Application was dropped or rewritten from another process
  • mover_free_easeus.tmp (PID: 3044)
Creates a software uninstall entry
  • msiexec.exe (PID: 2892)
  • mover_free_easeus.tmp (PID: 3044)
Application launched itself
  • msiexec.exe (PID: 2892)
  • iexplore.exe (PID: 2972)
Reads internet explorer settings
  • iexplore.exe (PID: 3632)
Reads Internet Cache Settings
  • iexplore.exe (PID: 3128)
  • iexplore.exe (PID: 3016)
  • iexplore.exe (PID: 3632)
Changes internet zones settings
  • iexplore.exe (PID: 2972)
  • iexplore.exe (PID: 3016)
Creates files in the program directory
  • mover_free_easeus.tmp (PID: 3044)
  • msiexec.exe (PID: 2892)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Screenshots

Processes

Total processes
92
Monitored processes
42
Malicious processes
11
Suspicious processes
6

Behavior graph

+
start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start iexplore.exe iexplore.exe iexplore.exe iexplore.exe test[1].exe no specs test[1].exe edownloader.exe mover_free_easeus.exe mover_free_easeus.tmp installpreproc.exe no specs appstoreproc.exe no specs downloader.exe msiexec.exe no specs msiexec.exe msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe drvinst.exe no specs drvinst.exe no specs applemobiledeviceservice.exe uexperice.exe no specs uexperice.exe no specs uexperice.exe no specs uexperice.exe no specs uexperice.exe no specs uexperice.exe cmd.exe no specs cmd.exe no specs fixffmpeg.exe no specs fixffmpeg.exe no specs fixffmpeg.exe fixffmpeg.exe fixffmpeg.exe fixffmpeg.exe fixffmpeg.exe fixffmpeg.exe no specs fixffmpeg.exe no specs fixffmpeg.exe no specs edownloader.exe no specs mobimoverui.exe
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
2972
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" -nohome
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
1
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\cryptbase.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\ieui.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\clbcatq.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\url.dll
c:\windows\system32\version.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\propsys.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\msfeeds.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\mlang.dll
c:\windows\system32\userenv.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\actxprxy.dll

PID
3128
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2972 CREDAT:71937
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
iexplore.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\comdlg32.dll
c:\program files\internet explorer\ieshims.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rsaenh.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\mlang.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\apphelp.dll
c:\program files\java\jre1.8.0_92\bin\ssv.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\version.dll
c:\progra~1\micros~1\office14\urlredir.dll
c:\windows\system32\secur32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\progra~1\micros~1\office14\msohev.dll
c:\program files\java\jre1.8.0_92\bin\jp2ssv.dll
c:\program files\java\jre1.8.0_92\bin\msvcr100.dll
c:\program files\java\jre1.8.0_92\bin\deploy.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\sxs.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll
c:\windows\system32\wpc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll

PID
3016
CMD
"C:\Program Files\Internet Explorer\iexplore.exe"
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
1
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\cryptbase.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\version.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\ieui.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\url.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\propsys.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\msfeeds.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mlang.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\naturallanguage6.dll
c:\windows\system32\nlsdata0009.dll
c:\windows\system32\nlslexicons0009.dll
c:\windows\system32\tquery.dll
c:\windows\system32\structuredquery.dll
c:\windows\system32\secur32.dll
c:\windows\system32\actxprxy.dll
c:\windows\system32\shdocvw.dll
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\rb73mz6y\test[1].exe
c:\windows\system32\mpr.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\userenv.dll
c:\windows\system32\linkinfo.dll

PID
3632
CMD
"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3016 CREDAT:71937
Path
C:\Program Files\Internet Explorer\iexplore.exe
Indicators
Parent process
iexplore.exe
User
admin
Integrity Level
LOW
Exit code
0
Version:
Company
Microsoft Corporation
Description
Internet Explorer
Version
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\comdlg32.dll
c:\program files\internet explorer\ieshims.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\internet explorer\sqmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rsaenh.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\mlang.dll
c:\windows\system32\uxtheme.dll
c:\program files\java\jre1.8.0_92\bin\ssv.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\version.dll
c:\progra~1\micros~1\office14\urlredir.dll
c:\windows\system32\secur32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\progra~1\micros~1\office14\msohev.dll
c:\program files\java\jre1.8.0_92\bin\jp2ssv.dll
c:\program files\java\jre1.8.0_92\bin\msvcr100.dll
c:\program files\java\jre1.8.0_92\bin\deploy.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\winmm.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\wdmaud.drv
c:\windows\system32\ksuser.dll
c:\windows\system32\avrt.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\audioses.dll
c:\windows\system32\msacm32.drv
c:\windows\system32\msacm32.dll
c:\windows\system32\midimap.dll
c:\windows\system32\wpc.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\slc.dll
c:\windows\system32\imageres.dll
c:\windows\system32\wintrust.dll

PID
2620
CMD
"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\test[1].exe"
Path
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\test[1].exe
Indicators
No indicators
Parent process
iexplore.exe
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\rb73mz6y\test[1].exe
c:\systemroot\system32\ntdll.dll

PID
3340
CMD
"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\test[1].exe"
Path
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\test[1].exe
Indicators
Parent process
iexplore.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\rb73mz6y\test[1].exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\propsys.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\version.dll
c:\windows\system32\shfolder.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\users\admin\appdata\local\temp\downloader_easeus\1.0.0\1free\edownloader.exe

PID
2648
CMD
"C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\1free\EDownloader.exe" EXEDIR=C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y ||| EXENAME=test[1].exe ||| DOWNLOAD_VERSION=free ||| PRODUCT_VERSION=1.0.0 ||| INSTALL_TYPE=0
Path
C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\1free\EDownloader.exe
Indicators
Parent process
test[1].exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\downloader_easeus\1.0.0\1free\edownloader.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\wship6.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msftedit.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\profapi.dll
c:\windows\system32\mshtml.dll
c:\windows\system32\msls31.dll
c:\windows\system32\version.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\msimtf.dll
c:\windows\system32\mlang.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\rb73mz6y\mover_free_easeus.exe
c:\windows\system32\propsys.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll

PID
3100
CMD
/verysilent /DIR="C:\Program Files\EaseUS\EaseUS MobiMover" /LANG=English agreeImprove =true GUID=B272D8F4-741D-49ee-AB9A-793C70EB1EC3
Path
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\mover_free_easeus.exe
Indicators
Parent process
EDownloader.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
EaseUS
Description
EaseUS MobiMover Setup
Version
4.5
Modules
Image
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\rb73mz6y\mover_free_easeus.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\shell32.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\is-fs4l1.tmp\mover_free_easeus.tmp

PID
3044
CMD
"C:\Users\admin\AppData\Local\Temp\is-FS4L1.tmp\mover_free_easeus.tmp" /SL5="$301AE,52609962,119296,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\mover_free_easeus.exe" /verysilent /DIR="C:\Program Files\EaseUS\EaseUS MobiMover" /LANG=English agreeImprove =true GUID=B272D8F4-741D-49ee-AB9A-793C70EB1EC3
Path
C:\Users\admin\AppData\Local\Temp\is-FS4L1.tmp\mover_free_easeus.tmp
Indicators
Parent process
mover_free_easeus.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Setup/Uninstall
Version
51.1052.0.0
Modules
Image
c:\users\admin\appdata\local\temp\is-fs4l1.tmp\mover_free_easeus.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\version.dll
c:\windows\system32\mpr.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\profapi.dll
c:\users\admin\appdata\local\temp\is-huenc.tmp\_isetup\_shfoldr.dll
c:\windows\system32\shfolder.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\bcryptprimitives.dll
c:\users\admin\appdata\local\temp\is-huenc.tmp\euactiveonline.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\imageres.dll
c:\windows\system32\clbcatq.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\msftedit.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\propsys.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\program files\easeus\easeus mobimover\bin\mobimoverui.exe
c:\program files\easeus\easeus mobimover\unins000.exe
c:\windows\system32\apphelp.dll
c:\program files\easeus\easeus mobimover\bin\installpreproc.exe
c:\program files\easeus\easeus mobimover\bin\uexperice.exe
c:\windows\system32\netutils.dll

PID
4000
CMD
"C:\Program Files\EaseUS\EaseUS MobiMover\bin\InstallPreProc.exe"
Path
C:\Program Files\EaseUS\EaseUS MobiMover\bin\InstallPreProc.exe
Indicators
No indicators
Parent process
mover_free_easeus.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\program files\easeus\easeus mobimover\bin\installpreproc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ole32.dll
c:\windows\system32\apphelp.dll
c:\program files\easeus\easeus mobimover\bin\appstoreproc.exe
c:\program files\easeus\easeus mobimover\bin\downloader.exe

PID
4016
CMD
"C:\Program Files\EaseUS\EaseUS MobiMover\bin\AppStoreProc.exe"
Path
C:\Program Files\EaseUS\EaseUS MobiMover\bin\AppStoreProc.exe
Indicators
No indicators
Parent process
InstallPreProc.exe
User
admin
Integrity Level
HIGH
Exit code
4294967295
Version:
Company
Description
Version
Modules
Image
c:\program files\easeus\easeus mobimover\bin\appstoreproc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
2856
CMD
-p
Path
C:\Program Files\EaseUS\EaseUS MobiMover\bin\downloader.exe
Indicators
Parent process
InstallPreProc.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\program files\easeus\easeus mobimover\bin\downloader.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ole32.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\msiexec.exe
c:\windows\system32\apphelp.dll

PID
3716
CMD
C:\Windows\system32\msiexec.exe /i C:\Users\admin\AppData\Local\Temp\MobiMover\InstallProc\Download\AppleApplicationSupport.msi /q /norestart
Path
C:\Windows\system32\msiexec.exe
Indicators
No indicators
Parent process
downloader.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\msimsg.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\rpcrtremote.dll

PID
2892
CMD
C:\Windows\system32\msiexec.exe /V
Path
C:\Windows\system32\msiexec.exe
Indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\msimsg.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msisip.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\winsta.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\microsoft.net\framework\v4.0.30319\fusion.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\vccorlib140.dll
c:\windows\system32\concrt140.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\vccorlib120.dll
c:\windows\system32\msvcp120.dll
c:\windows\system32\msvcr120.dll
c:\windows\system32\msvcp100.dll
c:\windows\system32\msvcr100.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d08d7da0442a985d\msvcr80.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\sxsstore.dll

PID
3904
CMD
C:\Windows\system32\MsiExec.exe -Embedding A00389C03851715E80DC3C7663CED9AD
Path
C:\Windows\system32\MsiExec.exe
Indicators
No indicators
Parent process
msiexec.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\mpr.dll
c:\windows\system32\winspool.drv
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\installer\msif076.tmp
c:\windows\installer\msif0d5.tmp
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\installer\msif191.tmp
c:\windows\installer\msif2ac.tmp
c:\windows\installer\msif2bc.tmp
c:\windows\installer\msif2bd.tmp
c:\windows\installer\msi145.tmp
c:\windows\installer\msi3d7.tmp
c:\windows\installer\msiaed.tmp

PID
1392
CMD
C:\Windows\system32\MsiExec.exe -Embedding 74D71715A45ECF2442611B456FD0A5B7 M Global\MSI0000
Path
C:\Windows\system32\MsiExec.exe
Indicators
No indicators
Parent process
msiexec.exe
User
SYSTEM
Integrity Level
SYSTEM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\installer\msi45f4.tmp
c:\windows\system32\firewallapi.dll

PID
3392
CMD
C:\Windows\system32\msiexec.exe /i C:\Users\admin\AppData\Local\Temp\MobiMover\InstallProc\Download\AppleMobileDeviceSupport.msi /q /norestart
Path
C:\Windows\system32\msiexec.exe
Indicators
No indicators
Parent process
downloader.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\msimsg.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\rpcrtremote.dll

PID
3844
CMD
C:\Windows\system32\MsiExec.exe -Embedding 9FCAA299B659DF89C4290024BB0FF143
Path
C:\Windows\system32\MsiExec.exe
Indicators
No indicators
Parent process
msiexec.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\installer\msi4fab.tmp
c:\windows\installer\msi5029.tmp
c:\windows\installer\msi5039.tmp
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\installer\msi5098.tmp
c:\windows\installer\msi50d7.tmp
c:\windows\installer\msi50d8.tmp
c:\windows\installer\msi5261.tmp
c:\windows\installer\msi5281.tmp
c:\windows\installer\msi63cd.tmp

PID
3468
CMD
C:\Windows\system32\MsiExec.exe -Embedding 0EB227DE151DB4C2D7C2712758BA75CC M Global\MSI0000
Path
C:\Windows\system32\MsiExec.exe
Indicators
Parent process
msiexec.exe
User
SYSTEM
Integrity Level
SYSTEM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\installer\msi5b7c.tmp
c:\windows\system32\wintrust.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\spinf.dll
c:\windows\system32\drvstore.dll
c:\windows\system32\p2pcollab.dll
c:\windows\system32\qagentrt.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\fveui.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\cabinet.dll
c:\windows\installer\msi5f27.tmp
c:\windows\installer\msi6225.tmp

PID
2508
CMD
DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{372953f3-de61-2d36-5d19-90740e1b0f58}\usbaapl.inf" "0" "64270aeef" "000004B0" "WinSta0\Default" "000005B4" "208" "C:\Program Files\Common Files\Apple\Mobile Device Support\Drivers"
Path
C:\Windows\system32\DrvInst.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Driver Installation Module
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\drvstore.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\spinf.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll

PID
3248
CMD
DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{75b16eae-3a25-6854-5159-11066dacd07d}\netaapl.inf" "0" "61971c80f" "000005B4" "WinSta0\Default" "00000060" "208" "C:\Program Files\Common Files\Apple\Mobile Device Support\NetDrivers"
Path
C:\Windows\system32\DrvInst.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Driver Installation Module
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\drvstore.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\spinf.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll

PID
3440
CMD
"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
Path
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
Indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Apple Inc.
Description
MobileDeviceService
Version
423.206.4.3
Modules
Image
c:\program files\common files\apple\mobile device support\applemobiledeviceservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcp100.dll
c:\windows\system32\msvcr100.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\common files\apple\apple application support\appleversions.dll
c:\windows\system32\version.dll
c:\program files\common files\apple\apple application support\yscrashdump.dll
c:\program files\common files\apple\apple application support\corefoundation.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\program files\common files\apple\apple application support\objc.dll
c:\program files\common files\apple\apple application support\asl.dll
c:\program files\common files\apple\apple application support\libdispatch.dll
c:\windows\system32\winmm.dll
c:\program files\common files\apple\apple application support\libicuin.dll
c:\program files\common files\apple\apple application support\libicuuc.dll
c:\program files\common files\apple\apple application support\icudt55.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
c:\windows\system32\profapi.dll
c:\program files\common files\apple\mobile device support\applemobiledeviceservice_main.dll
c:\program files\common files\apple\apple application support\pthreadvc2.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\program files\common files\apple\mobile device support\mobiledevice.dll
c:\program files\common files\apple\apple application support\cfnetwork.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\cryptui.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\program files\common files\apple\apple application support\libxml2.dll
c:\windows\system32\msvcr120.dll
c:\program files\common files\apple\apple application support\sqlite3.dll
c:\program files\common files\apple\apple application support\zlib1.dll
c:\program files\common files\apple\mobile device support\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\wintrust.dll

PID
3304
CMD
"C:\Program Files\EaseUS\EaseUS MobiMover\bin\uexperice.exe" -t 4097 4.5
Path
C:\Program Files\EaseUS\EaseUS MobiMover\bin\uexperice.exe
Indicators
No indicators
Parent process
mover_free_easeus.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\program files\easeus\easeus mobimover\bin\uexperice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcp90.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\easeus\easeus mobimover\bin\uexper.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll

PID
692
CMD
"C:\Program Files\EaseUS\EaseUS MobiMover\bin\uexperice.exe" -t 4098 1
Path
C:\Program Files\EaseUS\EaseUS MobiMover\bin\uexperice.exe
Indicators
No indicators
Parent process
mover_free_easeus.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\program files\easeus\easeus mobimover\bin\uexperice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcp90.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\easeus\easeus mobimover\bin\uexper.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll

PID
3812
CMD
"C:\Program Files\EaseUS\EaseUS MobiMover\bin\uexperice.exe" -t 4099 English
Path
C:\Program Files\EaseUS\EaseUS MobiMover\bin\uexperice.exe
Indicators
No indicators
Parent process
mover_free_easeus.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\program files\easeus\easeus mobimover\bin\uexperice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcp90.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\easeus\easeus mobimover\bin\uexper.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll

PID
3328
CMD
"C:\Program Files\EaseUS\EaseUS MobiMover\bin\uexperice.exe" -t 4100 1033
Path
C:\Program Files\EaseUS\EaseUS MobiMover\bin\uexperice.exe
Indicators
No indicators
Parent process
mover_free_easeus.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\program files\easeus\easeus mobimover\bin\uexperice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcp90.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\easeus\easeus mobimover\bin\uexper.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll

PID
3772
CMD
"C:\Program Files\EaseUS\EaseUS MobiMover\bin\uexperice.exe" -t 5508 20190107_installer_InstallerTest
Path
C:\Program Files\EaseUS\EaseUS MobiMover\bin\uexperice.exe
Indicators
No indicators
Parent process
mover_free_easeus.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\program files\easeus\easeus mobimover\bin\uexperice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcp90.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\easeus\easeus mobimover\bin\uexper.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll

PID
3760
CMD
"C:\Program Files\EaseUS\EaseUS MobiMover\bin\uexperice.exe" -i 0
Path
C:\Program Files\EaseUS\EaseUS MobiMover\bin\uexperice.exe
Indicators
Parent process
mover_free_easeus.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\program files\easeus\easeus mobimover\bin\uexperice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcp90.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\easeus\easeus mobimover\bin\uexper.dll
c:\windows\system32\nsi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\fwpuclnt.dll

PID
2416
CMD
"C:\Windows\system32\cmd.exe" /C ""C:\Program Files\EaseUS\EaseUS MobiMover\bin\windows_xp_ffmpeg_fix.cmd""
Path
C:\Windows\system32\cmd.exe
Indicators
No indicators
Parent process
mover_free_easeus.tmp
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\apphelp.dll
c:\program files\easeus\easeus mobimover\bin\fixffmpeg.exe

PID
3572
CMD
C:\Windows\system32\cmd.exe /c dir /b ff*.exe av*.dll sw*.dll po*.dll
Path
C:\Windows\system32\cmd.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Command Processor
Version
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Image
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
4076
CMD
FixFFmpeg ffmpeg.exe
Path
C:\Program Files\EaseUS\EaseUS MobiMover\bin\FixFFmpeg.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\program files\easeus\easeus mobimover\bin\fixffmpeg.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\winspool.drv
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
4092
CMD
FixFFmpeg ffprobe.exe
Path
C:\Program Files\EaseUS\EaseUS MobiMover\bin\FixFFmpeg.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\program files\easeus\easeus mobimover\bin\fixffmpeg.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\winspool.drv
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
936
CMD
FixFFmpeg avcodec-57.dll
Path
C:\Program Files\EaseUS\EaseUS MobiMover\bin\FixFFmpeg.exe
Indicators
Parent process
cmd.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\program files\easeus\easeus mobimover\bin\fixffmpeg.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\winspool.drv
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
1476
CMD
FixFFmpeg avdevice-57.dll
Path
C:\Program Files\EaseUS\EaseUS MobiMover\bin\FixFFmpeg.exe
Indicators
Parent process
cmd.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\program files\easeus\easeus mobimover\bin\fixffmpeg.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\winspool.drv
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
2392
CMD
FixFFmpeg avfilter-6.dll
Path
C:\Program Files\EaseUS\EaseUS MobiMover\bin\FixFFmpeg.exe
Indicators
Parent process
cmd.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\program files\easeus\easeus mobimover\bin\fixffmpeg.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\winspool.drv
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
1888
CMD
FixFFmpeg avformat-57.dll
Path
C:\Program Files\EaseUS\EaseUS MobiMover\bin\FixFFmpeg.exe
Indicators
Parent process
cmd.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\program files\easeus\easeus mobimover\bin\fixffmpeg.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\winspool.drv
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
2704
CMD
FixFFmpeg avutil-55.dll
Path
C:\Program Files\EaseUS\EaseUS MobiMover\bin\FixFFmpeg.exe
Indicators
Parent process
cmd.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\program files\easeus\easeus mobimover\bin\fixffmpeg.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\winspool.drv
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
3832
CMD
FixFFmpeg swresample-2.dll
Path
C:\Program Files\EaseUS\EaseUS MobiMover\bin\FixFFmpeg.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\program files\easeus\easeus mobimover\bin\fixffmpeg.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\winspool.drv
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
1644
CMD
FixFFmpeg swscale-4.dll
Path
C:\Program Files\EaseUS\EaseUS MobiMover\bin\FixFFmpeg.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\program files\easeus\easeus mobimover\bin\fixffmpeg.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\winspool.drv
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
2804
CMD
FixFFmpeg postproc-54.dll
Path
C:\Program Files\EaseUS\EaseUS MobiMover\bin\FixFFmpeg.exe
Indicators
No indicators
Parent process
cmd.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\program files\easeus\easeus mobimover\bin\fixffmpeg.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\winspool.drv
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll

PID
3608
CMD
INSTALL_TYPE=2 ||| REFERNUMBER=1000000 ||| RECOMMEND_URL=test
Path
C:\Users\admin\AppData\Local\Temp\downloader_easeus\1.0.0\1free\EDownloader.exe
Indicators
No indicators
Parent process
EDownloader.exe
User
admin
Integrity Level
HIGH
Exit code
2
Version:
Company
Description
Version
Modules
Image
c:\users\admin\appdata\local\temp\downloader_easeus\1.0.0\1free\edownloader.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\imm32.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasadhlp.dll

PID
3368
CMD
"C:\Program Files\EaseUS\EaseUS MobiMover\bin\MobiMoverUI.exe"
Path
C:\Program Files\EaseUS\EaseUS MobiMover\bin\MobiMoverUI.exe
Indicators
Parent process
EDownloader.exe
User
admin
Integrity Level
HIGH
Version:
Company
Description
EaseUS MobiMover
Version
4, 5, 0, 0
Modules
Image
c:\program files\easeus\easeus mobimover\bin\mobimoverui.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\easeus\easeus mobimover\bin\qt5core.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\mpr.dll
c:\program files\easeus\easeus mobimover\bin\msvcp120.dll
c:\program files\easeus\easeus mobimover\bin\msvcr120.dll
c:\program files\easeus\easeus mobimover\bin\qt5gui.dll
c:\program files\easeus\easeus mobimover\bin\qt5widgets.dll
c:\program files\easeus\easeus mobimover\bin\devicemanager.dll
c:\program files\easeus\easeus mobimover\bin\eulog.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcp90.dll
c:\windows\system32\version.dll
c:\program files\easeus\easeus mobimover\bin\videodecode.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\profapi.dll
c:\program files\easeus\easeus mobimover\bin\platforms\qwindows.dll
c:\windows\system32\winmm.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\uxtheme.dll
c:\program files\easeus\easeus mobimover\bin\uexper.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\program files\easeus\easeus mobimover\bin\buynow.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.6161_none_4bf7e3e2bf9ada4c\mfc90u.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\msimg32.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\dwmapi.dll
c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.6161_none_49768ef57548175e\mfc90enu.dll
c:\program files\easeus\easeus mobimover\bin\imageformats\qico.dll
c:\program files\easeus\easeus mobimover\bin\imageformats\qgif.dll
c:\program files\easeus\easeus mobimover\bin\imageformats\qjpeg.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\program files\common files\apple\apple application support\corefoundation.dll
c:\windows\system32\msvcr100.dll
c:\program files\common files\apple\apple application support\objc.dll
c:\windows\system32\msvcp100.dll
c:\program files\common files\apple\apple application support\asl.dll
c:\program files\common files\apple\apple application support\libdispatch.dll
c:\program files\common files\apple\apple application support\libicuin.dll
c:\program files\common files\apple\apple application support\libicuuc.dll
c:\program files\common files\apple\apple application support\icudt55.dll
c:\program files\easeus\easeus mobimover\bin\itunesmobiledevice.dll
c:\program files\common files\apple\apple application support\pthreadvc2.dll
c:\program files\common files\apple\apple application support\zlib1.dll
c:\program files\common files\apple\apple application support\cfnetwork.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\cryptui.dll
c:\windows\system32\wininet.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\program files\common files\apple\apple application support\libxml2.dll
c:\windows\system32\wsock32.dll
c:\program files\common files\apple\apple application support\sqlite3.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\program files\common files\apple\apple application support\api-ms-win-core-synch-l1-2-0.dll
c:\program files\common files\apple\mobile device support\airtraffichost.dll
c:\windows\system32\sspicli.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\portabledeviceapi.dll
c:\program files\easeus\easeus mobimover\bin\euactiveonline.dll
c:\program files\easeus\easeus mobimover\bin\eudownload.dll
c:\windows\system32\wship6.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasadhlp.dll
c:\program files\easeus\easeus mobimover\bin\euuserrate.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\fwpuclnt.dll

Registry activity

Total events
4435
Read events
1641
Write events
2776
Delete events
18

Modification events

PID
Process
Operation
Key
Name
Value
2972
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
CompatibilityFlags
0
2972
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2972
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2972
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
SecuritySafe
1
2972
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2972
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2972
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
{444523ED-14E6-11E9-91D7-5254004A04AF}
0
2972
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Type
4
2972
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Count
3
2972
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Time
E307010004000A000E002C002C000203
2972
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Type
4
2972
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Count
3
2972
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Time
E307010004000A000E002C002C000203
2972
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
FullScreen
no
2972
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Window_Placement
2C0000000200000003000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF20000000200000004003000078020000
2972
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\Links
Order
08000000020000000C01000001000000020000007E0000000000000070003200EC000000464B245120005355474745537E312E55524C0000540008000400EFBE454B974D464B24512A000000F94300000000020000000000000000000000000000005300750067006700650073007400650064002000530069007400650073002E00750072006C0000001C00000000000000820000000100000074003200E2000000464B24512000574542534C497E312E55524C0000580008000400EFBE454B864A464B24512A000000743E0000000003000000000000000000000000000000570065006200200053006C006900630065002000470061006C006C006500720079002E00750072006C0000001C00000000000000
2972
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Type
3
2972
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Count
3
2972
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Time
E307010004000A000E002C002C009F03
2972
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
LoadTime
10
2972
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Type
3
2972
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Count
3
2972
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Time
E307010004000A000E002C002C00CD03
2972
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
LoadTime
48
2972
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Type
3
2972
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Count
3
2972
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Time
E307010004000A000E002C002D00EF00
2972
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
LoadTime
19
2972
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
NotifyDownloadComplete
yes
3016
iexplore.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018082720180903
3016
iexplore.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018090920180910
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
CompatibilityFlags
0
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
SecuritySafe
1
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
460000006A000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
{5EB5D803-14E6-11E9-91D7-5254004A04AF}
0
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Type
4
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Count
4
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Time
E307010004000A000E002D001C003103
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Type
4
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Count
4
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}\iexplore
Time
E307010004000A000E002D001C003103
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
FullScreen
no
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Window_Placement
2C0000000200000003000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF20000000200000004003000078020000
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\Links
Order
08000000020000000C01000001000000020000007E0000000000000070003200EC000000464B245120005355474745537E312E55524C0000540008000400EFBE454B974D464B24512A000000F94300000000020000000000000000000000000000005300750067006700650073007400650064002000530069007400650073002E00750072006C0000001C00000000000000820000000100000074003200E2000000464B24512000574542534C497E312E55524C0000580008000400EFBE454B864A464B24512A000000743E0000000003000000000000000000000000000000570065006200200053006C006900630065002000470061006C006C006500720079002E00750072006C0000001C00000000000000
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Type
3
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Count
4
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
Time
E307010004000A000E002D001C00BE03
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\iexplore
LoadTime
9
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Type
3
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Count
4
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
Time
E307010004000A000E002D001C00DD03
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF}\iexplore
LoadTime
42
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Type
3
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Count
4
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
Time
E307010004000A000E002D001D001400
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DBC80044-A445-435B-BC74-9C25C1C588A9}\iexplore
LoadTime
16
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
Path
C:\Users\admin\Favorites\Links\Suggested Sites.url
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
Handler
{B0FA7D7C-7195-4F03-B03E-9DC1C9EBC394}
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
FeedUrl
https://ieonline.microsoft.com/#ieslice
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
DisplayName
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
ErrorState
0
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\0
DisplayMask
0
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
Path
C:\Users\admin\Favorites\Links\Web Slice Gallery.url
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
Handler
{B0FA7D7C-7195-4F03-B03E-9DC1C9EBC394}
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
FeedUrl
http://go.microsoft.com/fwlink/?LinkId=121315
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
DisplayName
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
ErrorState
0
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LinksBar\ItemCache\1
DisplayMask
0
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}\Enum
Implementing
1C00000001000000E307010004000A000E002D002F008B0200000000
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
NotifyDownloadComplete
yes
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019011020190111
CachePath
%USERPROFILE%\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019011020190111
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019011020190111
CachePrefix
:2019011020190111:
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019011020190111
CacheLimit
8192
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019011020190111
CacheOptions
11
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012019011020190111
CacheRepair
0
3016
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\WindowsSearch
UpgradeTime
CCF64F33F3A8D401
3632
iexplore.exe
delete key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012018082820180829
3632
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012019011020190111
CachePath
%USERPROFILE%\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012019011020190111
3632
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012019011020190111
CachePrefix
:2019011020190111:
3632
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012019011020190111
CacheLimit
8192
3632
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012019011020190111
CacheOptions
11
3632
iexplore.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Extensible Cache\MSHist012019011020190111
CacheRepair
0
2648
EDownloader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2648
EDownloader.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3044
mover_free_easeus.tmp
delete key
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
3044
mover_free_easeus.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Owner
E40B0000F0F38D33F3A8D401
3044
mover_free_easeus.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
SessionHash
3AA0880DACBFBA69BE1D35BCF894C5B7402D9F0742BCAAB3FA6040A859028ED8
3044
mover_free_easeus.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Sequence
1
3044
mover_free_easeus.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\EaseUS\MobiMover
intall_tmp
1
3044
mover_free_easeus.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
RegFiles0000
C:\Program Files\EaseUS\EaseUS MobiMover\bin\InstallPreProc.exe
3044
mover_free_easeus.tmp
write
HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
RegFilesHash
1193BA02E942E904CA02489E897CFE451209550D6D5F611B864A73753F166066
3044
mover_free_easeus.tmp
write
HKEY_CURRENT_USER\Software\EaseUS\MobiMover
Language
English
3044
mover_free_easeus.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\EaseUS\MobiMover
idv
1
3044
mover_free_easeus.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EaseUS MobiMover_is1
Inno Setup: Setup Version
5.5.8 (u)
3044
mover_free_easeus.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EaseUS MobiMover_is1
Inno Setup: App Path
C:\Program Files\EaseUS\EaseUS MobiMover
3044
mover_free_easeus.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EaseUS MobiMover_is1
InstallLocation
C:\Program Files\EaseUS\EaseUS MobiMover\
3044
mover_free_easeus.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EaseUS MobiMover_is1
Inno Setup: Icon Group
EaseUS MobiMover
3044
mover_free_easeus.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EaseUS MobiMover_is1
Inno Setup: User
admin
3044
mover_free_easeus.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EaseUS MobiMover_is1
Inno Setup: Selected Tasks
desktopicon
3044
mover_free_easeus.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EaseUS MobiMover_is1
Inno Setup: Deselected Tasks
3044
mover_free_easeus.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EaseUS MobiMover_is1
Inno Setup: Language
English
3044
mover_free_easeus.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EaseUS MobiMover_is1
DisplayName
EaseUS MobiMover 4.5
3044
mover_free_easeus.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EaseUS MobiMover_is1
DisplayIcon
C:\Program Files\EaseUS\EaseUS MobiMover\bin\MobiMoverUI.exe,0
3044
mover_free_easeus.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EaseUS MobiMover_is1
UninstallString
"C:\Program Files\EaseUS\EaseUS MobiMover\unins000.exe"
3044
mover_free_easeus.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EaseUS MobiMover_is1
QuietUninstallString
"C:\Program Files\EaseUS\EaseUS MobiMover\unins000.exe" /SILENT
3044
mover_free_easeus.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EaseUS MobiMover_is1
Publisher
EaseUS
3044
mover_free_easeus.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EaseUS MobiMover_is1
URLInfoAbout
https://www.easeus.com/support.htm
3044
mover_free_easeus.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EaseUS MobiMover_is1
HelpLink
https://www.easeus.com/support/mobimover/
3044
mover_free_easeus.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EaseUS MobiMover_is1
URLUpdateInfo
https://www.easeus.com/phone-transfer/mobimover-free.html
3044
mover_free_easeus.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EaseUS MobiMover_is1
NoModify
1
3044
mover_free_easeus.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EaseUS MobiMover_is1
NoRepair
1
3044
mover_free_easeus.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EaseUS MobiMover_is1
InstallDate
20190110
3044
mover_free_easeus.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EaseUS MobiMover_is1
EstimatedSize
158083
3044
mover_free_easeus.tmp
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
GlobalAssocChangedCounter
52
2892
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SideBySide\PatchedComponents
2892
msiexec.exe
delete key
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\5F\52C64B7E
2892
msiexec.exe
delete key
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\5F
2892
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
2892
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback
2892
msiexec.exe
delete key
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0001
2892
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress
2892
msiexec.exe
delete key
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\60\52C64B7E
2892
msiexec.exe
delete key
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\60
2892
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000_CLASSES\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
2892
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0001
Owner
4C0B000012D6C141F3A8D401
2892
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0001
SessionHash
577263C3764ADB17FBA23ED620C83BAB2BDF42D02F8DC73A955FD90DE61BA77E
2892
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0001
Sequence
1
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress
C:\Windows\Installer\25eda9.ipi
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\25edaa.rbs
30714099
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\25edaa.rbsLow
1180873696
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E233A253C5982E249BF6BFF186DC21D3
C8F2F80333D922B4A8C69D1CD3EB8F6C
02:\SOFTWARE\Apple Inc.\Apple Application Support\InstallDir
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\187492CC0E4679D4FBEBA5F0D9BF777C
C8F2F80333D922B4A8C69D1CD3EB8F6C
02:\SOFTWARE\Apple Inc.\Apple Application Support\UserVisibleVersion
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BD97BB3E371B820408CB4818302FBEEE
C8F2F80333D922B4A8C69D1CD3EB8F6C
00:\AppID\{85187E17-383D-4EC5-B8D6-D9466EE3DD92}\
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\060883B9A1F60BB4281B6AA7D8F1A720
C8F2F80333D922B4A8C69D1CD3EB8F6C
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\860A2E5B61059B346AA4FE60B8E45B95
C8F2F80333D922B4A8C69D1CD3EB8F6C
00:\Interface\{F5EFF418-0D49-49AB-A5C3-9E39AFD2B4A0}\
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9542250E22F8897489620BFE980410EE
C8F2F80333D922B4A8C69D1CD3EB8F6C
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\64E3CA3BF3523764EB72E57F49A25312
C8F2F80333D922B4A8C69D1CD3EB8F6C
00:\CLSID\{CE6AF8E5-3A75-4AF5-BD59-C42E7228B4F4}\
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F337907AC67089C4485DD6E3D890BEDD
C8F2F80333D922B4A8C69D1CD3EB8F6C
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2F3935DDDDC1C6B46813F4329DEABB32
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AC10A1CA37040E11EA5C421EFD7D0258
C8F2F80333D922B4A8C69D1CD3EB8F6C
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6A74668C37712AC41AC61834A0DD8088
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\ProgramData\Apple\Apple Application Support\kdrl\
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D88F4CD08D8AE88438BC3A3D893303B0
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\ProgramData\Apple\Installer Cache\AppleApplicationSupport 7.0.2\
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD7D8D86BA67E8356BC2A8DC5BF593C1
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-core-console-l1-1-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AD290A86CC1CE5A50B4CDB1985B8E742
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-core-datetime-l1-1-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\81F409F84DCAF6A58ACC2D18F262B40F
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-core-debug-l1-1-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B2768633A46F6AF5F966F8BC38E34E1B
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-core-errorhandling-l1-1-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4DEF1A75AED5AAF538A4CB43C0FCF1FE
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-core-file-l1-1-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\572D1F3B790902358A52011987CAB05E
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-core-file-l1-2-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F48EE607661266A56B678A0E4765B40E
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-core-file-l2-1-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C6815A590DD72505FBF5C4A53D3C628F
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-core-handle-l1-1-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D643BC87ABCADA6578E01521F9C371EA
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-core-heap-l1-1-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EB31E7C9DBE5BAA5E8E8AC2F3E06BDC6
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-core-interlocked-l1-1-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3256ABDED7B9A0153BE3F65277935DDA
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-core-libraryloader-l1-1-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A861F20ED4410552B9300FB5B05C967
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-core-localization-l1-2-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B751F0BF8AA8D4259AD37CBD812A9C9C
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-core-memory-l1-1-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\61D7E657A6846F059A8C9CE37B9BFC19
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-core-namedpipe-l1-1-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3FC4055EE0725E75C8BF72DA96F77D8A
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-core-processenvironment-l1-1-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BC66C31429F1D125693BF1624C055310
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-core-processthreads-l1-1-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EC427C6298D40A8548D28A1519462758
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-core-processthreads-l1-1-1.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\098963282C34C0A59B1BD9C922A628D3
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-core-profile-l1-1-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\74B0D760DFD4F3B5A95285F14C9E0871
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-core-rtlsupport-l1-1-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0940F0AEC6F4E55548E8B4402A30F928
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-core-string-l1-1-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0D3BA365FAA86805FB52AD614134CB6E
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-core-synch-l1-1-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\684D43E4F42BD395DBB1BB4FE336B735
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-core-synch-l1-2-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F1538E5393EDB7056B795B9665CEA146
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-core-sysinfo-l1-1-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ECFC65C7DABB54A58921D31391BDA4BB
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-core-timezone-l1-1-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7FD2F2C980914A45995ACD1573D46797
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-core-util-l1-1-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D3129CC55C98A7454AD15C7E40E7C897
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-crt-conio-l1-1-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BB854569342BFBA5580CF70E1AFB816F
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-crt-convert-l1-1-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\30C860FE9B472D050AD6D352DC9EA1A2
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-crt-environment-l1-1-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\37BB1CBDBA5CDA25A97555B41EC508E2
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-crt-filesystem-l1-1-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\477BA620B2CB3585D95B93FED77AB139
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-crt-heap-l1-1-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B4725AEACE86997579EC32FEA738009A
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-crt-locale-l1-1-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1D772E83B7A81A259B3B0FA00DB19AA9
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-crt-math-l1-1-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8A7794D9218718F51835E269FD00E2D8
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-crt-multibyte-l1-1-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\88EE9AA3AB33D30528BE456521D19E0E
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-crt-private-l1-1-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5B2D6E2EA1722C8588E71BE9BDD12E5B
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-crt-process-l1-1-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A14AC073755A1665BA423E47220AE205
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-crt-runtime-l1-1-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\138A913C06C3DB451A75DD00CFDE863A
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-crt-stdio-l1-1-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1539804B2BA40C752B37F6DCC8AC353F
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-crt-string-l1-1-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B62C7B6FD5EBE2351A474F21280A4025
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-crt-time-l1-1-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EAA6AAC28485E6E5F9232C462587D35A
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\api-ms-win-crt-utility-l1-1-0.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F615E2FBCAB327849B496652CB20E94D
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\ApplePushService.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6EAEE8A0BCFDED11D9EFDFB9658D5939
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AppleVersions.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F5566E1AEB04480428BEB5BECAFFD004
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F28390312066865458B41FD8A948BF10
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon_main.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\721237A2FF9593642A463D2F29C8E09D
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\ASL.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CAF15B86426BFD1159835BD2FD7D0258
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AVFoundationCF.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\69413F169B198734FA40BC8B73511DB0
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\CFNetwork.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4424E59BF2082E11EBE69334268807B9
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\CoreADI.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\32CB09AEE028F1448A991ABCBA7D14A3
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\CoreAudioToolbox.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0442009C5FC112947959B7D6F610F7CA
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\CoreFoundation.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08A47672A59119E4A84570973D211F4E
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\CoreGraphics.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A1AA4A84E8DBACF569D2CF0FC149436E
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\CoreLSKD.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FEA1C4DF5301F0245B51F4BEE29F33A3
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\CoreMedia.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\25D696ADF35C1E11C9964420268807B9
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\CoreText.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97E20904756EEF54396E52528A1A52D2
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\CoreVideo.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2FA601FC3EDD3D64EA868B1CF166AE0D
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\defaults.exe
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F1C8A60BD8BBA3042B021321D3DF044C
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\41019FDFF5361864CBD59AE9977DEC9B
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\Foundation.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EB8404248F5D2F05DA8DD59833B19921
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\icudt55.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F63E2ACFAE0214F42BB99DB8239E2E2E
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\icuin40.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\27658AF509F6E7B47B822F5ABFF100F3
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\icuuc40.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1508B1D599F5544488D93C0B55C7D592
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\JavaScriptCore.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4CE506E3FDE00E11F9355F810E7D0258
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\libcache.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C43B695C15EFB2F4F816EC14C28490D2
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\libdispatch.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7D2B950A75B5CB5598CEC86B43BF15B6
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\libexslt.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A1A8A32486B75CC4C85CC710DD5E7A72
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\libicuin.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\87D2B1D3388C32141ADA021144952108
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\libicuuc.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7E988BA0BA1896748BDE85AC83EABDB2
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\libtidy.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\82E29318ED5203248871DE35DB52B3DE
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6A4CD52AFD64C604DB85C56749300678
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\libxslt.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\014ECFD3854D72F5696E0EE69F743F36
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\lskd.rl
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4A9B0D38F7E021F52A9AD113ECF6FD58
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\MediaAccessibility.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DAF6CE2EF0C2A1747B32AA15F2576672
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\objc.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0150C7ED3493FD117909CAED558D5939
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\plutil.exe
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\44B339859ED2215409EFA7F1F1709820
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\pthreadVC2.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\47F09A8168A110F48A77712A12CFA135
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\QuartzCore.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C70A331F87624BB52BA7926614B863CE
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\secd.exe
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A6FF756E713D09409D722481189E968
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\SQLite3.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A30A58A207FC4CE57ACC81CE75924C6B
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\ucrtbase.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AF663E42B0BA9AB55880809D74BB9B0A
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\VersionCheckMe.exe
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7B20D45AB4C6E38429E9B02D0AA288F5
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\WebKit.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FC64B8D063342645A9D041514434E16E
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\WTF.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C4694819C6F40E11890A8DADED7D0258
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\YSCrashDump.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4A6930335007D615CAA259843BDB1CF8
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\YSIconStamper.exe
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\01BFAE57B36499E5BB1735F372016DC2
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\YSLoader.exe
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F2112C565E6C26743974BFF0DDB75DEC
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\YSUtilities.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C08050A185399F74B936F60CA8865A9B
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3247B2159FE26CD54BAB5E481AF28920
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\ar.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ECF6D50425998DD5CB6540275BD2AE51
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\ca.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6DDE6C695700C235C90F5940E03B89DF
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\cs.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2127ACD76F355FF569E4FEAD7606E90C
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\da.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\691CB83878A1D105DAF5AA0ABECE567C
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\de.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\054C8815994F958519C6D78D30C325F5
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\el.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E7F4B9878A6A31851B78C905A0019D70
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\en.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B34ACC39584BD1C5DAE237901EF44FFC
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\en_AU.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\03D88CA24490A77558BA4BC4942B96F6
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\en_GB.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F0165A6DC0F34345A82580703D01FB69
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\es.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6CB37C5DED2F43953B0DD82953E775C1
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\es_419.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\075A20327427CF154BC87DFBAE56F733
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\fi.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\85C5D36B6D8037C538695A63F05EC042
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\fr.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E03DC7471E468DA58BB3BFC1036A84BB
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\fr_CA.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FA77A4E6AB444E5584CC6B218D72846
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\he.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B16A9DCEE4D25FB53A64549182A9044E
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\hi.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EC9358C785E7BA25B84641C846448AFE
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\hr.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\89EA9F28F7CCBF25095D4FAF1615D13C
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\hu.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8787A19F67C49A05A9091078256D74CE
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\id.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BEBD0F7DD675AAE5A9A281EAB6A29FB6
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\it.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C38E9B044C8AC50518EC07C9A458DB92
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\ja.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\14F93789E027F615D8F9748C8066DB89
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\ko.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F445D814E741EB75B8E5C5CEB0B2FA59
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\ms.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\44EDEA336985B3A5AB376802F8B7CB4C
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\nb.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\63A4B922F5ABEC3579B3C4377F013A7A
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\nl.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B9A55B138F053D1529823255C181BE7A
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\pl.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CCB2F3153401EFB5F95877F6B524BE80
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\pt.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E5350455AFED275529AA4AC2DCD0A33B
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\pt_PT.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\34E6761300FE0955DB47EB51FDE136CF
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\ro.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F11A142CDE5AD0D55AA5A2AAC83D4A2C
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\ru.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F9F22D870956B225786B1C6592FD00FD
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\sk.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7B5E8AA9C7BE8D25189C2932FDC70202
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\sv.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EA91BD6A42FAF62599EBA65583233C92
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\th.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CA37DDA9466E2F95C9E21D7DEC195102
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\tr.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B19F1AFBB70460850B95DDA5FD307692
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\uk.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7B5E61879CAA6575EAC0C19CD518C9AE
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\vi.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3976800605291A65EB27716FBA8D9C97
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\zh_CN.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A19A278E30D154E58AB40C450A33CE18
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\zh_HK.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D7BE0E9195A798C53977370AA8889374
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AuthKitWin.resources\zh_TW.lproj\AuthKitWinLocalized.dll
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6A5AFE7F000D0E112AA4FA0E744210B9
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AVFoundationCF.resources\AVCFAssetExportPresets.plist
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A82159C0311FEAC4881C26E1CD264847
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AVFoundationCF.resources\AVFoundationCFSupport.plist
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C16528093EB602942A25B858D9165E3C
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AVFoundationCF.resources\Info.plist
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\67583FA6D205F3E57B8A61B131DD9A7C
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AVFoundationCF.resources\ar.lproj\AVCFError.strings
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7E8D186840A722B588596ABFD9021013
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AVFoundationCF.resources\ar.lproj\AVCFMediaSelectionOption.strings
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A41C7E246E2E3575EA796C6D3A03410E
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AVFoundationCF.resources\ca.lproj\AVCFError.strings
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B01D2F75A263D8250A79CFEC249D71AD
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AVFoundationCF.resources\ca.lproj\AVCFMediaSelectionOption.strings
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\20C6E007CC4F58254A5B82F81A51CDCE
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AVFoundationCF.resources\cs.lproj\AVCFError.strings
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0CAB11458B0C7B450B980AA41B0774F9
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AVFoundationCF.resources\cs.lproj\AVCFMediaSelectionOption.strings
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\294EED269A56C5156A42D6127880D3D4
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AVFoundationCF.resources\da.lproj\AVCFError.strings
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2C339E21FD7D14153BDC6A99B1B8896B
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AVFoundationCF.resources\da.lproj\AVCFMediaSelectionOption.strings
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DDF60E0242C9F2853B5D07E544D5E0FA
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AVFoundationCF.resources\Dutch.lproj\AVCFError.strings
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9C65BCF31FECD5F55B6DD772B7E8EBD5
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AVFoundationCF.resources\Dutch.lproj\AVCFMediaSelectionOption.strings
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CAF69D0592B643654BCA45E8E76263FA
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AVFoundationCF.resources\el.lproj\AVCFError.strings
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\36101544F680AEF5CA253FBFD34ED9E5
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AVFoundationCF.resources\el.lproj\AVCFMediaSelectionOption.strings
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1738558F4AA65AB548B3A17670F3AEDF
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AVFoundationCF.resources\English.lproj\AVCFError.strings
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\84ECD2C9329DFA25D9A46DB547FF3DF8
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AVFoundationCF.resources\English.lproj\AVCFMediaSelectionOption.strings
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A2619CCD693DE45E8B6C912430B571A
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AVFoundationCF.resources\en_GB.lproj\AVCFError.strings
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E5316F77C21D9B456BB0DC274840ABF4
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AVFoundationCF.resources\en_GB.lproj\AVCFMediaSelectionOption.strings
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4FC2B0FA5BCB47152A3FCB274764398E
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AVFoundationCF.resources\es_419.lproj\AVCFError.strings
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EAC33F8FDF7C94C50966A4A94F99938B
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AVFoundationCF.resources\es_419.lproj\AVCFMediaSelectionOption.strings
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6B60E770D9C7C085CB5BB4EECABB9C4D
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AVFoundationCF.resources\fi.lproj\AVCFError.strings
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4CF3F18A351297D50B97AA5AC6F3441D
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AVFoundationCF.resources\fi.lproj\AVCFMediaSelectionOption.strings
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\31B907BB0C1FB8F549061622476CB8C7
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AVFoundationCF.resources\French.lproj\AVCFError.strings
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1180969AC1049EA5A892FADCB1572A5B
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AVFoundationCF.resources\French.lproj\AVCFMediaSelectionOption.strings
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\463AD4D1EAEB7F35FA186959DF2F8794
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Support\AVFoundationCF.resources\German.lproj\AVCFError.strings
2892
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F181287AA5728F450BCF50669656F44B
C8F2F80333D922B4A8C69D1CD3EB8F6C
C:\Program Files\Common Files\Apple\Apple Application Su