General Info

File name

CommunityClipsSetup_1813.msi

Full analysis
https://app.any.run/tasks/7e7038f2-1e01-4af6-a533-973bfddd5448
Verdict
Malicious activity
Analysis date
10/9/2019, 16:03:47
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-msi
File info:
Composite Document File V2 Document, Little Endian, Os: Windows, Version 5.2, MSI Installer, Create Time/Date: Mon Jun 21 08:00:00 1999, Name of Creating Application: Windows Installer, Security: 1, Code page: 1252, Template: Intel;1033, Number of Pages: 200, Revision Number: {A5766F94-C04B-48F4-9219-A2CA61F01DC0}, Title: Community Clips, Author: Microsoft, Number of Words: 2, Last Saved Time/Date: Thu Jun 19 22:53:38 2008, Last Printed: Thu Jun 19 22:53:38 2008
MD5

2349e63e0690385b7579f3cd16fd6915

SHA1

e6056ab3de0b86d96c03cf76546860e122e05b9e

SHA256

2bcdf7918e439556268aaf457a6895f5dbf274c888f272932e18809bb4c48341

SSDEEP

196608:SVaOOtokclkc00tE+xeO3yRxDmGmgVyoLzaMUgGcQUrjHj5nasvU3hW0cd4Gn:SVzk6vVtE+o6sw24fkj5ruav

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
120 seconds
Additional time used
60 seconds
Fakenet option
off
Heavy Evaision option
on
MITM proxy
off
Route via Tor
on
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (75.0.3770.100)
  • Google Update Helper (1.3.34.7)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.7.2 (4.7.03062)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (14.21.27702.2)
  • Microsoft Visual C++ 2019 X86 Additional Runtime - 14.21.27702 (14.21.27702)
  • Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.21.27702 (14.21.27702)
  • Mozilla Firefox 68.0.1 (x86 en-US) (68.0.1)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • Update for Microsoft .NET Framework 4.7.2 (KB4087364) (1)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB4019990
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Application was dropped or rewritten from another process
  • wmenc.exe (PID: 2820)
  • WMEncAgt.exe (PID: 2064)
  • wmasfdist.exe (PID: 4088)
  • settmp.exe (PID: 2932)
  • settmp.exe (PID: 3580)
  • wmstypelib.exe (PID: 2168)
  • WMFDist.exe (PID: 3140)
  • CommunityClips.exe (PID: 2500)
  • WMEncoder.exe (PID: 2868)
  • WMEncoder.exe (PID: 2900)
Loads dropped or rewritten executable
  • MsiExec.exe (PID: 3296)
  • MsiExec.exe (PID: 3356)
  • MsiExec.exe (PID: 4000)
  • MsiExec.exe (PID: 3932)
  • MsiExec.exe (PID: 1300)
  • MsiExec.exe (PID: 3344)
  • MsiExec.exe (PID: 4056)
  • MsiExec.exe (PID: 2480)
  • MsiExec.exe (PID: 2244)
  • MsiExec.exe (PID: 568)
  • MsiExec.exe (PID: 3436)
  • wmstypelib.exe (PID: 2168)
  • rundll32.exe (PID: 3516)
  • rundll32.exe (PID: 3224)
  • wmasfdist.exe (PID: 4088)
  • WMEncoder.exe (PID: 2868)
  • CommunityClips.exe (PID: 2500)
Creates COM task schedule object
  • MsiExec.exe (PID: 3296)
  • MsiExec.exe (PID: 3356)
  • MsiExec.exe (PID: 3932)
  • MsiExec.exe (PID: 1300)
  • MsiExec.exe (PID: 3344)
  • MsiExec.exe (PID: 568)
  • MsiExec.exe (PID: 2480)
  • MsiExec.exe (PID: 3436)
  • MsiExec.exe (PID: 2244)
  • MsiExec.exe (PID: 4056)
  • MsiExec.exe (PID: 3776)
  • msiexec.exe (PID: 3064)
Removes files from Windows directory
  • DrvInst.exe (PID: 2964)
  • wmstypelib.exe (PID: 2168)
  • wmasfdist.exe (PID: 4088)
  • DrvInst.exe (PID: 3308)
Uses RUNDLL32.EXE to load library
  • wmstypelib.exe (PID: 2168)
  • wmasfdist.exe (PID: 4088)
Executed via COM
  • DrvInst.exe (PID: 2964)
  • DrvInst.exe (PID: 3308)
  • DrvInst.exe (PID: 968)
  • DrvInst.exe (PID: 2100)
Creates files in the Windows directory
  • DrvInst.exe (PID: 2964)
  • wmstypelib.exe (PID: 2168)
  • wmasfdist.exe (PID: 4088)
  • DrvInst.exe (PID: 3308)
  • msiexec.exe (PID: 3064)
Executable content was dropped or overwritten
  • wmstypelib.exe (PID: 2168)
  • DrvInst.exe (PID: 2964)
  • rundll32.exe (PID: 3516)
  • DrvInst.exe (PID: 3308)
  • wmasfdist.exe (PID: 4088)
  • rundll32.exe (PID: 3224)
  • WMEncoder.exe (PID: 2868)
  • msiexec.exe (PID: 3064)
  • msiexec.exe (PID: 2612)
Creates files in the driver directory
  • DrvInst.exe (PID: 2964)
  • DrvInst.exe (PID: 3308)
Modifies the open verb of a shell class
  • msiexec.exe (PID: 3064)
Starts Microsoft Installer
  • WMEncoder.exe (PID: 2868)
Executed as Windows Service
  • vssvc.exe (PID: 3156)
Application was dropped or rewritten from another process
  • MSIC799.tmp (PID: 2180)
Starts application with an unusual extension
  • msiexec.exe (PID: 3064)
Changes settings of System certificates
  • DrvInst.exe (PID: 3308)
Dropped object may contain Bitcoin addresses
  • msiexec.exe (PID: 3064)
Loads dropped or rewritten executable
  • MsiExec.exe (PID: 3096)
  • msiexec.exe (PID: 3064)
  • MsiExec.exe (PID: 2212)
  • MsiExec.exe (PID: 2688)
  • MsiExec.exe (PID: 2508)
Creates files in the program directory
  • MsiExec.exe (PID: 2212)
  • msiexec.exe (PID: 3064)
Creates a software uninstall entry
  • msiexec.exe (PID: 3064)
Low-level read access rights to disk partition
  • vssvc.exe (PID: 3156)
Searches for installed software
  • msiexec.exe (PID: 3064)
Application launched itself
  • msiexec.exe (PID: 3064)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.msi
|   Microsoft Windows Installer (93.3%)
.pps/ppt
|   Microsoft PowerPoint document (5.2%)
.msi
|   Microsoft Installer (100%)
EXIF
FlashPix
CreateDate:
1999:06:21 07:00:00
Software:
Windows Installer
Security:
Password protected
CodePage:
Windows Latin 1 (Western European)
Template:
Intel;1033
Pages:
200
RevisionNumber:
{A5766F94-C04B-48F4-9219-A2CA61F01DC0}
Title:
Community Clips
Subject:
null
Author:
Microsoft
Keywords:
null
Comments:
null
Words:
2
ModifyDate:
2008:06:19 21:53:38
LastPrinted:
2008:06:19 21:53:38

Screenshots

Processes

Total processes
74
Monitored processes
37
Malicious processes
16
Suspicious processes
2

Behavior graph

+
start drop and start drop and start drop and start drop and start drop and start drop and start msiexec.exe msiexec.exe msiexec.exe no specs vssvc.exe no specs drvinst.exe no specs msiexec.exe no specs msiexec.exe no specs communityclips.exe no specs wmencoder.exe no specs wmencoder.exe msiexec.exe no specs drvinst.exe no specs msiexec.exe no specs settmp.exe no specs wmasfdist.exe rundll32.exe drvinst.exe wmfdist.exe no specs settmp.exe no specs wmstypelib.exe rundll32.exe drvinst.exe msic799.tmp no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs msiexec.exe no specs wmencagt.exe no specs wmenc.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
2612
CMD
"C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\CommunityClipsSetup_1813.msi"
Path
C:\Windows\System32\msiexec.exe
Indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\msimsg.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\propsys.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msisip.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\microsoft.net\framework\v4.0.30319\fusion.dll
c:\windows\system32\msihnd.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\riched20.dll
c:\windows\system32\msls31.dll
c:\windows\system32\msvcr120_clr0400.dll

PID
3064
CMD
C:\Windows\system32\msiexec.exe /V
Path
C:\Windows\system32\msiexec.exe
Indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\msimsg.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\srclient.dll
c:\windows\system32\spp.dll
c:\windows\system32\vssapi.dll
c:\windows\system32\atl.dll
c:\windows\system32\vsstrace.dll
c:\windows\system32\vss_ps.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\es.dll
c:\windows\system32\sxs.dll
c:\windows\system32\propsys.dll
c:\windows\system32\samlib.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msisip.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\winsta.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\microsoft.net\framework\v4.0.30319\fusion.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\msvcr120_clr0400.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\cabinet.dll
c:\windows\assembly\tmp\stujoxl6\microsoft.office.interop.excel.dll
c:\windows\assembly\tmp\9by86sy6\office.dll
c:\windows\assembly\tmp\efrgdzob\ccinterface.dll
c:\windows\assembly\tmp\kjec7llx\microsoft.office.interop.word.dll
c:\windows\assembly\tmp\amoyoqvb\microsoft.officelabs.common.dll
c:\windows\assembly\tmp\n1l16aiy\microsoft.office.interop.powerpoint.dll
c:\program files\microsoft\office labs\communityclips\communityclips.exe
c:\windows\system32\linkinfo.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\slc.dll
c:\program files\windows media components\encoder\wmenc.exe
c:\program files\windows media components\encoder\wmeditor.exe
c:\program files\windows media components\encoder\wmproedt.exe
c:\program files\windows media components\encoder\wmstreamedt.exe
c:\program files\windows media components\encoder\settmp.exe
c:\windows\installer\msic799.tmp
c:\program files\windows media components\encoder\wmencagt.exe

PID
2508
CMD
C:\Windows\system32\MsiExec.exe -Embedding CFC4DDD4B1AAFCF35785AD03205F32D9 C
Path
C:\Windows\system32\MsiExec.exe
Indicators
No indicators
Parent process
msiexec.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\users\admin\appdata\local\temp\msi7d78.tmp
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll
c:\users\admin\appdata\local\temp\msi7e06.tmp

PID
3156
CMD
C:\Windows\system32\vssvc.exe
Path
C:\Windows\system32\vssvc.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Microsoft® Volume Shadow Copy Service
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\vssvc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\atl.dll
c:\windows\system32\ole32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\vssapi.dll
c:\windows\system32\vsstrace.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\clusapi.dll
c:\windows\system32\cryptdll.dll
c:\windows\system32\xolehlp.dll
c:\windows\system32\version.dll
c:\windows\system32\resutils.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\authz.dll
c:\windows\system32\virtdisk.dll
c:\windows\system32\fltlib.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\vss_ps.dll
c:\windows\system32\samlib.dll
c:\windows\system32\es.dll
c:\windows\system32\propsys.dll
c:\windows\system32\catsrvut.dll
c:\windows\system32\mfcsubs.dll
c:\windows\system32\sxs.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll

PID
2100
CMD
DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot22" "" "" "695c3f483" "00000000" "00000394" "000003D0"
Path
C:\Windows\system32\DrvInst.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Driver Installation Module
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\spinf.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\spfileq.dll

PID
2688
CMD
C:\Windows\system32\MsiExec.exe -Embedding C946BB470EF50EA3D2B64D279A15565E
Path
C:\Windows\system32\MsiExec.exe
Indicators
No indicators
Parent process
msiexec.exe
User
admin
Integrity Level
MEDIUM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\installer\msi3c92.tmp
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll
c:\windows\installer\msi3d4e.tmp

PID
2212
CMD
C:\Windows\system32\MsiExec.exe -Embedding 81D974ADDBBAC722A7C0AF17EFA1B73C M Global\MSI0000
Path
C:\Windows\system32\MsiExec.exe
Indicators
No indicators
Parent process
msiexec.exe
User
SYSTEM
Integrity Level
SYSTEM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\installer\msi44d3.tmp
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system\9e0a3b9b9f457233a335d7fba8f95419\system.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.configuratio#\f02737c83305687a68c088927a6c5a98\system.configuration.install.ni.dll
c:\windows\system32\sxs.dll
c:\program files\microsoft\office labs\communityclips\microsoft.officelabs.common.dll
c:\windows\installer\msi47b3.tmp
c:\windows\assembly\nativeimages_v2.0.50727_32\system.configuration\bc09ad2d49d8535371845cd7532f9271\system.configuration.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.xml\461d3b6b3f43e6fbe6c897d5936e17e4\system.xml.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.runtime.seri#\0728af1479c3388cadf85ccfc2b12582\system.runtime.serialization.formatters.soap.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.drawing\dbfe8642a8ed7b2b103ad28e0c96418a\system.drawing.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.windows.forms\3afcd5168c7a6cb02eab99d7fd71e102\system.windows.forms.ni.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorjit.dll
c:\windows\assembly\gac_32\system.data\2.0.0.0__b77a5c561934e089\system.data.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.data\1e85062785e286cd9eae9c26d2c61f73\system.data.ni.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\shfolder.dll

PID
2500
CMD
"C:\Program Files\Microsoft\Office Labs\CommunityClips\CommunityClips.exe"
Path
C:\Program Files\Microsoft\Office Labs\CommunityClips\CommunityClips.exe
Indicators
No indicators
Parent process
msiexec.exe
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Office Labs
Description
CommunityClips
Version
1.0.1813.0
Modules
Image
c:\program files\microsoft\office labs\communityclips\communityclips.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\version.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\profapi.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\mscorlib\62a0b3e4b40ec0e8c5cfaa0c8848e64a\mscorlib.ni.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorjit.dll
c:\windows\assembly\tmp\amoyoqvb\microsoft.officelabs.common.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system\9e0a3b9b9f457233a335d7fba8f95419\system.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.drawing\dbfe8642a8ed7b2b103ad28e0c96418a\system.drawing.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.windows.forms\3afcd5168c7a6cb02eab99d7fd71e102\system.windows.forms.ni.dll
c:\windows\system32\uxtheme.dll
c:\windows\assembly\gac_msil\system.windows.forms\2.0.0.0__b77a5c561934e089\system.windows.forms.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.configuration\bc09ad2d49d8535371845cd7532f9271\system.configuration.ni.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.xml\461d3b6b3f43e6fbe6c897d5936e17e4\system.xml.ni.dll
c:\program files\microsoft\office labs\communityclips\microsoft.officelabs.update.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\microsoft.net\framework\v2.0.50727\culture.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\riched20.dll
c:\windows\assembly\tmp\efrgdzob\ccinterface.dll
c:\windows\system32\propsys.dll
c:\windows\system32\oleaut32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\wship6.dll
c:\windows\system32\winhttp.dll
c:\windows\system32\webio.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\sspicli.dll
c:\program files\microsoft\office labs\communityclips\wmencoder.exe
c:\windows\system32\mpr.dll
c:\windows\system32\shfolder.dll
c:\program files\microsoft\office labs\communityclips\sqmapi.dll
c:\program files\microsoft\office labs\communityclips\axinterop.wmplib.dll
c:\windows\system32\wmp.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\wmploc.dll
c:\windows\system32\sxs.dll
c:\program files\microsoft\office labs\communityclips\interop.wmplib.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\mfplat.dll
c:\windows\system32\avrt.dll
c:\windows\system32\audioses.dll
c:\windows\system32\jscript.dll
c:\windows\assembly\nativeimages_v2.0.50727_32\system.runtime.remo#\5cae93d923c8378370758489e5535820\system.runtime.remoting.ni.dll

PID
2900
CMD
"C:\Program Files\Microsoft\Office Labs\CommunityClips\WMEncoder.exe" /Q
Path
C:\Program Files\Microsoft\Office Labs\CommunityClips\WMEncoder.exe
Indicators
No indicators
Parent process
CommunityClips.exe
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
Microsoft Corporation
Description
Windows Media Component Setup Application
Version
9.00.00.2980
Modules
Image
c:\program files\microsoft\office labs\communityclips\wmencoder.exe
c:\systemroot\system32\ntdll.dll

PID
2868
CMD
"C:\Program Files\Microsoft\Office Labs\CommunityClips\WMEncoder.exe" /Q
Path
C:\Program Files\Microsoft\Office Labs\CommunityClips\WMEncoder.exe
Indicators
Parent process
CommunityClips.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Media Component Setup Application
Version
9.00.00.2980
Modules
Image
c:\program files\microsoft\office labs\communityclips\wmencoder.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\version.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\winspool.drv
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\qcap.dll
c:\windows\system32\quartz.dll
c:\windows\system32\cryptbase.dll
c:\users\admin\appdata\local\temp\ixp000.tmp\advpack.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\spinf.dll
c:\windows\system32\spfileq.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msiexec.exe

PID
1096
CMD
msiexec.exe /i "C:\Windows\Installer\WMEncoder.msi" /qb
Path
C:\Windows\system32\msiexec.exe
Indicators
No indicators
Parent process
WMEncoder.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\msctf.dll
c:\windows\system32\imm32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\msimsg.dll
c:\windows\system32\propsys.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\rpcrtremote.dll

PID
968
CMD
DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot23" "" "" "631c88d3b" "00000000" "00000564" "000005AC"
Path
C:\Windows\system32\DrvInst.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Driver Installation Module
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\spinf.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\p2pcollab.dll
c:\windows\system32\qagentrt.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\fveui.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\spfileq.dll

PID
3096
CMD
C:\Windows\system32\MsiExec.exe -Embedding A418F4150EF8DCA85CE9248116404E31
Path
C:\Windows\system32\MsiExec.exe
Indicators
No indicators
Parent process
msiexec.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\installer\msi9cba.tmp
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samlib.dll
c:\windows\installer\msi9e61.tmp
c:\windows\installer\msi9fab.tmp
c:\windows\installer\msib8a4.tmp
c:\program files\windows media components\encoder\wmfdist.exe
c:\windows\installer\msief75.tmp

PID
2932
CMD
"C:\Program Files\Windows Media Components\Encoder\settmp.exe" /wrap:wmasfdist.exe /Q:A /R:N
Path
C:\Program Files\Windows Media Components\Encoder\settmp.exe
Indicators
No indicators
Parent process
msiexec.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\program files\windows media components\encoder\settmp.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\windows media components\encoder\wmasfdist.exe

PID
4088
CMD
wmasfdist.exe /Q:A /R:N
Path
C:\Program Files\Windows Media Components\Encoder\wmasfdist.exe
Indicators
Parent process
settmp.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Media Component Setup Application
Version
9.00.00.2980
Modules
Image
c:\program files\windows media components\encoder\wmasfdist.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\version.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\winspool.drv
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\msdownld.tmp\ixp000.tmp\advpack.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\spinf.dll
c:\windows\system32\spfileq.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\rundll32.exe

PID
3224
CMD
rundll32 C:\Windows\msdownld.tmp\IXP000.TMP\msoobci.dll,DoInstall C:\Windows\msdownld.tmp\IXP000.TMP\asferr.inf
Path
C:\Windows\system32\rundll32.exe
Indicators
Parent process
wmasfdist.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows host process (Rundll32)
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\msdownld.tmp\ixp000.tmp\msoobci.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\devobj.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\spinf.dll
c:\windows\system32\syssetup.dll
c:\windows\system32\drvstore.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\wintrust.dll

PID
3308
CMD
DrvInst.exe "4" "0" "C:\IExp0.tmp\{47f41335-9d76-24b5-7920-5b4937b79757}\asferr.inf" "0" "6f63f8ba3" "000002A8" "WinSta0\Default" "00000564" "208" "C:\Windows\msdownld.tmp\IXP000.TMP"
Path
C:\Windows\system32\DrvInst.exe
Indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Driver Installation Module
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\user32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\drvstore.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\spinf.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll

PID
3140
CMD
/R:N /Q:A
Path
C:\Program Files\Windows Media Components\Encoder\WMFDist.exe
Indicators
No indicators
Parent process
MsiExec.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Media Component Setup Application
Version
9.00.00.2980
Modules
Image
c:\program files\windows media components\encoder\wmfdist.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\version.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\mpr.dll

PID
3580
CMD
"C:\Program Files\Windows Media Components\Encoder\settmp.exe" /wrap:wmstypelib.exe /Q:A /R:N
Path
C:\Program Files\Windows Media Components\Encoder\settmp.exe
Indicators
No indicators
Parent process
msiexec.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\program files\windows media components\encoder\settmp.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\program files\windows media components\encoder\wmstypelib.exe

PID
2168
CMD
wmstypelib.exe /Q:A /R:N
Path
C:\Program Files\Windows Media Components\Encoder\wmstypelib.exe
Indicators
Parent process
settmp.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Win32 Cabinet Self-Extractor
Version
6.00.2600.0000
Modules
Image
c:\program files\windows media components\encoder\wmstypelib.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\version.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\winspool.drv
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\msdownld.tmp\ixp000.tmp\advpack.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\spinf.dll
c:\windows\system32\rundll32.exe
c:\windows\system32\spfileq.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\cryptbase.dll

PID
3516
CMD
rundll32 C:\Windows\msdownld.tmp\IXP000.TMP\msoobci.dll,DoInstall C:\Windows\msdownld.tmp\IXP000.TMP\wmstypelib.inf
Path
C:\Windows\system32\rundll32.exe
Indicators
Parent process
wmstypelib.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows host process (Rundll32)
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\rundll32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\msdownld.tmp\ixp000.tmp\msoobci.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\devobj.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\spinf.dll
c:\windows\system32\syssetup.dll
c:\windows\system32\drvstore.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\wintrust.dll

PID
2964
CMD
DrvInst.exe "4" "0" "C:\IExp1.tmp\{28535efd-be2b-7898-b823-d27dbf431e14}\wmstypelib.inf" "0" "63e6bda8f" "00000564" "WinSta0\Default" "000005C4" "208" "C:\Windows\msdownld.tmp\IXP000.TMP"
Path
C:\Windows\system32\DrvInst.exe
Indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Driver Installation Module
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\drvstore.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\spinf.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll

PID
2180
CMD
"C:\Windows\Installer\MSIC799.tmp" /ShutDown
Path
C:\Windows\Installer\MSIC799.tmp
Indicators
No indicators
Parent process
msiexec.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Description
Version
Modules
Image
c:\windows\installer\msic799.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll

PID
3776
CMD
"C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\Windows Media Components\Encoder\StreamEditor.dll"
Path
C:\Windows\system32\MsiExec.exe
Indicators
No indicators
Parent process
msiexec.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\program files\windows media components\encoder\streameditor.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\devrtl.dll

PID
3436
CMD
"C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\Windows Media Components\Encoder\WMdevctl.dll"
Path
C:\Windows\system32\MsiExec.exe
Indicators
No indicators
Parent process
msiexec.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\program files\windows media components\encoder\wmdevctl.dll
c:\windows\system32\olepro32.dll
c:\windows\system32\avicap32.dll
c:\windows\system32\msvfw32.dll
c:\windows\system32\devrtl.dll

PID
4056
CMD
"C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\Windows Media Components\Encoder\wmedque.dll"
Path
C:\Windows\system32\MsiExec.exe
Indicators
No indicators
Parent process
msiexec.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\program files\windows media components\encoder\wmedque.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\quartz.dll
c:\windows\system32\devenum.dll

PID
2480
CMD
"C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\Windows Media Components\Encoder\WMEncEng.dll"
Path
C:\Windows\system32\MsiExec.exe
Indicators
No indicators
Parent process
msiexec.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\program files\windows media components\encoder\wmenceng.dll
c:\windows\system32\msdmo.dll
c:\windows\system32\avifil32.dll
c:\windows\system32\msvfw32.dll
c:\windows\system32\olepro32.dll
c:\windows\system32\devrtl.dll

PID
2244
CMD
"C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\Windows Media Components\Encoder\wmesrcwp.dll"
Path
C:\Windows\system32\MsiExec.exe
Indicators
No indicators
Parent process
msiexec.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\user32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\program files\windows media components\encoder\wmesrcwp.dll
c:\windows\system32\avicap32.dll
c:\windows\system32\msvfw32.dll
c:\windows\system32\olepro32.dll
c:\windows\system32\devrtl.dll
c:\program files\windows media components\encoder\wmenceng.dll
c:\windows\system32\msdmo.dll
c:\windows\system32\avifil32.dll
c:\program files\windows media components\encoder\wmexres.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\quartz.dll
c:\windows\system32\devenum.dll

PID
568
CMD
"C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\Windows Media Components\Encoder\WMexfmwp.dll"
Path
C:\Windows\system32\MsiExec.exe
Indicators
No indicators
Parent process
msiexec.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\program files\windows media components\encoder\wmexfmwp.dll
c:\windows\system32\msdmo.dll
c:\windows\system32\msvfw32.dll
c:\windows\system32\devrtl.dll
c:\program files\windows media components\encoder\wmenceng.dll
c:\windows\system32\avifil32.dll
c:\windows\system32\olepro32.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\quartz.dll

PID
1300
CMD
"C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\Windows Media Components\Encoder\wmprevu.dll"
Path
C:\Windows\system32\MsiExec.exe
Indicators
No indicators
Parent process
msiexec.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\program files\windows media components\encoder\wmprevu.dll
c:\windows\system32\msdmo.dll
c:\windows\system32\msvfw32.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\quartz.dll
c:\windows\system32\devenum.dll

PID
3344
CMD
"C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\Windows Media Components\Encoder\wmex.dll"
Path
C:\Windows\system32\MsiExec.exe
Indicators
No indicators
Parent process
msiexec.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\program files\windows media components\encoder\wmex.dll
c:\windows\system32\olepro32.dll
c:\windows\system32\msdmo.dll
c:\windows\system32\devrtl.dll
c:\program files\windows media components\encoder\wmexres.dll

PID
3932
CMD
"C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\Windows Media Components\Encoder\mspshell.dll"
Path
C:\Windows\system32\MsiExec.exe
Indicators
No indicators
Parent process
msiexec.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\program files\windows media components\encoder\mspshell.dll
c:\windows\system32\olepro32.dll
c:\windows\system32\devrtl.dll

PID
3296
CMD
"C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\Windows Media Components\Encoder\Fileinfo.dll"
Path
C:\Windows\system32\MsiExec.exe
Indicators
No indicators
Parent process
msiexec.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\program files\windows media components\encoder\fileinfo.dll
c:\windows\system32\devrtl.dll

PID
3356
CMD
"C:\Windows\system32\MsiExec.exe" /Y "C:\Program Files\Windows Media Components\Encoder\wmencloc.dll"
Path
C:\Windows\system32\MsiExec.exe
Indicators
No indicators
Parent process
msiexec.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\program files\windows media components\encoder\wmencloc.dll
c:\windows\system32\devrtl.dll

PID
4000
CMD
"C:\Windows\system32\MsiExec.exe" /Y "C:\Windows\system32\declrds.ax"
Path
C:\Windows\system32\MsiExec.exe
Indicators
No indicators
Parent process
msiexec.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\declrds.ax
c:\windows\system32\devrtl.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\quartz.dll
c:\windows\system32\devenum.dll

PID
2064
CMD
"C:\Program Files\Windows Media Components\Encoder\WMEncAgt.exe" /regserver
Path
C:\Program Files\Windows Media Components\Encoder\WMEncAgt.exe
Indicators
No indicators
Parent process
msiexec.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Media Encoder Agent
Version
9.00.00.2980
Modules
Image
c:\program files\windows media components\encoder\wmencagt.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll

PID
2820
CMD
"C:\Program Files\Windows Media Components\Encoder\wmenc.exe" /regserver
Path
C:\Program Files\Windows Media Components\Encoder\wmenc.exe
Indicators
No indicators
Parent process
msiexec.exe
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Windows Media Encoder
Version
9.00.00.2980 built by: lab03_dev(bld4act)
Modules
Image
c:\program files\windows media components\encoder\wmenc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\winmm.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\nsi.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\winspool.drv
c:\windows\system32\cryptbase.dll

Registry activity

Total events
3717
Read events
1152
Write events
2524
Delete events
41

Modification events

PID
Process
Operation
Key
Name
Value
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
SrCreateRp (Enter)
4000000000000000323A8F86AA7ED501F80B0000F40A0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppCreate (Enter)
40000000000000008C9C9186AA7ED501F80B0000F40A0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
LastIndex
24
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppGatherWriterMetadata (Enter)
4000000000000000645ED486AA7ED501F80B0000F40A0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
IDENTIFY (Enter)
4000000000000000BEC0D686AA7ED501F80B000008050000E8030000010000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
IDENTIFY (Leave)
4000000000000000841A9387AA7ED501F80B000008050000E8030000000000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppGatherWriterMetadata (Leave)
400000000000000014C34F8DAA7ED501F80B0000F40A0000D3070000010000000000000000000000000000000000000000000000000000000000000000000000
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppAddInterestingComponents (Enter)
400000000000000014C34F8DAA7ED501F80B0000F40A0000D4070000000000000000000000000000000000000000000000000000000000000000000000000000
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppAddInterestingComponents (Leave)
40000000000000003E38658DAA7ED501F80B0000F40A0000D4070000010000000000000000000000000000000000000000000000000000000000000000000000
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
PREPAREBACKUP (Enter)
400000000000000068AD7A8DAA7ED501F80B000030090000E9030000010000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
PREPAREBACKUP (Leave)
400000000000000046E7948DAA7ED501F80B000030090000E9030000000000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
GETSTATE (Enter)
400000000000000046E7948DAA7ED501F80B00004C070000F9030000010000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
GETSTATE (Leave)
4000000000000000AE709E8DAA7ED501F80B00004C070000F9030000000000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
DOSNAPSHOT (Enter)
40000000000000006235A38DAA7ED501F80B0000F40A00000A040000010000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
DOSNAPSHOT (Leave)
4000000000000000C8B4858EAA7ED501F80B0000740900000A040000000000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppCreate (Leave)
4000000000000000C8B4858EAA7ED501F80B0000F40A0000D0070000010000000000000000000000000000000000000000000000000000000000000000000000
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
SrCreateRp (Leave)
4000000000000000C8B4858EAA7ED501F80B0000F40A0000D5070000010000000000000000000000000000000000000000000000000000000000000000000000
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
FirstRun
0
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
LastIndex
24
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\Volatile
NestingLevel
1
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\Volatile
StartNesting
323A8F86AA7ED501
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000_CLASSES\Local Settings\MuiCache\72\52C64B7E
LanguageList
en-US
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Owner
F80B0000C0CDB971AA7ED501
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
SessionHash
A081CB198B239E412BE3C88C9658C4B67EB6467175C8DDED95ACED9EF773FE88
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Sequence
1
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress
C:\Windows\Installer\193918.ipi
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Config.Msi\
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\193919.rbs
30768818
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\193919.rbsLow
4049823872
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2A22BBDF8764655DDDA336C37B232795
08A45F78E851C634B990FFDF728FB14D
<\Microsoft.Office.Interop.Excel,Version="12.0.0.0",Culture="neutral",PublicKeyToken="71E9BCE111E9429C",ProcessorArchitecture="MSIL"
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4D815F6F8AE141611C38E3515D4AC3BC
08A45F78E851C634B990FFDF728FB14D
C:\Program Files\Microsoft\Office Labs\CommunityClips\CCInterface.dll
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\09B75AA1991326304616289FE2A08993
08A45F78E851C634B990FFDF728FB14D
C:\Program Files\Microsoft\Office Labs\CommunityClips\sqmapi.dll
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8CA3E56A4295C73A6F7CBC631216CBA0
08A45F78E851C634B990FFDF728FB14D
C:\Program Files\Microsoft\Office Labs\CommunityClips\AxInterop.WMPLib.dll
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5FC650BA81AEC9842E0EC75AEFB987C
08A45F78E851C634B990FFDF728FB14D
C:\Program Files\Windows Media Components\Encoder\Profiles\commclips_V2.prx
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BE1F9881AAE94787F81EE4EE27368BFF
08A45F78E851C634B990FFDF728FB14D
C:\Program Files\Microsoft\Office Labs\CommunityClips\wmenc.exe
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9DF6045CF69DF4FFA6A099E191F972DB
08A45F78E851C634B990FFDF728FB14D
<\office,Version="12.0.0.0",Culture="neutral",PublicKeyToken="71E9BCE111E9429C",ProcessorArchitecture="MSIL"
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BF5C0C2D8AAF86EF6C5D8BE8FC4E1B92
08A45F78E851C634B990FFDF728FB14D
C:\Program Files\Microsoft\Office Labs\CommunityClips\Interop.WMEncoderLib.dll
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\35C9FB5BCB9BF93DA4348629CDF7E9FE
08A45F78E851C634B990FFDF728FB14D
C:\Program Files\Microsoft\Office Labs\CommunityClips\Interop.WMPLib.dll
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5B2383CEEF1FBD51B614233680687B7E
08A45F78E851C634B990FFDF728FB14D
<\Microsoft.Office.Interop.Word,Version="12.0.0.0",Culture="neutral",PublicKeyToken="71E9BCE111E9429C",ProcessorArchitecture="MSIL"
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CBFC77DDA832BBF0F3B214968422C6C7
08A45F78E851C634B990FFDF728FB14D
<\Microsoft.OfficeLabs.Common,Version="1.0.1813.0",Culture="neutral",PublicKeyToken="31BF3856AD364E35",ProcessorArchitecture="x86"
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\96BD305A62B267BEE20A0F372514ECBA
08A45F78E851C634B990FFDF728FB14D
C:\Program Files\Microsoft\Office Labs\CommunityClips\WMEncoder.exe
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5BF0261D5A33280BB999C8BCCB311F84
08A45F78E851C634B990FFDF728FB14D
<\Microsoft.Office.Interop.PowerPoint,Version="12.0.0.0",Culture="neutral",PublicKeyToken="71E9BCE111E9429C",ProcessorArchitecture="MSIL"
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5D135004A2E7B3EE3DD205C533B917A
08A45F78E851C634B990FFDF728FB14D
C:\Program Files\Microsoft\Office Labs\CommunityClips\Microsoft.OfficeLabs.Update.dll
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08A45F78E851C634B990FFDF728FB14D
08A45F78E851C634B990FFDF728FB14D
C:\Program Files\Microsoft\Office Labs\CommunityClips\
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\293A1E0A5B2266B142B05DBBE6105DDD
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office\Word\Addins\OCommClips.Connect\Description
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\60B7BBAFE92C7998D9E2EAF22F97CA36
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office\Word\Addins\OCommClips.Connect\LoadBehavior
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AAF7D100B5DB57947CC1834A3E5EE0C8
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office\Word\Addins\OCommClips.Connect\FriendlyName
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\96E499B04024E1131DF534F1FC315355
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office\PowerPoint\Addins\OCommClips.Connect\Description
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\045185E1FFA2A5F165176FA456665ECD
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office\PowerPoint\Addins\OCommClips.Connect\LoadBehavior
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F7EC8BF43AC8BDA4CF25AE7DDCAD82F5
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office\PowerPoint\Addins\OCommClips.Connect\FriendlyName
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DDFD5E37864FB5894992778949AFE0FE
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office\Excel\AddIns\OCommClips.Connect\LoadBehavior
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C2BF2D68C9B9BFAAD920559E20A734B0
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office\Excel\AddIns\OCommClips.Connect\FriendlyName
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E9D2F1814414DCAADBC97C8BE40F4FB5
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office\Excel\AddIns\OCommClips.Connect\Description
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\613567E227D039D44493F4436E6ED00E
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office\12.0\Common\Research\Sources\{9ACF08B9-8B40-4637-8B6C-E6F04D4F2AD4}\{32D8440E-693D-4EE1-9FE3-8FDBE96C9C52}\Display
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\75F0331D99E77291E114E8BB335841AB
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office\12.0\Common\Research\Sources\{9ACF08B9-8B40-4637-8B6C-E6F04D4F2AD4}\{32D8440E-693D-4EE1-9FE3-8FDBE96C9C52}\Description
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D8C4F160EEF648726E42BF9BD4645218
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office\12.0\Common\Research\Sources\{9ACF08B9-8B40-4637-8B6C-E6F04D4F2AD4}\{32D8440E-693D-4EE1-9FE3-8FDBE96C9C52}\Parental
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E2728C5FE85FB37A75969BAD580A3825
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office\12.0\Common\Research\Sources\{9ACF08B9-8B40-4637-8B6C-E6F04D4F2AD4}\{32D8440E-693D-4EE1-9FE3-8FDBE96C9C52}\Status
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E10E85F8BB4F86E246C03C55FE08B34
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office\12.0\Common\Research\Sources\{9ACF08B9-8B40-4637-8B6C-E6F04D4F2AD4}\{32D8440E-693D-4EE1-9FE3-8FDBE96C9C52}\CategoryID
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5715B4EAA97A0EA9E8AD727493002A47
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office\12.0\Common\Research\Sources\{9ACF08B9-8B40-4637-8B6C-E6F04D4F2AD4}\{32D8440E-693D-4EE1-9FE3-8FDBE96C9C52}\ServiceName
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8B261F6F5D8980C65875F236683D88EA
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office\12.0\Common\Research\Sources\{9ACF08B9-8B40-4637-8B6C-E6F04D4F2AD4}\{32D8440E-693D-4EE1-9FE3-8FDBE96C9C52}\TermsOfUse
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C3DD6D7CF6824DE6A6E447B6CFBA3A5E
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office\12.0\Common\Research\Sources\{9ACF08B9-8B40-4637-8B6C-E6F04D4F2AD4}\{32D8440E-693D-4EE1-9FE3-8FDBE96C9C52}\PersistData
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6A92E8005C63F617263D7DD698C0E311
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office\12.0\Common\Research\Sources\{9ACF08B9-8B40-4637-8B6C-E6F04D4F2AD4}\{32D8440E-693D-4EE1-9FE3-8FDBE96C9C52}\SortOrder
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA37BB8CCDE58F96BD2BC83DD9B6D598
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office\12.0\Common\Research\Sources\{9ACF08B9-8B40-4637-8B6C-E6F04D4F2AD4}\AboutPath
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9B77A6B13BC1C3BC6BC8D4327CA567A5
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office\12.0\Common\Research\Sources\{9ACF08B9-8B40-4637-8B6C-E6F04D4F2AD4}\Type
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\01F7C6AA9DC826F1066D49668D2233F9
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office\12.0\Common\Research\Sources\{9ACF08B9-8B40-4637-8B6C-E6F04D4F2AD4}\ProviderName
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86BEB22FCF21658FF8D734212E2C75D5
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office\12.0\Common\Research\Sources\{9ACF08B9-8B40-4637-8B6C-E6F04D4F2AD4}\Status
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A820E445A3BD43AB01D0B160810C7E57
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office\12.0\Common\Research\Sources\{9ACF08B9-8B40-4637-8B6C-E6F04D4F2AD4}\QueryPath
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\755FEC0E477601EDCD10D68F81E4A77A
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office\12.0\Common\Research\Sources\{9ACF08B9-8B40-4637-8B6C-E6F04D4F2AD4}\UpdateStatus
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7891D6EDE4CCD716B359051718AAA0DE
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office\12.0\Common\Research\Sources\{9ACF08B9-8B40-4637-8B6C-E6F04D4F2AD4}\Revision
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E229F37903C3E2B2632BF2B2E65C61C8
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office\12.0\Common\Research\Sources\{9ACF08B9-8B40-4637-8B6C-E6F04D4F2AD4}\RegistrationPath
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D5321114A026D1C6A66151B87E6BCA15
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office Labs\CommunityClips\1.0\CClipsResearchServiceUrl
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\477226C8E357CDDA087073DE5B8644D6
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office Labs\CommunityClips\1.0\MediaLocation
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8555CCF55126114C56C9875E9A8B5568
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office Labs\CommunityClips\1.0\UploadInterval
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AAE7B7DC255D7A9DCDF226961E3B4CC5
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office Labs\CommunityClips\1.0\SQMUploadDateTime
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A36658EC7F95110DE0E8DBDA8F0D3BE0
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office Labs\CommunityClips\1.0\ProfileName
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\90E47941E3A446B24A67F6FCF6A0E175
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office Labs\CommunityClips\1.0\CommunityClipsUploadUrl
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3FB1F58D13F158231D4D105D306D61AF
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office Labs\CommunityClips\1.0\Height
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6149F8B2C1925512ED956A4DC5D9A034
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office Labs\CommunityClips\1.0\ShowHelpOnStartup
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CA766556953A5DD69617525CA144219D
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office Labs\CommunityClips\1.0\DoNotShowStartDialog
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EDB1A951B65E3BBE28CBC2B23F85734E
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office Labs\CommunityClips\1.0\InstallDirectory
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FE72F4E9D3C8326AE7C342A4E4D3E51C
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office Labs\CommunityClips\1.0\SqmEnabled
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D7181E365E4C1AD9EF07CC1603A01CD4
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office Labs\CommunityClips\1.0\InstallDate
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2CD8627F34EBC1EB37F22670A8A5DB1B
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office Labs\CommunityClips\1.0\TitleVideoFilePath
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E0E9FD7C4853031B94C73CE23127200D
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office Labs\CommunityClips\1.0\AutoStartOnLogon
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\05E5460C511BE4F7EFCF47961747868A
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office Labs\CommunityClips\1.0\Width
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6A3751750C4AA8A5F07DAD3A64CD068C
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office Labs\CommunityClips\1.0\AppendTitleVideoFilePath
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0570E543EB17C02607C29CCDC3139E95
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office Labs\CommunityClips\1.0\Port
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\47D80B216B46D399B007DF34D65A6C46
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\Office Labs\Sqm\Products\1\EnableSqm
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DCB5E4B5233B0E2DB8A5FD0C2D150E83
08A45F78E851C634B990FFDF728FB14D
02:\Software\Microsoft\IdentityCRL\Environment\INT\RemoteFile
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\073338F9EAE3C87179648EF4839EF4C2
08A45F78E851C634B990FFDF728FB14D
02:\Software\Microsoft\IdentityCRL\RemoteFile
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E870E1E6DCCFA1C678F8450EF4F2C331
08A45F78E851C634B990FFDF728FB14D
C:\Program Files\Microsoft\Office Labs\CommunityClips\CommunityClips.exe
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D3400DE6303C70D42B0A17D0D5E47607
08A45F78E851C634B990FFDF728FB14D
01:\Software\Microsoft\OfficeLabs\Update\Products\{87F54A80-158E-436C-9B09-FFFD27F81BD4}\EnableAutoUpdate
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\06AEB62C8BF735C25A5919391EBA6F68
08A45F78E851C634B990FFDF728FB14D
C:\Program Files\Microsoft\Office Labs\CommunityClips\OCommClips.dll
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2791CB9297F2C9B468ED2078EE14717C
08A45F78E851C634B990FFDF728FB14D
00:\CLSID\{29BC1972-2F79-4B9C-86DE-0287EE4117C7}\InprocServer32\
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\092950EDA5E2C13F732B76D5DF03B81A
08A45F78E851C634B990FFDF728FB14D
C:\Program Files\Microsoft\Office Labs\CommunityClips\CommunityClips.exe.config
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0EF3EF66E27A1950A5461A20BA04809A
08A45F78E851C634B990FFDF728FB14D
C:\Program Files\Microsoft\Office Labs\CommunityClips\Microsoft.OfficeLabs.Common.pdb
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5A274A992979090A0C929D1F4F256A9F
08A45F78E851C634B990FFDF728FB14D
C:\Program Files\Microsoft\Office Labs\CommunityClips\CommunityClips.pdb
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\42627FD3BEAC2E918857BF5025F81E94
08A45F78E851C634B990FFDF728FB14D
C:\Program Files\Microsoft\Office Labs\CommunityClips\CCInterface.pdb
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E601AC23A547CFD9CA1F497CC0F11919
08A45F78E851C634B990FFDF728FB14D
C:\Program Files\Microsoft\Office Labs\CommunityClips\Microsoft.OfficeLabs.Common.dll
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1CB3979ACA0C3530FC816945EE1B4EDC
08A45F78E851C634B990FFDF728FB14D
<\CCInterface,Version="1.0.1813.0",Culture="neutral",PublicKeyToken="31BF3856AD364E35",ProcessorArchitecture="x86"
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\95B7AB90130DBF24E8D0FE4A251A388D
08A45F78E851C634B990FFDF728FB14D
C:\Program Files\Microsoft\Office Labs\CommunityClips\styles.css
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BD003E88AF607CEB4603EB506FE25747
08A45F78E851C634B990FFDF728FB14D
C:\Program Files\Microsoft\Office Labs\CommunityClips\Eula.rtf
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4AC657B6108082DB8819EC94A0EEDC9F
08A45F78E851C634B990FFDF728FB14D
C:\Program Files\Microsoft\Office Labs\CommunityClips\img\button_headerSearch.png
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9D07415332654BBDD1B4F465D9778598
08A45F78E851C634B990FFDF728FB14D
C:\Program Files\Microsoft\Office Labs\CommunityClips\communityClipsHelp.htm
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9DD75087C6093771CF35AFCC32B8CE81
08A45F78E851C634B990FFDF728FB14D
C:\Program Files\Microsoft\Office Labs\CommunityClips\img\logo_wpTemp.png
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E89F9A74936701F175B050236539DD10
08A45F78E851C634B990FFDF728FB14D
C:\Program Files\Microsoft\Office Labs\CommunityClips\img\logo_header.png
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B25D6B54DC8BFB279A145DDF62BDD58
08A45F78E851C634B990FFDF728FB14D
C:\Program Files\Microsoft\Office Labs\CommunityClips\img\substituteCode_searchBox.png
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5A54863C8B2ADF3EC8C624D71EFC70CE
08A45F78E851C634B990FFDF728FB14D
C:\Program Files\Microsoft\Office Labs\CommunityClips\PrivacyStatement.htm
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\Microsoft\Office Labs\CommunityClips\
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\Microsoft\Office Labs\
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\Microsoft\Office Labs\CommunityClips\img\
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\Windows Media Components\Encoder\Profiles\
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\Windows Media Components\Encoder\
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\Windows Media Components\
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Windows\Installer\{87F54A80-158E-436C-9B09-FFFD27F81BD4}\
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Labs\
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\OCommClips.Connect
OCommClips.Connect
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{29BC1972-2F79-4B9C-86DE-0287EE4117C7}\ProgId
OCommClips.Connect
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{29BC1972-2F79-4B9C-86DE-0287EE4117C7}\InprocServer32
mscoree.dll
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{29BC1972-2F79-4B9C-86DE-0287EE4117C7}\InprocServer32
RuntimeVersion
v2.0.50727
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{29BC1972-2F79-4B9C-86DE-0287EE4117C7}\InprocServer32
CodeBase
C:\Program Files\Microsoft\Office Labs\CommunityClips\OCommClips.dll
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{29BC1972-2F79-4B9C-86DE-0287EE4117C7}\InprocServer32
ThreadingModel
Both
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{29BC1972-2F79-4B9C-86DE-0287EE4117C7}\InprocServer32
Class
OCommClips.Connect
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{29BC1972-2F79-4B9C-86DE-0287EE4117C7}\InprocServer32
Assembly
OCommClips, Version=1.0.1813.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{29BC1972-2F79-4B9C-86DE-0287EE4117C7}
OCommClips.Connect
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\OCommClips.Connect\CLSID
{29BC1972-2F79-4B9C-86DE-0287EE4117C7}
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{29BC1972-2F79-4B9C-86DE-0287EE4117C7}\InprocServer32\1.0.1813.0
Assembly
OCommClips, Version=1.0.1813.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{29BC1972-2F79-4B9C-86DE-0287EE4117C7}\InprocServer32\1.0.1813.0
CodeBase
C:\Program Files\Microsoft\Office Labs\CommunityClips\OCommClips.dll
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{29BC1972-2F79-4B9C-86DE-0287EE4117C7}\InprocServer32\1.0.1813.0
RuntimeVersion
v2.0.50727
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{29BC1972-2F79-4B9C-86DE-0287EE4117C7}\InprocServer32\1.0.1813.0
Class
OCommClips.Connect
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office\Word\Addins\OCommClips.Connect
Description
Create and share videos
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office\Word\Addins\OCommClips.Connect
LoadBehavior
3
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office\Word\Addins\OCommClips.Connect
FriendlyName
Community Clips
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office\PowerPoint\Addins\OCommClips.Connect
Description
Create and share videos
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office\PowerPoint\Addins\OCommClips.Connect
LoadBehavior
3
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office\PowerPoint\Addins\OCommClips.Connect
FriendlyName
Community Clips
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office\Excel\AddIns\OCommClips.Connect
LoadBehavior
3
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office\Excel\AddIns\OCommClips.Connect
FriendlyName
Community Clips
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office\Excel\AddIns\OCommClips.Connect
Description
Create and share videos
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office\12.0\Common\Research\Sources\{9ACF08B9-8B40-4637-8B6C-E6F04D4F2AD4}\{32D8440E-693D-4EE1-9FE3-8FDBE96C9C52}
Display
On
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office\12.0\Common\Research\Sources\{9ACF08B9-8B40-4637-8B6C-E6F04D4F2AD4}\{32D8440E-693D-4EE1-9FE3-8FDBE96C9C52}
Description
Community Clips Video Registration Service for Microsoft Office Research Library.
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office\12.0\Common\Research\Sources\{9ACF08B9-8B40-4637-8B6C-E6F04D4F2AD4}\{32D8440E-693D-4EE1-9FE3-8FDBE96C9C52}
Parental
Unsupported
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office\12.0\Common\Research\Sources\{9ACF08B9-8B40-4637-8B6C-E6F04D4F2AD4}\{32D8440E-693D-4EE1-9FE3-8FDBE96C9C52}
Status
Enabled
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office\12.0\Common\Research\Sources\{9ACF08B9-8B40-4637-8B6C-E6F04D4F2AD4}\{32D8440E-693D-4EE1-9FE3-8FDBE96C9C52}
CategoryID
1073741824
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office\12.0\Common\Research\Sources\{9ACF08B9-8B40-4637-8B6C-E6F04D4F2AD4}\{32D8440E-693D-4EE1-9FE3-8FDBE96C9C52}
ServiceName
Office Labs Community Clips
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office\12.0\Common\Research\Sources\{9ACF08B9-8B40-4637-8B6C-E6F04D4F2AD4}\{32D8440E-693D-4EE1-9FE3-8FDBE96C9C52}
TermsOfUse
Copyright (c) 2007 Microsoft.
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office\12.0\Common\Research\Sources\{9ACF08B9-8B40-4637-8B6C-E6F04D4F2AD4}\{32D8440E-693D-4EE1-9FE3-8FDBE96C9C52}
PersistData
0
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office\12.0\Common\Research\Sources\{9ACF08B9-8B40-4637-8B6C-E6F04D4F2AD4}\{32D8440E-693D-4EE1-9FE3-8FDBE96C9C52}
SortOrder
0
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office\12.0\Common\Research\Sources\{9ACF08B9-8B40-4637-8B6C-E6F04D4F2AD4}
AboutPath
http://kn205:1234/CCWeb/Services../about.aspx
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office\12.0\Common\Research\Sources\{9ACF08B9-8B40-4637-8B6C-E6F04D4F2AD4}
Type
SOAP
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office\12.0\Common\Research\Sources\{9ACF08B9-8B40-4637-8B6C-E6F04D4F2AD4}
ProviderName
Office Labs Community Clips
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office\12.0\Common\Research\Sources\{9ACF08B9-8B40-4637-8B6C-E6F04D4F2AD4}
Status
Enabled
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office\12.0\Common\Research\Sources\{9ACF08B9-8B40-4637-8B6C-E6F04D4F2AD4}
QueryPath
http://kn205:1234/CCWeb/Services/VideoResearchQuery.asmx
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office\12.0\Common\Research\Sources\{9ACF08B9-8B40-4637-8B6C-E6F04D4F2AD4}
UpdateStatus
1
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office\12.0\Common\Research\Sources\{9ACF08B9-8B40-4637-8B6C-E6F04D4F2AD4}
Revision
0
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office\12.0\Common\Research\Sources\{9ACF08B9-8B40-4637-8B6C-E6F04D4F2AD4}
RegistrationPath
http://kn205:1234/CCWeb/Services/VideoResearchRegistration.asmx
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office Labs\CommunityClips\1.0
CClipsResearchServiceUrl
http://communityclips.officelabs.com/Services/VideoResearchQuery.asmx?wsdl
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office Labs\CommunityClips\1.0
MediaLocation
C:\Users\admin\AppData\Roaming\Local\Microsoft\Office Labs\CommunityClips\Video
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office Labs\CommunityClips\1.0
UploadInterval
24
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office Labs\CommunityClips\1.0
SQMUploadDateTime
1/1/2007 12:00:00 AM
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office Labs\CommunityClips\1.0
ProfileName
CommunityClips_V2
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office Labs\CommunityClips\1.0
CommunityClipsUploadUrl
http://communityclips.officelabs.com/Upload.aspx?path=Upload&client=desktop&file={0}&keywords={1}
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office Labs\CommunityClips\1.0
Height
0
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office Labs\CommunityClips\1.0
ShowHelpOnStartup
False
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office Labs\CommunityClips\1.0
DoNotShowStartDialog
0
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office Labs\CommunityClips\1.0
InstallDirectory
C:\Program Files\Microsoft\Office Labs\CommunityClips\
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office Labs\CommunityClips\1.0
SqmEnabled
True
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office Labs\CommunityClips\1.0
InstallDate
0
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office Labs\CommunityClips\1.0
TitleVideoFilePath
C:\Program Files\Microsoft\Office Labs\CommunityClips\Title.wmv
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office Labs\CommunityClips\1.0
AutoStartOnLogon
False
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office Labs\CommunityClips\1.0
Width
0
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office Labs\CommunityClips\1.0
AppendTitleVideoFilePath
0
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office Labs\CommunityClips\1.0
Port
9999
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Office Labs\Sqm\Products\1
EnableSqm
1
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\OfficeLabs\Update\Products\{87F54A80-158E-436C-9B09-FFFD27F81BD4}
EnableAutoUpdate
1
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IdentityCRL\Environment\INT
RemoteFile
http://clientconfig.passport-int.net/PPCRLconfig.srf
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IdentityCRL
RemoteFile
http://clientconfig.passport.net/PPCRLconfig.srf
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\08A45F78E851C634B990FFDF728FB14D\InstallProperties
LocalPackage
C:\Windows\Installer\19391a.msi
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\08A45F78E851C634B990FFDF728FB14D\InstallProperties
AuthorizedCDFPrefix
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\08A45F78E851C634B990FFDF728FB14D\InstallProperties
Comments
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\08A45F78E851C634B990FFDF728FB14D\InstallProperties
Contact
Microsoft
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\08A45F78E851C634B990FFDF728FB14D\InstallProperties
DisplayVersion
1.0.0
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\08A45F78E851C634B990FFDF728FB14D\InstallProperties
HelpLink
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\08A45F78E851C634B990FFDF728FB14D\InstallProperties
HelpTelephone
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\08A45F78E851C634B990FFDF728FB14D\InstallProperties
InstallDate
20191009
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\08A45F78E851C634B990FFDF728FB14D\InstallProperties
InstallLocation
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\08A45F78E851C634B990FFDF728FB14D\InstallProperties
InstallSource
C:\Users\admin\AppData\Local\Temp\
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\08A45F78E851C634B990FFDF728FB14D\InstallProperties
ModifyPath
MsiExec.exe /I{87F54A80-158E-436C-9B09-FFFD27F81BD4}
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\08A45F78E851C634B990FFDF728FB14D\InstallProperties
Publisher
Microsoft
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\08A45F78E851C634B990FFDF728FB14D\InstallProperties
Readme
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\08A45F78E851C634B990FFDF728FB14D\InstallProperties
Size
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\08A45F78E851C634B990FFDF728FB14D\InstallProperties
EstimatedSize
17000
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\08A45F78E851C634B990FFDF728FB14D\InstallProperties
UninstallString
MsiExec.exe /I{87F54A80-158E-436C-9B09-FFFD27F81BD4}
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\08A45F78E851C634B990FFDF728FB14D\InstallProperties
URLInfoAbout
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\08A45F78E851C634B990FFDF728FB14D\InstallProperties
URLUpdateInfo
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\08A45F78E851C634B990FFDF728FB14D\InstallProperties
VersionMajor
1
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\08A45F78E851C634B990FFDF728FB14D\InstallProperties
VersionMinor
0
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\08A45F78E851C634B990FFDF728FB14D\InstallProperties
WindowsInstaller
1
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\08A45F78E851C634B990FFDF728FB14D\InstallProperties
Version
16777216
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\08A45F78E851C634B990FFDF728FB14D\InstallProperties
Language
1033
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{87F54A80-158E-436C-9B09-FFFD27F81BD4}
AuthorizedCDFPrefix
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{87F54A80-158E-436C-9B09-FFFD27F81BD4}
Comments
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{87F54A80-158E-436C-9B09-FFFD27F81BD4}
Contact
Microsoft
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{87F54A80-158E-436C-9B09-FFFD27F81BD4}
DisplayVersion
1.0.0
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{87F54A80-158E-436C-9B09-FFFD27F81BD4}
HelpLink
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{87F54A80-158E-436C-9B09-FFFD27F81BD4}
HelpTelephone
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{87F54A80-158E-436C-9B09-FFFD27F81BD4}
InstallDate
20191009
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{87F54A80-158E-436C-9B09-FFFD27F81BD4}
InstallLocation
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{87F54A80-158E-436C-9B09-FFFD27F81BD4}
InstallSource
C:\Users\admin\AppData\Local\Temp\
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{87F54A80-158E-436C-9B09-FFFD27F81BD4}
ModifyPath
MsiExec.exe /I{87F54A80-158E-436C-9B09-FFFD27F81BD4}
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{87F54A80-158E-436C-9B09-FFFD27F81BD4}
Publisher
Microsoft
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{87F54A80-158E-436C-9B09-FFFD27F81BD4}
Readme
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{87F54A80-158E-436C-9B09-FFFD27F81BD4}
Size
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{87F54A80-158E-436C-9B09-FFFD27F81BD4}
EstimatedSize
17000
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{87F54A80-158E-436C-9B09-FFFD27F81BD4}
UninstallString
MsiExec.exe /I{87F54A80-158E-436C-9B09-FFFD27F81BD4}
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{87F54A80-158E-436C-9B09-FFFD27F81BD4}
URLInfoAbout
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{87F54A80-158E-436C-9B09-FFFD27F81BD4}
URLUpdateInfo
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{87F54A80-158E-436C-9B09-FFFD27F81BD4}
VersionMajor
1
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{87F54A80-158E-436C-9B09-FFFD27F81BD4}
VersionMinor
0
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{87F54A80-158E-436C-9B09-FFFD27F81BD4}
WindowsInstaller
1
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{87F54A80-158E-436C-9B09-FFFD27F81BD4}
Version
16777216
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{87F54A80-158E-436C-9B09-FFFD27F81BD4}
Language
1033
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\772EE2B08CA9C1B4986A824B1AF439ED
08A45F78E851C634B990FFDF728FB14D
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\08A45F78E851C634B990FFDF728FB14D\InstallProperties
DisplayName
Community Clips from Microsoft Office Labs
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{87F54A80-158E-436C-9B09-FFFD27F81BD4}
DisplayName
Community Clips from Microsoft Office Labs
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\Global
Microsoft.Office.Interop.Excel,Version="12.0.0.0",Culture="neutral",PublicKeyToken="71E9BCE111E9429C",ProcessorArchitecture="MSIL"
q?7dS}Rua9v4u^z43Z2m>Q?`Vzi1.Xm1NfJ7.AXhD
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\Global
office,Version="12.0.0.0",Culture="neutral",PublicKeyToken="71E9BCE111E9429C",ProcessorArchitecture="MSIL"
q?7dS}Rua9v4u^z43Z2m>xGdIhlCp'{TGuo,qLRle
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\Global
Microsoft.Office.Interop.Word,Version="12.0.0.0",Culture="neutral",PublicKeyToken="71E9BCE111E9429C",ProcessorArchitecture="MSIL"
q?7dS}Rua9v4u^z43Z2m>1k9wt`@2%*kExsGV39Ps
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\Global
Microsoft.OfficeLabs.Common,Version="1.0.1813.0",Culture="neutral",PublicKeyToken="31BF3856AD364E35",ProcessorArchitecture="x86"
q?7dS}Rua9v4u^z43Z2m>`5=3pK)i'(9=MoI}~)~O
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\Global
Microsoft.Office.Interop.PowerPoint,Version="12.0.0.0",Culture="neutral",PublicKeyToken="71E9BCE111E9429C",ProcessorArchitecture="MSIL"
q?7dS}Rua9v4u^z43Z2m>w_,Al0c$gaargKj-HcM?
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\Global
CCInterface,Version="1.0.1813.0",Culture="neutral",PublicKeyToken="31BF3856AD364E35",ProcessorArchitecture="x86"
q?7dS}Rua9v4u^z43Z2m>HZoO_A$u($PIm3C}1k2k
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Microsoft|Office Labs|CommunityClips|CCInterface.dll
CCInterface,Version="1.0.1813.0",Culture="neutral",PublicKeyToken="31BF3856AD364E35",ProcessorArchitecture="x86"
q?7dS}Rua9v4u^z43Z2m>[email protected][Gxoo1+*l?Go)U[5Cj
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Microsoft|Office Labs|CommunityClips|AxInterop.WMPLib.dll
AxInterop.WMPLib,Version="1.0.0.0",Culture="neutral",PublicKeyToken="F9E8B29D1FCEC5B5",ProcessorArchitecture="MSIL"
q?7dS}Rua9v4u^z43Z2m>+D~O^q59V]=2{[[email protected]&
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Microsoft|Office Labs|CommunityClips|Interop.WMEncoderLib.dll
interop.WMEncoderLib,Version="1.0.0.0",Culture="neutral",PublicKeyToken="F9E8B29D1FCEC5B5",ProcessorArchitecture="MSIL"
q?7dS}Rua9v4u^z43Z2m>!rUgl.25jzb_!sUc{'J1
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Microsoft|Office Labs|CommunityClips|Interop.WMPLib.dll
Interop.WMPLib,Version="1.0.0.0",Culture="neutral",PublicKeyToken="F9E8B29D1FCEC5B5",ProcessorArchitecture="MSIL"
q?7dS}Rua9v4u^z43Z2m>482Kch4D$m[6c'Wi&.$v
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Microsoft|Office Labs|CommunityClips|Microsoft.OfficeLabs.Update.dll
Microsoft.OfficeLabs.Update,Version="1.2.6.2",Culture="neutral",PublicKeyToken="9419C49C344E4491",ProcessorArchitecture="MSIL"
q?7dS}Rua9v4u^z43Z2m>Hvr+!K&$4rbr-Ch~n~d^
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Microsoft|Office Labs|CommunityClips|CommunityClips.exe
CommunityClips,Version="1.0.1813.0",Culture="neutral",PublicKeyToken="31BF3856AD364E35",ProcessorArchitecture="x86"
q?7dS}Rua9v4u^z43Z2m>J'@IKz8ChJujN+qKxP3)
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Microsoft|Office Labs|CommunityClips|OCommClips.dll
OCommClips,Version="1.0.1813.0",Culture="neutral",PublicKeyToken="31BF3856AD364E35",ProcessorArchitecture="MSIL"
q?7dS}Rua9v4u^z43Z2m>LMHQg1(y82.0KLW.d'HS
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Program Files|Microsoft|Office Labs|CommunityClips|Microsoft.OfficeLabs.Common.dll
Microsoft.OfficeLabs.Common,Version="1.0.1813.0",Culture="neutral",PublicKeyToken="31BF3856AD364E35",ProcessorArchitecture="x86"
q?7dS}Rua9v4u^z43Z2m>N2SC48Z!kZy-F0iwffkV
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\08A45F78E851C634B990FFDF728FB14D
DefaultFeature
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\08A45F78E851C634B990FFDF728FB14D\Features
DefaultFeature
Q?`[email protected][Gxoo1+*l?Go)U[5CjImyW+X!M*$k&C4y-1JS6+D~O^q59V]=2{[[email protected]&Y*[email protected]&Ag6DzY1.iRmGt*_VeeN'hBZubX~3{xGdIhlCp'{TGuo,qLRle!rUgl.25jzb_!sUc{'J1482Kch4D$m[6c'Wi&.$v1k9wt`@2%*kExsGV39Ps`5=3pK)i'(9=MoI}~)~OlP%&^,lVbt[pE=M2$V6`w_,Al0c$gaargKj-HcM?Hvr+!K&$4rbr-Ch~n~d^q?7dS}Rua9v4u^z43Z2m2b+e['BSm+=@GGeKV5Apa*gYyU+t6T~xXC3O}{%HpX0&!Ufp[?=[email protected]]3}7$U*jrf&i`qk3gK)'[email protected]{h,w2S)-,=u*@b0_~o$ev]A$C%(@[email protected]``[email protected]{XK!4!Ya5nouTz8DS]@(z_]mG~sH7e]&&F}h*}o,u_X.}HdcK1WE22Ax2.&[email protected]$.&n45qv!q=B+8l&u3*+~2n?eZqRmd~U9{$-MXd0=bljdck,SQ8SQ~w6Y`h^!xAAoz_4TB5*@wwM3_+si2V^E!`!j9=_T$a7,*kYU%ur=yi?QM'^5GxaLFfJBw]sGeW*+a2)I7iX*f]KlCUUJZuQmr,T23!ZjuNLN9lAKc^&V({TkSiq%~'Jm[A~lnv`0T0[{m+Uk0Cj,0ME.q+D)Ez1lj_f5J*-ZsJ{HKd12[E&rov,'?nx1+yr((w$!FWS,+C(2zpdg!mz$_V&uM{!T9qHDVGpm(fpx[+Bo^k0MQpxFFDGfw^KLLse3uk_x[XCy_s1l4ms1TI)%UPEWv8t{XhJI$YdTp7=9B^2--Ug'ds`%@N8uM)(-KWT+lFvNF$h.Buhrgis2SEwV&k~G,znUizrI0~CnEsrwGk[M3sk+hIp`_V`f'&XT])@=Ky1(!vakmey~Cp[%Vn+n084P4-Omi_1Hy4w%!25{[e-,JFEmpHRV9MOLXHiJWAKCTnFhsc0jn~+0y)od.itjEQs176]Er(iosZg&gI^[email protected][0gm~^[email protected]`+f0FeG%~D`-b~OC8io'Zya1)U%3&8ZqkQjxofh9uvPWA{[email protected]_Ym%~Cs.R+E4CDa]ul,JihK]o4r=YSGl,^zo)a=uDBGY!)p+E9Y6{Jq9gO*IHPKHEEmNyjlYD(~ffbl?6Dyd=[dWAX*=@}bAqSW82J'@IKz8ChJujN+qKxP3)ST?][email protected](?C'Vxg-LLMHQg1(y82.0KLW.d'[email protected](y}h**IFplHR.w'Of$F)_4w[X&a+I?e.l$11rp!qjjC_$tDHY)TN[[.H%gvf)[email protected]+o2C+~MLw$1gEh?N2SC48Z!kZy-F0iwffkVHZoO_A$u($PIm3C}1k2klPj-&i-wT9Xjm!^yswYnqRZ~SZOoBf&ctp$38RLMpO`UJm0VleZOCf?=[email protected]%*(5-!*]o2GtgCu}-0TRUqXNZcaU*@@jsj,2u!+LCk%?][_},m'Q)[email protected][AW.2bBN.pX')%S?RBmgffN?r2jy9Pys*rt
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\08A45F78E851C634B990FFDF728FB14D\Patches
AllPatches
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\08A45F78E851C634B990FFDF728FB14D
ProductName
Community Clips from Microsoft Office Labs
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\08A45F78E851C634B990FFDF728FB14D
PackageCode
49F6675AB40C4F8429912AAC160FD10C
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\08A45F78E851C634B990FFDF728FB14D
Language
1033
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\08A45F78E851C634B990FFDF728FB14D
Version
16777216
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\08A45F78E851C634B990FFDF728FB14D
Assignment
1
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\08A45F78E851C634B990FFDF728FB14D
AdvertiseFlags
388
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\08A45F78E851C634B990FFDF728FB14D
ProductIcon
C:\Windows\Installer\{87F54A80-158E-436C-9B09-FFFD27F81BD4}\_6FEFF9B68218417F98F549.exe
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\08A45F78E851C634B990FFDF728FB14D
InstanceType
0
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\08A45F78E851C634B990FFDF728FB14D
AuthorizedLUAApp
0
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\08A45F78E851C634B990FFDF728FB14D
DeploymentFlags
2
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\772EE2B08CA9C1B4986A824B1AF439ED
08A45F78E851C634B990FFDF728FB14D
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\08A45F78E851C634B990FFDF728FB14D\SourceList
PackageName
CommunityClipsSetup_1813.msi
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\08A45F78E851C634B990FFDF728FB14D\SourceList\Net
1
C:\Users\admin\AppData\Local\Temp\
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\08A45F78E851C634B990FFDF728FB14D\SourceList\Media
1
;
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\08A45F78E851C634B990FFDF728FB14D
Clients
:
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\08A45F78E851C634B990FFDF728FB14D\SourceList
LastUsedSource
n;1;C:\Users\admin\AppData\Local\Temp\
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
582
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
73
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
582
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.Office.Interop.Excel,12.0.0.0,,71e9bce111e9429c
FA05FC8FAA7ED501
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
583
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
74
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
583
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
office,12.0.0.0,,71e9bce111e9429c
CA180F90AA7ED501
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
584
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
75
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
584
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.Office.Interop.Word,12.0.0.0,,71e9bce111e9429c
D83F1690AA7ED501
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
585
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
585
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.OfficeLabs.Common,1.0.1813.0,,31bf3856ad364e35,x86
32A21890AA7ED501
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
586
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
76
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
586
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.Office.Interop.PowerPoint,12.0.0.0,,71e9bce111e9429c
9A2B2290AA7ED501
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
587
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
587
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
CCInterface,1.0.1813.0,,31bf3856ad364e35,x86
7EDD1390AA7ED501
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings
StringCacheGeneration
115
3064
msiexec.exe
delete key
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\72\52C64B7E
3064
msiexec.exe
delete key
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\72
3064
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
3064
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\Volatile
NestingLevel
0
3064
msiexec.exe
delete key
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
3064
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
SrCreateRp (Enter)
4000000000000000D4B25B95AA7ED501F80B00003C0B0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppCreate (Enter)
4000000000000000D4B25B95AA7ED501F80B00003C0B0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
LastIndex
25
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppGatherWriterMetadata (Enter)
400000000000000088776095AA7ED501F80B00003C0B0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
IDENTIFY (Enter)
4000000000000000E2D96295AA7ED501F80B0000680C0000E8030000010000000000000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
IDENTIFY (Leave)
40000000000000006270FB95AA7ED501F80B0000680C0000E8030000000000000000000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppGatherWriterMetadata (Leave)
40000000000000001616F69BAA7ED501F80B00003C0B0000D3070000010000000000000000000000000000000000000000000000000000000000000000000000
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppAddInterestingComponents (Enter)
40000000000000001616F69BAA7ED501F80B00003C0B0000D4070000000000000000000000000000000000000000000000000000000000000000000000000000
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppAddInterestingComponents (Leave)
4000000000000000A814159CAA7ED501F80B00003C0B0000D4070000010000000000000000000000000000000000000000000000000000000000000000000000
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
PREPAREBACKUP (Enter)
40000000000000002CEC2C9CAA7ED501F80B00004C090000E9030000010000000000000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
PREPAREBACKUP (Leave)
40000000000000002674559CAA7ED501F80B00004C090000E9030000000000000000000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
GETSTATE (Enter)
40000000000000002674559CAA7ED501F80B000020090000F9030000010000000000000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
GETSTATE (Leave)
4000000000000000E85F619CAA7ED501F80B000020090000F9030000000000000000000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
DOSNAPSHOT (Enter)
4000000000000000F686689CAA7ED501F80B00003C0B00000A040000010000000000000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
DOSNAPSHOT (Leave)
4000000000000000187A7F9DAA7ED501F80B0000E40700000A040000000000000000000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppCreate (Leave)
4000000000000000187A7F9DAA7ED501F80B00003C0B0000D0070000010000000000000000000000000000000000000000000000000000000000000000000000
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
SrCreateRp (Leave)
4000000000000000187A7F9DAA7ED501F80B00003C0B0000D5070000010000000000000000000000000000000000000000000000000000000000000000000000
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
LastIndex
25
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\Volatile
StartNesting
D4B25B95AA7ED501
3064
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
SessionHash
067B0C6FF35847A15A29BA9D91D1B52B85740778DAE4904B9E2DFD151D4B64A8
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress
C:\Windows\Installer\19391d.ipi
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\19391e.rbs
30768819
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\19391e.rbsLow
1886576
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\344889D18CA2ACD448F991318C7443EA
0D00C83EB86A81348A6A7F4D5B1BFDE0
C:\Program Files\Windows Media Components\Encoder\wmenc.exe
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C0D2EA4DD2D48AE4CA91EFCA29EB37F0
0D00C83EB86A81348A6A7F4D5B1BFDE0
C:\Program Files\Windows Media Components\Encoder\wmfdist.exe
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\288A287678597104FB722A0D1FA04631
0D00C83EB86A81348A6A7F4D5B1BFDE0
C:\Program Files\Windows Media Components\Encoder\StreamEditor.dll
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0EB310B678C127E48A3F51D8F8BAFB47
0D00C83EB86A81348A6A7F4D5B1BFDE0
C:\Program Files\Windows Media Components\Encoder\WMdevctl.dll
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E91D22521CF7F674AA79B8671EC4942B
0D00C83EB86A81348A6A7F4D5B1BFDE0
C:\Program Files\Windows Media Components\Encoder\wmedque.dll
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7926DBDCBD8EF6D4EB7161343BEBCDBB
0D00C83EB86A81348A6A7F4D5B1BFDE0
C:\Program Files\Windows Media Components\Encoder\WMEncEng.dll
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C916C63EFDC8499428BB6BA06D328FCA
0D00C83EB86A81348A6A7F4D5B1BFDE0
C:\Program Files\Windows Media Components\Encoder\wmesrcwp.dll
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\790D14068C204824292EA42B10618B1D
0D00C83EB86A81348A6A7F4D5B1BFDE0
C:\Program Files\Windows Media Components\Encoder\WMexfmwp.dll
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FBF41C5A73E4A194FAD8B53FE8B9514C
0D00C83EB86A81348A6A7F4D5B1BFDE0
C:\Program Files\Windows Media Components\Encoder\WMEXres.dll
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D7C370230BB8DCF4A8C57DE57E45AAAF
0D00C83EB86A81348A6A7F4D5B1BFDE0
C:\Program Files\Windows Media Components\Encoder\wmprevu.dll
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\65B629ECF142EE648BC36A78203F447C
0D00C83EB86A81348A6A7F4D5B1BFDE0
C:\Program Files\Windows Media Components\Encoder\wmex.dll
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\58215BE750141C74F93B161C80FCCC86
0D00C83EB86A81348A6A7F4D5B1BFDE0
C:\Program Files\Windows Media Components\Encoder\wmstypelib.exe
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5248F35698F7694DB460FB9806CC31B
0D00C83EB86A81348A6A7F4D5B1BFDE0
C:\Program Files\Windows Media Components\Encoder\settmp.exe
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D81994CF33DB21646A25C76767B8CD87
0D00C83EB86A81348A6A7F4D5B1BFDE0
C:\Program Files\Windows Media Components\Encoder\wmasfdist.exe
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\212DB4632547F1A4B807DC137A1A364F
0D00C83EB86A81348A6A7F4D5B1BFDE0
C:\Program Files\Windows Media Components\Encoder\mspshell.dll
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\73C87E818E7E6384E86F8694C62C444D
0D00C83EB86A81348A6A7F4D5B1BFDE0
C:\Program Files\Windows Media Components\Encoder\Fileinfo.dll
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\55DBEF284E1A21C4C853D5D1EDBB75DD
0D00C83EB86A81348A6A7F4D5B1BFDE0
C:\Program Files\Windows Media Components\Encoder\wmencode.chm
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3510CB34FAB357540ACAF000D59D8813
0D00C83EB86A81348A6A7F4D5B1BFDE0
02:\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\VideoCameraDeviceHandler\EventHandlers\DeviceArrival\VideoCameraArrival
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E088CBDAD19008440B610E1D7A3A41E8
0D00C83EB86A81348A6A7F4D5B1BFDE0
C:\Program Files\Windows Media Components\Encoder\wmeditor.exe
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D261F554DF1D5014783A055023B55FCB
0D00C83EB86A81348A6A7F4D5B1BFDE0
C:\Program Files\Windows Media Components\Encoder\WMEncAgt.exe
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F659B66A0B904B742A7B58F105FA015D
0D00C83EB86A81348A6A7F4D5B1BFDE0
C:\Program Files\Windows Media Components\Encoder\wmencloc.dll
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0F462311AA23FC944B9693A55B2B5784
0D00C83EB86A81348A6A7F4D5B1BFDE0
C:\Program Files\Windows Media Components\Encoder\WMProEdt.exe
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9C1A738FFA2A01B4D9ED521932802179
0D00C83EB86A81348A6A7F4D5B1BFDE0
C:\Program Files\Windows Media Components\Encoder\wmencres.dll
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A5C5565FFA40B0428942267B7170855
0D00C83EB86A81348A6A7F4D5B1BFDE0
C:\Program Files\Windows Media Components\Encoder\wmstreamedt.exe
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B5BEBBBEF304D234DB5F9F88C3780EBF
0D00C83EB86A81348A6A7F4D5B1BFDE0
C:\Program Files\Windows Media Components\Encoder\dw15.exe
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1EE1D968779E26849B4BD8D57A9C701C
0D00C83EB86A81348A6A7F4D5B1BFDE0
C:\Program Files\Windows Media Components\Encoder\1033\dwintl.dll
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E2F85F09943114141AE94CAFC500D2DB
0D00C83EB86A81348A6A7F4D5B1BFDE0
C:\Program Files\Windows Media Components\Encoder\Profiles\schi.prx
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6C8E136052682884188DCF5AB0BFB9E3
0D00C83EB86A81348A6A7F4D5B1BFDE0
C:\Program Files\Windows Media Components\Encoder\Templates\CaptureLocal.wme
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\15C77334179103140A96E3146C99C999
0D00C83EB86A81348A6A7F4D5B1BFDE0
C:\Program Files\Windows Media Components\Encoder\Settings\d0_cbr_audio_cd.prx
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1170724443B75AD43B5066749287A578
0D00C83EB86A81348A6A7F4D5B1BFDE0
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
C:\Windows\system32\declrds.ax
1
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E148D06ED6DE2A439745B2459FC7FBE
0D00C83EB86A81348A6A7F4D5B1BFDE0
C?\Windows\system32\declrds.ax
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\Windows Media Components\Encoder\1033\
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\Windows Media Components\Encoder\Templates\
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Program Files\Windows Media Components\Encoder\Settings\
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Windows\Installer\{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}\
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media\
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media\Utilities\
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WindowsMedia.prx\shell\Open\command
"C:\Program Files\Windows Media Components\Encoder\WMProEdt.exe" "%1"
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WindowsMedia.prx\shell\Open\command
command
j~C.rad~W9Dq%Nm!WDk'>lvlT(t2If?*[email protected]? "%1"
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.prx
WindowsMedia.prx
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WMEncSession\shell\Open\command
"C:\Program Files\Windows Media Components\Encoder\wmenc.exe" "%1"
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WMEncSession\shell\Open\command
command
j~C.rad~W9Dq%Nm!WDk'>PSTS,.{-!AyLl.)qa(~` "%1"
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.wme
WMEncSession
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media\Encoder
Version
9.00.2980
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media\Encoder
InstallDir
C:\Program Files\Windows Media Components\Encoder\
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media\Encoder\9.0\Registration\ProductID
69542-846-6335335-04896
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media\MsiInstall
WMEncoder
Yes
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\wmenc.exe
Path
C:\Program Files\Windows Media Components\Encoder\
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\wmenc.exe
C:\Program Files\Windows Media Components\Encoder\WMEnc.exe
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\EventHandlers\VideoCameraArrival
MSWMEncVCArrival
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSWMEncVCArrival
DefaultIcon
C:\Program Files\Windows Media Components\Encoder\WMEnc.exe,-128
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSWMEncVCArrival
InitCmdLine
C:\Program Files\Windows Media Components\Encoder\WMEnc.exe
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSWMEncVCArrival
Provider
Windows Media Encoder 9 Series
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSWMEncVCArrival
Action
Start Encoding
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSWMEncVCArrival
ProgID
Shell.HWEventHandlerShellExecute
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.prx\OpenWithList\WMProEdt.exe
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.wme\OpenWithList\wmenc.exe
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WindowsMedia.prx
FriendlyTypeName
@C:\Program Files\Windows Media Components\Encoder\WMExres.dll,-14218
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WindowsMedia.prx\DefaultIcon
C:\Program Files\Windows Media Components\Encoder\WMProEdt.exe,-101
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WMEncSession
FriendlyTypeName
@C:\Program Files\Windows Media Components\Encoder\WMEncres.dll,-110
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WMEncSession\DefaultIcon
C:\Program Files\Windows Media Components\Encoder\WMEnc.exe,-128
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\Windows Media Encoder
EventMessageFile
C:\Program Files\Windows Media Components\Encoder\dw15.exe
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\eventlog\Application\Windows Media Encoder
TypesSupported
7
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Media Encoder 9
DisplayName
Windows Media Encoder 9 Series
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Media Encoder 9
DisplayIcon
C:\Program Files\Windows Media Components\Encoder\WMEnc.exe
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Media Encoder 9
UninstallString
msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\DeviceHandlers\VideoCameraDeviceHandler\EventHandlers\DeviceArrival
VideoCameraArrival
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0\InstallProperties
RegOwner
admin
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0\InstallProperties
RegCompany
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0\InstallProperties
ProductID
69542-846-6335335-04896
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0\InstallProperties
LocalPackage
C:\Windows\Installer\19391f.msi
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0\InstallProperties
AuthorizedCDFPrefix
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0\InstallProperties
Comments
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0\InstallProperties
Contact
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0\InstallProperties
DisplayVersion
9.00.2980
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0\InstallProperties
HelpLink
http://go.microsoft.com/fwlink/?LinkId=9647
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0\InstallProperties
HelpTelephone
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0\InstallProperties
InstallDate
20191009
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0\InstallProperties
InstallLocation
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0\InstallProperties
InstallSource
C:\Windows\Installer\
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0\InstallProperties
ModifyPath
MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0\InstallProperties
Publisher
Microsoft Corporation
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0\InstallProperties
Readme
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0\InstallProperties
Size
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0\InstallProperties
EstimatedSize
13910
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0\InstallProperties
SystemComponent
1
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0\InstallProperties
UninstallString
MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0\InstallProperties
URLInfoAbout
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0\InstallProperties
URLUpdateInfo
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0\InstallProperties
VersionMajor
9
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0\InstallProperties
VersionMinor
0
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0\InstallProperties
WindowsInstaller
1
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0\InstallProperties
Version
150997924
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0\InstallProperties
Language
1033
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
AuthorizedCDFPrefix
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
Comments
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
Contact
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
DisplayVersion
9.00.2980
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
HelpLink
http://go.microsoft.com/fwlink/?LinkId=9647
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
HelpTelephone
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
InstallDate
20191009
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
InstallLocation
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
InstallSource
C:\Windows\Installer\
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
ModifyPath
MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
Publisher
Microsoft Corporation
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
Readme
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
Size
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
EstimatedSize
13910
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
SystemComponent
1
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
UninstallString
MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
URLInfoAbout
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
URLUpdateInfo
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
VersionMajor
9
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
VersionMinor
0
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
WindowsInstaller
1
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
Version
150997924
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
Language
1033
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\FDD81D5A32E908540B77388732EA531C
0D00C83EB86A81348A6A7F4D5B1BFDE0
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0\InstallProperties
DisplayName
Windows Media Encoder 9 Series
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
DisplayName
Windows Media Encoder 9 Series
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\0D00C83EB86A81348A6A7F4D5B1BFDE0
WMEncoder
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0\Features
WMEncoder
PSTS,.{-!AyLl.)qa(~`6H4FmDto?AD,{Z`QP.{'9*l=IGewZ8(w^'lFPg7)[U9IJ3E'6Ah(BEUBtMTM1iSx.vuUz=meT+NRiYAbXZY-kT=[email protected]*rs4.`?~XcM&s&DZ`[email protected]{8?^gE*R?`6=6w'km$hqxe)4'o-`AENzPF`UuWyK{BIkKUgl=K5lZS%Tn&iInRfPxP=(?Ic{0g1l$cIgcz}BioGZ?'})-Z6%xza4&6*zrICT=j5u)N%7mpN5PBN5X1zn?ybV!4uZMVwAqF!+xan5?`oPZ?q2y6mhN_+Rc([email protected],M8p.p~MLj9ydSC=*[email protected]`iYE$=LmWNll=QaUfn0A==cEu8S}4e$iQ.ge?OKQ^.[q&?~41.-dwdPmlvlT(t2If?*[email protected]?ov$kx&[email protected][s?`VRX)[email protected]{[email protected]*nPCmP~itnW4Z9_g&%Tt8!zyLJR=S0pS=?'8k(Fc+H&gma-ZV]2b{8!~dZyp7)meeE8~$IYtA?{}ZE^[email protected][9z3ry8]$I{[email protected]=VxdRS)lc-GVeZp?PDIM9rgHpt
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0\Patches
AllPatches
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0
ProductName
Windows Media Encoder 9 Series
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0
PackageCode
CD3F63C514B87CB4BAF81D5D62B42891
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0
Language
1033
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0
Version
150997924
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0
Assignment
1
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0
AdvertiseFlags
388
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0
ProductIcon
C:\Windows\Installer\{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}\ARPIcon
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0
InstanceType
0
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0
AuthorizedLUAApp
0
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0
DeploymentFlags
3
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\FDD81D5A32E908540B77388732EA531C
0D00C83EB86A81348A6A7F4D5B1BFDE0
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0\SourceList
PackageName
WMEncoder.msi
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0\SourceList\Net
1
C:\Windows\Installer\
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0\SourceList\Media
1
;
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0
Clients
:
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\0D00C83EB86A81348A6A7F4D5B1BFDE0\SourceList
LastUsedSource
n;1;C:\Windows\Installer\
3064
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings
StringCacheGeneration
116
3064
msiexec.exe
delete key
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\73\52C64B7E
3064
msiexec.exe
delete key
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\73
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
IDENTIFY (Enter)
400000000000000080ACE286AA7ED501540C000048080000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
IDENTIFY (Enter)
400000000000000080ACE286AA7ED501540C0000800D0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
IDENTIFY (Enter)
400000000000000080ACE286AA7ED501540C0000F00B0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
IDENTIFY (Enter)
400000000000000080ACE286AA7ED501540C000030080000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
IDENTIFY (Leave)
40000000000000003471E786AA7ED501540C000048080000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
IDENTIFY (Leave)
40000000000000008ED3E986AA7ED501540C0000800D0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
IDENTIFY (Leave)
4000000000000000E835EC86AA7ED501540C000030080000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
IDENTIFY (Leave)
40000000000000004298EE86AA7ED501540C0000F00B0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_BEGINPREPARE (Enter)
400000000000000068AD7A8DAA7ED501540C0000F00B000001040000010000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_BEGINPREPARE (Leave)
400000000000000068AD7A8DAA7ED501540C0000F00B000001040000000000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPAREBACKUP (Enter)
40000000000000001C727F8DAA7ED501540C000030080000E9030000010000000100000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPAREBACKUP (Enter)
40000000000000001C727F8DAA7ED501540C0000F00B0000E9030000010000000100000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPAREBACKUP (Enter)
40000000000000001C727F8DAA7ED501540C0000800D0000E9030000010000000100000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPAREBACKUP (Leave)
400000000000000076D4818DAA7ED501540C0000800D0000E9030000000000000100000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_STABLE (SetCurrentState)
400000000000000076D4818DAA7ED501540C0000800D000001000000010000000100000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPAREBACKUP (Leave)
400000000000000076D4818DAA7ED501540C000030080000E9030000000000000100000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_STABLE (SetCurrentState)
400000000000000076D4818DAA7ED501540C00003008000001000000010000000100000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPAREBACKUP (Leave)
400000000000000076D4818DAA7ED501540C0000F00B0000E9030000000000000100000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_STABLE (SetCurrentState)
400000000000000076D4818DAA7ED501540C0000F00B000001000000010000000100000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
GETSTATE (Enter)
4000000000000000AE709E8DAA7ED501540C0000F00B0000F9030000010000000100000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
GETSTATE (Enter)
4000000000000000AE709E8DAA7ED501540C000030080000F9030000010000000100000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
GETSTATE (Enter)
4000000000000000AE709E8DAA7ED501540C0000800D0000F9030000010000000100000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
GETSTATE (Leave)
4000000000000000AE709E8DAA7ED501540C000030080000F9030000000000000100000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
GETSTATE (Leave)
4000000000000000AE709E8DAA7ED501540C0000F00B0000F9030000000000000100000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
GETSTATE (Leave)
4000000000000000AE709E8DAA7ED501540C0000800D0000F9030000000000000100000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_ENDPREPARE (Enter)
40000000000000006235A38DAA7ED501540C00008C09000002040000010000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_ENDPREPARE (Leave)
4000000000000000347F0E8EAA7ED501540C00008C09000002040000000000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
PREPARESNAPSHOT (Enter)
40000000000000008EE1108EAA7ED501540C00008C090000EA030000010000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPARESNAPSHOT (Enter)
40000000000000009C08188EAA7ED501540C0000AC050000EA030000010000000100000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPARESNAPSHOT (Enter)
40000000000000009C08188EAA7ED501540C0000B0030000EA030000010000000100000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPARESNAPSHOT (Enter)
40000000000000009C08188EAA7ED501540C00001C070000EA030000010000000100000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPARESNAPSHOT (Leave)
4000000000000000C67D2D8EAA7ED501540C0000AC050000EA030000000000000100000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)
4000000000000000C67D2D8EAA7ED501540C0000AC05000002000000010000000100000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPARESNAPSHOT (Leave)
4000000000000000C67D2D8EAA7ED501540C00001C070000EA030000000000000100000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)
4000000000000000C67D2D8EAA7ED501540C00001C07000002000000010000000100000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPARESNAPSHOT (Leave)
400000000000000020E02F8EAA7ED501540C0000B0030000EA030000000000000100000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)
400000000000000020E02F8EAA7ED501540C0000B003000002000000010000000100000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
PREPARESNAPSHOT (Leave)
400000000000000074CA5A8EAA7ED501540C00008C090000EA030000000000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE (Enter)
400000000000000074CA5A8EAA7ED501540C00008C090000EB030000010000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_FRONT (Enter)
400000000000000074CA5A8EAA7ED501540C00008C090000EC030000010000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
FREEZE (Enter)
4000000000000000288F5F8EAA7ED501540C00007C080000EB030000010000000200000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
FREEZE (Leave)
4000000000000000288F5F8EAA7ED501540C00007C080000EB030000000000000200000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_WAITING_FOR_THAW (SetCurrentState)
4000000000000000288F5F8EAA7ED501540C00007C08000003000000010000000200000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
BKGND_FREEZE_THREAD (Enter)
4000000000000000288F5F8EAA7ED501540C000094090000FC030000010000000300000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_FRONT (Leave)
400000000000000082F1618EAA7ED501540C00008C090000EC030000000000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_BACK (Enter)
400000000000000082F1618EAA7ED501540C00008C090000ED030000010000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_BACK (Leave)
4000000000000000DC53648EAA7ED501540C00008C090000ED030000000000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_SYSTEM (Enter)
4000000000000000DC53648EAA7ED501540C00008C090000EE030000010000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
FREEZE (Enter)
400000000000000036B6668EAA7ED501540C00007C080000EB030000010000000200000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
FREEZE (Leave)
400000000000000036B6668EAA7ED501540C00007C080000EB030000000000000200000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_WAITING_FOR_THAW (SetCurrentState)
400000000000000036B6668EAA7ED501540C00007C08000003000000010000000200000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
BKGND_FREEZE_THREAD (Enter)
400000000000000036B6668EAA7ED501540C00006C030000FC030000010000000300000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_SYSTEM (Leave)
4000000000000000EA7A6B8EAA7ED501540C00008C090000EE030000000000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_KTM (Enter)
4000000000000000EA7A6B8EAA7ED501540C00008C090000F0030000010000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_KTM (Leave)
4000000000000000EA7A6B8EAA7ED501540C00008C090000F0030000000000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_RM (Enter)
4000000000000000EA7A6B8EAA7ED501540C00008C090000EF030000010000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
FREEZE (Enter)
40000000000000009E3F708EAA7ED501540C00001C070000EB030000010000000200000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
FREEZE (Leave)
4000000000000000F8A1728EAA7ED501540C00001C070000EB030000000000000200000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_WAITING_FOR_THAW (SetCurrentState)
4000000000000000F8A1728EAA7ED501540C00001C07000003000000010000000200000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
BKGND_FREEZE_THREAD (Enter)
4000000000000000F8A1728EAA7ED501540C00009C0A0000FC030000010000000300000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_RM (Leave)
4000000000000000F8A1728EAA7ED501540C00008C090000EF030000000000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE (Leave)
4000000000000000F8A1728EAA7ED501540C00008C090000EB030000000000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_PRECOMMIT (Enter)
4000000000000000F8A1728EAA7ED501540C00008C09000003040000010000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_PRECOMMIT (Leave)
4000000000000000F8A1728EAA7ED501540C00008C09000003040000000000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
OPEN_VOLUME_HANDLE (Enter)
4000000000000000F8A1728EAA7ED501540C00008C090000FD030000010000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
OPEN_VOLUME_HANDLE (Enter)
4000000000000000F8A1728EAA7ED501540C0000980A0000FD030000010000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
OPEN_VOLUME_HANDLE (Leave)
4000000000000000602B7C8EAA7ED501540C0000980A0000FD030000000000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
OPEN_VOLUME_HANDLE (Leave)
4000000000000000602B7C8EAA7ED501540C00008C090000FD030000000000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
IOCTL_FLUSH_AND_HOLD (Enter)
4000000000000000602B7C8EAA7ED501540C0000980A0000FE030000010000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
IOCTL_FLUSH_AND_HOLD (Leave)
40000000000000006E52838EAA7ED501540C0000980A0000FE030000000000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
IOCTL_RELEASE (Enter)
40000000000000006E52838EAA7ED501540C0000980A0000FF030000010000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
IOCTL_RELEASE (Leave)
40000000000000006E52838EAA7ED501540C0000980A0000FF030000000000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
IOCTL_FLUSH_AND_HOLD (Enter)
4000000000000000602B7C8EAA7ED501540C00008C090000FE030000010000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
IOCTL_FLUSH_AND_HOLD (Leave)
40000000000000006E52838EAA7ED501540C00008C090000FE030000000000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
IOCTL_RELEASE (Enter)
40000000000000006E52838EAA7ED501540C00008C090000FF030000010000000000000000000000000000000000000000000000000000000000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
IOCTL_RELEASE (Leave)
40000000000000006E52838EAA7ED501540C00008C090000FF030000000000000000000000000000000000000000000000000000000000000000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_COMMIT (Enter)
40000000000000006E52838EAA7ED501540C0000A00A000004040000010000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_COMMIT (Leave)
40000000000000006E52838EAA7ED501540C0000A00A000004040000000000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_POSTCOMMIT (Enter)
40000000000000006E52838EAA7ED501540C00008C09000005040000010000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_POSTCOMMIT (Leave)
4000000000000000C8B4858EAA7ED501540C00008C09000005040000000000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
THAW_KTM (Enter)
4000000000000000C8B4858EAA7ED501540C00008C090000F4030000010000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
THAW_KTM (Leave)
4000000000000000C8B4858EAA7ED501540C00008C090000F4030000000000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
THAW (Enter)
4000000000000000C8B4858EAA7ED501540C00008C090000F2030000010000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
THAW (Enter)
40000000000000007C798A8EAA7ED501540C0000B0030000F2030000010000000300000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
THAW (Enter)
40000000000000007C798A8EAA7ED501540C0000AC050000F2030000010000000300000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
BKGND_FREEZE_THREAD (Leave)
40000000000000007C798A8EAA7ED501540C00006C030000FC030000000000000300000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
THAW (Enter)
40000000000000007C798A8EAA7ED501540C000098090000F2030000010000000300000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
BKGND_FREEZE_THREAD (Leave)
40000000000000007C798A8EAA7ED501540C000094090000FC030000000000000300000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
THAW (Leave)
40000000000000007C798A8EAA7ED501540C0000B0030000F2030000000000000300000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
THAW (Leave)
40000000000000007C798A8EAA7ED501540C0000AC050000F2030000000000000300000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
BKGND_FREEZE_THREAD (Leave)
40000000000000007C798A8EAA7ED501540C00009C0A0000FC030000000000000300000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_WAITING_FOR_POST_SNAPSHOT (SetCurrentState)
40000000000000007C798A8EAA7ED501540C0000B003000004000000010000000300000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_WAITING_FOR_POST_SNAPSHOT (SetCurrentState)
40000000000000007C798A8EAA7ED501540C0000AC05000004000000010000000300000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
THAW (Leave)
40000000000000007C798A8EAA7ED501540C000098090000F2030000000000000300000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_WAITING_FOR_POST_SNAPSHOT (SetCurrentState)
40000000000000007C798A8EAA7ED501540C00009809000004000000010000000300000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
THAW (Leave)
40000000000000007C798A8EAA7ED501540C00008C090000F2030000000000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_PREFINALCOMMIT (Enter)
40000000000000007C798A8EAA7ED501540C00008C09000006040000010000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_PREFINALCOMMIT (Leave)
4000000000000000543BCD8EAA7ED501540C00008C09000006040000000000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
POSTSNAPSHOT (Enter)
4000000000000000543BCD8EAA7ED501540C00008C090000F5030000010000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
POSTSNAPSHOT (Enter)
40000000000000000800D28EAA7ED501540C000098090000F5030000010000000400000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
POSTSNAPSHOT (Enter)
40000000000000000800D28EAA7ED501540C00001C070000F5030000010000000400000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
POSTSNAPSHOT (Enter)
40000000000000000800D28EAA7ED501540C0000AC050000F5030000010000000400000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
POSTSNAPSHOT (Leave)
40000000000000006262D48EAA7ED501540C00001C070000F5030000000000000400000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_WAITING_FOR_BACKUP_COMPLETE (SetCurrentState)
40000000000000006262D48EAA7ED501540C00001C07000005000000010000000400000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
POSTSNAPSHOT (Leave)
40000000000000006262D48EAA7ED501540C000098090000F5030000000000000400000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_WAITING_FOR_BACKUP_COMPLETE (SetCurrentState)
40000000000000006262D48EAA7ED501540C00009809000005000000010000000400000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
POSTSNAPSHOT (Leave)
400000000000000066D0848FAA7ED501540C0000AC050000F5030000000000000400000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_WAITING_FOR_BACKUP_COMPLETE (SetCurrentState)
400000000000000066D0848FAA7ED501540C0000AC05000005000000010000000400000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
POSTSNAPSHOT (Leave)
400000000000000066D0848FAA7ED501540C00008C090000F5030000000000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_POSTFINALCOMMIT (Enter)
400000000000000066D0848FAA7ED501540C00008C09000007040000010000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_POSTFINALCOMMIT (Leave)
400000000000000090459A8FAA7ED501540C00008C09000007040000000000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
BACKUPSHUTDOWN (Enter)
4000000000000000141DB28FAA7ED501540C00008C090000FB030000010000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
BACKUPSHUTDOWN (Enter)
4000000000000000C8E1B68FAA7ED501540C0000B0030000FB030000010000000500000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
BACKUPSHUTDOWN (Leave)
4000000000000000C8E1B68FAA7ED501540C0000B0030000FB030000000000000500000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
BACKUPSHUTDOWN (Enter)
4000000000000000C8E1B68FAA7ED501540C0000B0030000FB030000010000000500000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
BACKUPSHUTDOWN (Leave)
4000000000000000C8E1B68FAA7ED501540C0000B0030000FB030000000000000500000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
BACKUPSHUTDOWN (Enter)
4000000000000000C8E1B68FAA7ED501540C0000AC050000FB030000010000000500000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
BACKUPSHUTDOWN (Leave)
4000000000000000C8E1B68FAA7ED501540C0000AC050000FB030000000000000500000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
BACKUPSHUTDOWN (Leave)
4000000000000000C8E1B68FAA7ED501540C00008C090000FB030000000000000000000000000000DB4CA3780E6F57439C4F88E90E003A630000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
IDENTIFY (Enter)
4000000000000000A4C56E95AA7ED501540C00004C080000E8030000010000000500000000000000000000000000000000000000000000000000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
IDENTIFY (Enter)
4000000000000000A4C56E95AA7ED501540C000048080000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
IDENTIFY (Enter)
4000000000000000A4C56E95AA7ED501540C0000800D0000E8030000010000000500000000000000000000000000000000000000000000000000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
IDENTIFY (Enter)
4000000000000000A4C56E95AA7ED501540C0000F00B0000E8030000010000000500000000000000000000000000000000000000000000000000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
IDENTIFY (Leave)
400000000000000066B17A95AA7ED501540C0000F00B0000E8030000000000000500000000000000000000000000000000000000000000000000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
IDENTIFY (Leave)
400000000000000066B17A95AA7ED501540C00004C080000E8030000000000000500000000000000000000000000000000000000000000000000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
IDENTIFY (Leave)
4000000000000000C0137D95AA7ED501540C000048080000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
IDENTIFY (Leave)
400000000000000074D88195AA7ED501540C0000800D0000E8030000000000000500000000000000000000000000000000000000000000000000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_BEGINPREPARE (Enter)
4000000000000000D2892A9CAA7ED501540C0000800D000001040000010000000000000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_BEGINPREPARE (Leave)
4000000000000000D2892A9CAA7ED501540C0000800D000001040000000000000000000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPAREBACKUP (Enter)
4000000000000000E0B0319CAA7ED501540C000048080000E9030000010000000500000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPAREBACKUP (Enter)
4000000000000000E0B0319CAA7ED501540C0000800D0000E9030000010000000500000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPAREBACKUP (Enter)
4000000000000000E0B0319CAA7ED501540C00004C080000E9030000010000000500000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPAREBACKUP (Leave)
4000000000000000A29C3D9CAA7ED501540C0000800D0000E9030000000000000100000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_STABLE (SetCurrentState)
4000000000000000A29C3D9CAA7ED501540C0000800D000001000000010000000100000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPAREBACKUP (Leave)
4000000000000000FCFE3F9CAA7ED501540C00004C080000E9030000000000000100000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_STABLE (SetCurrentState)
4000000000000000FCFE3F9CAA7ED501540C00004C08000001000000010000000100000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPAREBACKUP (Leave)
4000000000000000FCFE3F9CAA7ED501540C000048080000E9030000000000000100000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_STABLE (SetCurrentState)
4000000000000000FCFE3F9CAA7ED501540C00004808000001000000010000000100000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
GETSTATE (Enter)
40000000000000008EFD5E9CAA7ED501540C000048080000F9030000010000000100000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
GETSTATE (Enter)
40000000000000008EFD5E9CAA7ED501540C0000800D0000F9030000010000000100000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
GETSTATE (Enter)
40000000000000008EFD5E9CAA7ED501540C0000F00B0000F9030000010000000100000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
GETSTATE (Leave)
40000000000000008EFD5E9CAA7ED501540C0000F00B0000F9030000000000000100000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
GETSTATE (Leave)
4000000000000000E85F619CAA7ED501540C000048080000F9030000000000000100000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
GETSTATE (Leave)
4000000000000000E85F619CAA7ED501540C0000800D0000F9030000000000000100000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_ENDPREPARE (Enter)
4000000000000000F686689CAA7ED501540C0000D009000002040000010000000000000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_ENDPREPARE (Leave)
40000000000000003E81E49CAA7ED501540C0000D009000002040000000000000000000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
PREPARESNAPSHOT (Enter)
40000000000000003E81E49CAA7ED501540C0000D0090000EA030000010000000000000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPARESNAPSHOT (Enter)
40000000000000004CA8EB9CAA7ED501540C0000B0030000EA030000010000000100000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPARESNAPSHOT (Enter)
40000000000000004CA8EB9CAA7ED501540C00007C080000EA030000010000000100000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPARESNAPSHOT (Enter)
40000000000000004CA8EB9CAA7ED501540C0000AC050000EA030000010000000100000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPARESNAPSHOT (Leave)
4000000000000000ECCD119DAA7ED501540C0000AC050000EA030000000000000100000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)
4000000000000000ECCD119DAA7ED501540C0000AC05000002000000010000000100000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPARESNAPSHOT (Leave)
4000000000000000ECCD119DAA7ED501540C0000B0030000EA030000000000000100000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)
4000000000000000ECCD119DAA7ED501540C0000B003000002000000010000000100000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPARESNAPSHOT (Leave)
4000000000000000ECCD119DAA7ED501540C00007C080000EA030000000000000100000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)
4000000000000000ECCD119DAA7ED501540C00007C08000002000000010000000100000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
PREPARESNAPSHOT (Leave)
40000000000000009A1A3F9DAA7ED501540C0000D0090000EA030000000000000000000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE (Enter)
40000000000000009A1A3F9DAA7ED501540C0000D0090000EB030000010000000000000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_FRONT (Enter)
40000000000000009A1A3F9DAA7ED501540C0000D0090000EC030000010000000000000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
FREEZE (Enter)
4000000000000000F47C419DAA7ED501540C00007C080000EB030000010000000200000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
FREEZE (Leave)
4000000000000000F47C419DAA7ED501540C00007C080000EB030000000000000200000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_WAITING_FOR_THAW (SetCurrentState)
4000000000000000F47C419DAA7ED501540C00007C08000003000000010000000200000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
BKGND_FREEZE_THREAD (Enter)
40000000000000004EDF439DAA7ED501540C000064020000FC030000010000000300000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_FRONT (Leave)
400000000000000002A4489DAA7ED501540C0000D0090000EC030000000000000000000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_BACK (Enter)
400000000000000002A4489DAA7ED501540C0000D0090000ED030000010000000000000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_BACK (Leave)
40000000000000005C064B9DAA7ED501540C0000D0090000ED030000000000000000000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_SYSTEM (Enter)
40000000000000005C064B9DAA7ED501540C0000D0090000EE030000010000000000000000000000BF03844635D67640A6A2B66215AAA5780000000000000000
3156
vssvc.exe
write