General Info

File name

PVPubgVIP8.2 (di' cu~).EXE

Full analysis
https://app.any.run/tasks/5b8f1650-2252-4c2d-80fc-e669eaaac6e2
Verdict
Malicious activity
Analysis date
8/13/2019, 18:02:44
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows
MD5

e065d23e2d11ba7aebf58ebdb5a14931

SHA1

2a1d0fcc1e16dca61653b9d32d6866da8d3dd004

SHA256

3847f998dc005f1f2e6608e4aaa694a334e9d935ee2927fb5c6bd29f3c6c8cd2

SSDEEP

98304:8ElmoNGP6aNPFFja43VcbIeJn+ZBd+PUbwrDsuT7pHNvK3zAHIytB0:Nlmo4P6aNjja43YIxBd+PNjxNvK3di

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
120 seconds
Additional time used
60 seconds
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (75.0.3770.100)
  • Google Update Helper (1.3.34.7)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.7.2 (4.7.03062)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 (14.21.27702.2)
  • Microsoft Visual C++ 2019 X86 Additional Runtime - 14.21.27702 (14.21.27702)
  • Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.21.27702 (14.21.27702)
  • Mozilla Firefox 68.0.1 (x86 en-US) (68.0.1)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • Update for Microsoft .NET Framework 4.7.2 (KB4087364) (1)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB4019990
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Application was dropped or rewritten from another process
  • install.exe (PID: 3368)
  • 453BE91F.EXE (PID: 1480)
  • VC2008.EXE (PID: 360)
Loads dropped or rewritten executable
  • install.exe (PID: 3368)
Changes settings of System certificates
  • 453BE91F.EXE (PID: 1480)
Creates files in the Windows directory
  • msiexec.exe (PID: 3420)
Removes files from Windows directory
  • msiexec.exe (PID: 3420)
Executable content was dropped or overwritten
  • VC2008.EXE (PID: 360)
  • msiexec.exe (PID: 3420)
  • PVPubgVIP8.2 (di' cu~).EXE (PID: 2944)
  • 453BE91F.EXE (PID: 1480)
  • 4E8EDF95.EXE (PID: 2580)
Adds / modifies Windows certificates
  • 453BE91F.EXE (PID: 1480)
Starts itself from another location
  • PVPubgVIP8.2 (di' cu~).EXE (PID: 2944)
Creates a software uninstall entry
  • msiexec.exe (PID: 3420)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.dll
|   Win32 Dynamic Link Library (generic) (43.5%)
.exe
|   Win32 Executable (generic) (29.8%)
.exe
|   Generic Win/DOS Executable (13.2%)
.exe
|   DOS Executable Generic (13.2%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2019:07:29 09:58:45+02:00
PEType:
PE32
LinkerVersion:
6
CodeSize:
348160
InitializedDataSize:
2703360
UninitializedDataSize:
null
EntryPoint:
0x739000
OSVersion:
4
ImageVersion:
1
SubsystemVersion:
4
Subsystem:
Windows GUI
FileVersionNumber:
1.0.0.0
ProductVersionNumber:
1.0.0.0
FileFlagsMask:
0x0000
FileFlags:
(none)
FileOS:
Win32
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
English (U.S.)
CharacterSet:
Unicode
Comments:
Microsoft Coporation
CompanyName:
Microsoft Coporation
FileDescription:
Microsoft Coporation
ProductName:
Microsoft Coporation
FileVersion:
1
ProductVersion:
1
InternalName:
PV LOADER
OriginalFileName:
PV LOADER.EXE
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
29-Jul-2019 07:58:45
Detected languages
English - United States
Comments:
Microsoft Coporation
CompanyName:
Microsoft Coporation
FileDescription:
Microsoft Coporation
ProductName:
Microsoft Coporation
FileVersion:
1.00
ProductVersion:
1.00
InternalName:
PV LOADER
OriginalFilename:
PV LOADER.EXE
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x000000C8
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
7
Time date stamp:
29-Jul-2019 07:58:45
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
0x00001000 0x00058000 0x00010000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 7.88235
.rsrc 0x00059000 0x0029296C 0x00286000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 7.9821
.idata 0x002EC000 0x00001000 0x00001000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0.175446
0x002ED000 0x00296000 0x00001000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0.0407044
govzcxjp 0x00583000 0x001B5000 0x001B5000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 7.84915
daalxhbn 0x00738000 0x00001000 0x00001000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 7.73639
.taggant 0x00739000 0x00003000 0x00003000 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 0.553943
Resources
1

101

30001

30002

30003

30004

30005

30006

30007

30008

30009

30010

30011

30012

Imports
    kernel32.dll

Exports

    No exports.

Screenshots

Processes

Total processes
44
Monitored processes
7
Malicious processes
1
Suspicious processes
1

Behavior graph

+
drop and start start drop and start drop and start drop and start pvpubgvip8.2 (di' cu~).exe no specs pvpubgvip8.2 (di' cu~).exe 4e8edf95.exe 453be91f.exe vc2008.exe install.exe no specs msiexec.exe
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
2252
CMD
"C:\Users\admin\AppData\Local\Temp\PVPubgVIP8.2 (di' cu~).EXE"
Path
C:\Users\admin\AppData\Local\Temp\PVPubgVIP8.2 (di' cu~).EXE
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
Microsoft Coporation
Description
Microsoft Coporation
Version
1.00
Modules
Image
c:\users\admin\appdata\local\temp\pvpubgvip8.2 (di' cu~).exe

PID
2944
CMD
"C:\Users\admin\AppData\Local\Temp\PVPubgVIP8.2 (di' cu~).EXE"
Path
C:\Users\admin\AppData\Local\Temp\PVPubgVIP8.2 (di' cu~).EXE
Indicators
Parent process
––
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Coporation
Description
Microsoft Coporation
Version
1.00
Modules
Image
c:\users\admin\appdata\local\temp\pvpubgvip8.2 (di' cu~).exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sxs.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\wbem\wbemdisp.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbem\wmiutils.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\scrrun.dll
c:\windows\system32\version.dll
c:\windows\system32\propsys.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\sspicli.dll
c:\users\admin\appdata\local\temp\4e8edf95.exe

PID
2580
CMD
"C:\Users\admin\AppData\Local\Temp\4E8EDF95.EXE" C:\Users\admin\AppData\Local\Temp\PVPubgVIP8.2 (di' cu~).EXE
Path
C:\Users\admin\AppData\Local\Temp\4E8EDF95.EXE
Indicators
Parent process
PVPubgVIP8.2 (di' cu~).EXE
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Coporation
Description
Microsoft Coporation
Version
1.00
Modules
Image
c:\users\admin\appdata\local\temp\4e8edf95.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sxs.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\wbem\wbemdisp.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbem\wmiutils.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\scrrun.dll
c:\windows\system32\version.dll
c:\windows\system32\propsys.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\profapi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\users\admin\appdata\local\temp\453be91f.exe

PID
1480
CMD
"C:\Users\admin\AppData\Local\Temp\453BE91F.EXE"
Path
C:\Users\admin\AppData\Local\Temp\453BE91F.EXE
Indicators
Parent process
4E8EDF95.EXE
User
admin
Integrity Level
HIGH
Version:
Company
Microsoft Coporation
Description
Microsoft Coporation
Version
1.00
Modules
Image
c:\users\admin\appdata\local\temp\453be91f.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\winmm.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\d3d9.dll
c:\windows\system32\version.dll
c:\windows\system32\d3d8thk.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\imagehlp.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\sxs.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\psapi.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\iertutil.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\wbem\wbemdisp.dll
c:\windows\system32\wbemcomn.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\wbem\wbemprox.dll
c:\windows\system32\wbem\wmiutils.dll
c:\windows\system32\wbem\wbemsvc.dll
c:\windows\system32\wbem\fastprox.dll
c:\windows\system32\ntdsapi.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\scrrun.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\profapi.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\userenv.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\schannel.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\credssp.dll
c:\windows\system32\secur32.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll
c:\windows\system32\apphelp.dll
c:\users\admin\appdata\local\temp\lib\vc2008.exe

PID
360
CMD
C:\Users\admin\AppData\Local\Temp\LIB\VC2008.EXE /Q
Path
C:\Users\admin\AppData\Local\Temp\LIB\VC2008.EXE
Indicators
Parent process
453BE91F.EXE
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
Microsoft Visual C++ 2008 Redistributable Setup
Version
9.0.30729.17
Modules
Image
c:\users\admin\appdata\local\temp\lib\vc2008.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ole32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\clusapi.dll
c:\windows\system32\cryptdll.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\feclient.dll
c:\windows\system32\apphelp.dll
c:\a64949a19f6d1a42e24d09b2a3d844\install.exe

PID
3368
CMD
c:\a64949a19f6d1a42e24d09b2a3d844\.\install.exe /Q
Path
c:\a64949a19f6d1a42e24d09b2a3d844\install.exe
Indicators
No indicators
Parent process
VC2008.EXE
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
External Installer
Version
9.0.30729.1 built by: SP
Modules
Image
c:\a64949a19f6d1a42e24d09b2a3d844\install.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ole32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\devobj.dll
c:\a64949a19f6d1a42e24d09b2a3d844\install.res.1033.dll
c:\windows\system32\version.dll
c:\program files\mozilla firefox\updater.exe
c:\windows\system32\secur32.dll
c:\windows\system32\msi.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\msimsg.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\rpcrtremote.dll

PID
3420
CMD
C:\Windows\system32\msiexec.exe /V
Path
C:\Windows\system32\msiexec.exe
Indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Windows® installer
Version
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\msiexec.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msi.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shell32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\winspool.drv
c:\windows\system32\mpr.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\version.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\msimsg.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msisip.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\winsta.dll
c:\windows\system32\sxs.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v4.0.30319\clr.dll
c:\windows\microsoft.net\framework\v4.0.30319\fusion.dll
c:\windows\system32\rstrtmgr.dll
c:\windows\system32\devrtl.dll
c:\program files\common files\microsoft shared\vc\msdia90.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\sxsstore.dll

Registry activity

Total events
1182
Read events
946
Write events
230
Delete events
6

Modification events

PID
Process
Operation
Key
Name
Value
2944
PVPubgVIP8.2 (di' cu~).EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2944
PVPubgVIP8.2 (di' cu~).EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2580
4E8EDF95.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2580
4E8EDF95.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
1480
453BE91F.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Name
453BE91F.EXE
1480
453BE91F.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\453BE91F_RASAPI32
EnableFileTracing
0
1480
453BE91F.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\453BE91F_RASAPI32
EnableConsoleTracing
0
1480
453BE91F.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\453BE91F_RASAPI32
FileTracingMask
4294901760
1480
453BE91F.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\453BE91F_RASAPI32
ConsoleTracingMask
4294901760
1480
453BE91F.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\453BE91F_RASAPI32
MaxFileSize
1048576
1480
453BE91F.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\453BE91F_RASAPI32
FileDirectory
%windir%\tracing
1480
453BE91F.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\453BE91F_RASMANCS
EnableFileTracing
0
1480
453BE91F.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\453BE91F_RASMANCS
EnableConsoleTracing
0
1480
453BE91F.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\453BE91F_RASMANCS
FileTracingMask
4294901760
1480
453BE91F.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\453BE91F_RASMANCS
ConsoleTracingMask
4294901760
1480
453BE91F.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\453BE91F_RASMANCS
MaxFileSize
1048576
1480
453BE91F.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\453BE91F_RASMANCS
FileDirectory
%windir%\tracing
1480
453BE91F.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
1480
453BE91F.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000092000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
1480
453BE91F.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
1480
453BE91F.EXE
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
1480
453BE91F.EXE
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E
LanguageList
en-US
1480
453BE91F.EXE
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D4DE20D05E66FC53FE1A50882C78DB2852CAE474
Blob
040000000100000010000000ACB694A59C17E0D791529BB19706A6E40B0000000100000030000000440069006700690043006500720074002000420061006C00740069006D006F0072006500200052006F006F007400000053000000010000006200000030603020060A2B06010401B13E01640130123010060A2B0601040182373C0101030200C0301F06096086480186FD6C020130123010060A2B0601040182373C0101030200C0301B060567810C010130123010060A2B0601040182373C0101030200C00F0000000100000014000000CE0E658AA3E847E467A147B3049191093D055E6F140000000100000014000000E59D5930824758CCACFA085436867B3AB5044DF01D0000000100000010000000918AD43A9475F78BB5243DE886D8103C030000000100000014000000D4DE20D05E66FC53FE1A50882C78DB2852CAE47419000000010000001000000068CB42B035EA773E52EF50ECF50EC52909000000010000003E000000303C06082B0601050507030106082B0601050507030406082B0601050507030206082B0601050507030306082B0601050507030906082B0601050507030862000000010000002000000016AF57A9F676B0AB126095AA5EBADEF22AB31119D644AC95CD4B93DBF3F26AEB20000000010000007B030000308203773082025FA0030201020204020000B9300D06092A864886F70D0101050500305A310B300906035504061302494531123010060355040A130942616C74696D6F726531133011060355040B130A43796265725472757374312230200603550403131942616C74696D6F7265204379626572547275737420526F6F74301E170D3030303531323138343630305A170D3235303531323233353930305A305A310B300906035504061302494531123010060355040A130942616C74696D6F726531133011060355040B130A43796265725472757374312230200603550403131942616C74696D6F7265204379626572547275737420526F6F7430820122300D06092A864886F70D01010105000382010F003082010A0282010100A304BB22AB983D57E826729AB579D429E2E1E89580B1B0E35B8E2B299A64DFA15DEDB009056DDB282ECE62A262FEB488DA12EB38EB219DC0412B01527B8877D31C8FC7BAB988B56A09E773E81140A7D1CCCA628D2DE58F0BA650D2A850C328EAF5AB25878A9A961CA967B83F0CD5F7F952132FC21BD57070F08FC012CA06CB9AE1D9CA337A77D6F8ECB9F16844424813D2C0C2A4AE5E60FEB6A605FCB4DD075902D459189863F5A563E0900C7D5DB2067AF385EAEBD403AE5E843E5FFF15ED69BCF939367275CF77524DF3C9902CB93DE5C923533F1F2498215C079929BDC63AECE76E863A6B97746333BD681831F0788D76BFFC9E8E5D2A86A74D90DC271A390203010001A3453043301D0603551D0E04160414E59D5930824758CCACFA085436867B3AB5044DF030120603551D130101FF040830060101FF020103300E0603551D0F0101FF040403020106300D06092A864886F70D01010505000382010100850C5D8EE46F51684205A0DDBB4F27258403BDF764FD2DD730E3A41017EBDA2929B6793F76F6191323B8100AF958A4D46170BD04616A128A17D50ABDC5BC307CD6E90C258D86404FECCCA37E38C637114FEDDD68318E4CD2B30174EEBE755E07481A7F70FF165C84C07985B805FD7FBE6511A30FC002B4F852373904D5A9317A18BFA02AF41299F7A34582E33C5EF59D9EB5C89E7C2EC8A49E4E08144B6DFD706D6B1A63BD64E61FB7CEF0F29F2EBB1BB7F250887392C2E2E3168D9A3202AB8E18DDE91011EE7E35AB90AF3E30947AD0333DA7650FF5FC8E9E62CF47442C015DBB1DB532D247D2382ED0FE81DC326A1EB5EE3CD5FCE7811D19C32442EA6339A9
3420
msiexec.exe
delete key
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\72\52C64B7E
3420
msiexec.exe
delete key
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\72
3420
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
3420
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback
3420
msiexec.exe
delete key
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
3420
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress
3420
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000_CLASSES\Local Settings\MuiCache\72\52C64B7E
LanguageList
en-US
3420
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Owner
5C0D0000B27074B3F051D501
3420
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
SessionHash
52F6628BA19E336045E9D2286EAD537F293B3D29AC1F6F3E026FB6BD511A9F29
3420
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Sequence
1
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress
c:\Windows\Installer\385bae.ipi
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
c:\Config.Msi\
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
c:\Config.Msi\385baf.rbs
30757369
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
c:\Config.Msi\385baf.rbsLow
363385776
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AA5D9C68C00F12943B2F6CA09FE28244
D20352A90C039D93DBF6126ECE614057
02:\SOFTWARE\Microsoft\DevDiv\VC\Servicing\9.0\SP
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9DDA695F96EBE974FAAE0D63A6F7BE67
D20352A90C039D93DBF6126ECE614057
02:\SOFTWARE\Microsoft\DevDiv\VC\Servicing\9.0\RED\1033\Install
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
c:\Program Files\Common Files\Microsoft Shared\VC\msdia90.dll
2
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A771E8EB1E10BCE44AA8014E39DCC206
D20352A90C039D93DBF6126ECE614057
c?\Program Files\Common Files\Microsoft Shared\VC\msdia90.dll
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D2B3EF2522FB0693FA4336E05E3EE623
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5FAA65EA0C3FB4D388951A5EA0E372FB
D20352A90C039D93DBF6126ECE614057
>atl90.dll\Microsoft.VC90.ATL,version="9.0.30729.1",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32"
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6E5749FF32D22E334AADA52C638EE202
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\58E5A2495BC8DC53B8B9416C9DCD30D0
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\69F8E9220EA16E2348822DBCAC217204
D20352A90C039D93DBF6126ECE614057
>\policy.9.0.Microsoft.VC90.ATL,version="9.0.30729.1",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32-policy"
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D78B2F612F88EF5329150B96F703BDB9
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B121D1754691A29369A50091D3A51E1A
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\75E123D699E378B3FB32C2FD3F63C14B
D20352A90C039D93DBF6126ECE614057
>msvcr90.dll\Microsoft.VC90.CRT,version="9.0.30729.1",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32"
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\909E59FB5F378733ABE9A56AB30732F0
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E22E976033B685437B6E78A79C856562
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\489285C3706753E33A733D3D72903715
D20352A90C039D93DBF6126ECE614057
>\policy.9.0.Microsoft.VC90.CRT,version="9.0.30729.1",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32-policy"
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F74C83443EF904D34AF9EDBF71F48762
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D36A387FC01EF2F33B9CDB1C9FE8BDDC
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9DD834BCB1B20E23A96A6DAD28ECD979
D20352A90C039D93DBF6126ECE614057
>mfc90.dll\Microsoft.VC90.MFC,version="9.0.30729.1",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32"
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3E285BE69D65F4B3F83D8E11830483F1
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FCC01B60BAF4F3637A6C90A523BD3667
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3A880436E76DD633495267B76A09C747
D20352A90C039D93DBF6126ECE614057
>\policy.9.0.Microsoft.VC90.MFC,version="9.0.30729.1",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32-policy"
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9166B4ED039A84439930ADDFB2752F5F
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CA8E8AC867D93C337A32F95688D8BE90
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\10BB9476A37D3473E83136181DC18A8F
D20352A90C039D93DBF6126ECE614057
>mfc90cht.dll\Microsoft.VC90.MFCLOC,version="9.0.30729.1",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32"
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F271DD6DEFFB195369723CE5A4356601
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9884982C831F68D3CB5FF5B9BE77DA61
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C7CF67A49199C64339EA5C26D3462CA3
D20352A90C039D93DBF6126ECE614057
>\policy.9.0.Microsoft.VC90.MFCLOC,version="9.0.30729.1",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32-policy"
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A3FC9C46D3D588B3BBBB5F5A009F7578
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AA35D58AD6095C13693E2EB19B51E4C2
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3F4F115D119AFC23CA11C979FE49B8CF
D20352A90C039D93DBF6126ECE614057
>vcomp90.dll\Microsoft.VC90.OpenMP,version="9.0.21022.8",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32"
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CF68F61B49DBAF0389AA71BA5EF44087
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C01B6B82F14EB2036A37104F63245722
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\75EC17D83CDB0B43DADAAEC4A5CF6946
D20352A90C039D93DBF6126ECE614057
>\policy.9.0.Microsoft.VC90.OpenMP,version="9.0.21022.8",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32-policy"
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A891A946D91CF523FBA37CAE6EF2E56F
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4EE57BB6B8E2E3848AA4773134975546
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D72CFC1B540B9014C983F2B89EC0AD3A
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\9139CDB10A2211C458036000CA13F613
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\298095F840DB82A4C997E3EE402B0B0D
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1DBFA1B595D618049AFE66A3138BEBC3
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AC1BF68872161FB4C94C84F195523AB7
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\CCCD3CF96BADF7E42A9468F29E623555
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D44BDE8068B242B43963888890D3BA9B
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\97486C5D001A175448A3E30BF3B775B3
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BFB8A0EA52A3591408D6120D165BAF11
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3A82B8DA21FCE4542840AD18154B6003
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3FFF22A42C37CBB4DA2CC697237A99B9
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\303FD3DF888283041A37A5688745D217
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8267078178EFD2D43874621BFF124618
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BB9303D405CDB134CB30CD367AC97F2B
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E8D57C26BBC0BA4086B6AE65D820A79
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6C131C196F822F5418614A704F514399
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B5E445F6BDBA2B346B9FC57B7169F65B
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCB893E3BCA189C4B96FA7F49DC89DA5
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3CC3911F7FC23D948BF67404DA99F113
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3E81E5FA91DB0274CBFA0C024E748E82
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA0CEFB36BB0E664381F5BCC75524D33
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\53714D3915F0E734D9809C232714222E
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\8477A35EABCAFE040A730AE47C57DEA2
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\614A75AA111769C4BB8A6B8F035000B0
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F1546C7E77B0CE34EADB0FEAE4DB0BC7
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A771E8EB1E10BCE44AA8014E39DCC206\D20352A90C039D93DBF6126ECE614057
PatchGUID
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A771E8EB1E10BCE44AA8014E39DCC206\D20352A90C039D93DBF6126ECE614057
MediaCabinet
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A771E8EB1E10BCE44AA8014E39DCC206\D20352A90C039D93DBF6126ECE614057
File
FL_msdia71_dll_2_60035_x86_ln.3643236F_FC70_11D3_A536_0090278A1BB8
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A771E8EB1E10BCE44AA8014E39DCC206\D20352A90C039D93DBF6126ECE614057
ComponentVersion
9.0.30729.1
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A771E8EB1E10BCE44AA8014E39DCC206\D20352A90C039D93DBF6126ECE614057
ProductVersion
9.0.30729
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A771E8EB1E10BCE44AA8014E39DCC206\D20352A90C039D93DBF6126ECE614057
PatchSize
0
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A771E8EB1E10BCE44AA8014E39DCC206\D20352A90C039D93DBF6126ECE614057
PatchAttributes
0
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A771E8EB1E10BCE44AA8014E39DCC206\D20352A90C039D93DBF6126ECE614057
PatchSequence
0
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A771E8EB1E10BCE44AA8014E39DCC206\D20352A90C039D93DBF6126ECE614057
SharedComponent
0
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A771E8EB1E10BCE44AA8014E39DCC206\D20352A90C039D93DBF6126ECE614057
IsFullFile
0
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DevDiv\VC\Servicing\9.0
SP
1
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DevDiv\VC\Servicing\9.0
SPIndex
1
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DevDiv\VC\Servicing\9.0\RED\1033
Install
1
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DevDiv\VC\Servicing\9.0\RED\1033
InstallerType
MSI
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DevDiv\VC\Servicing\9.0\RED\1033
SP
1
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DevDiv\VC\Servicing\9.0\RED\1033
SPIndex
1
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DevDiv\VC\Servicing\9.0\RED\1033
SPName
SP1
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057\InstallProperties
LocalPackage
c:\Windows\Installer\385bb0.msi
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057\InstallProperties
AuthorizedCDFPrefix
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057\InstallProperties
Comments
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057\InstallProperties
Contact
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057\InstallProperties
DisplayVersion
9.0.30729
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057\InstallProperties
HelpLink
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057\InstallProperties
HelpTelephone
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057\InstallProperties
InstallDate
20190813
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057\InstallProperties
InstallLocation
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057\InstallProperties
InstallSource
c:\a64949a19f6d1a42e24d09b2a3d844\
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057\InstallProperties
ModifyPath
MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057\InstallProperties
NoModify
1
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057\InstallProperties
NoRepair
1
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057\InstallProperties
Publisher
Microsoft Corporation
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057\InstallProperties
Readme
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057\InstallProperties
Size
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057\InstallProperties
EstimatedSize
240
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057\InstallProperties
UninstallString
MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057\InstallProperties
URLInfoAbout
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057\InstallProperties
URLUpdateInfo
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057\InstallProperties
VersionMajor
9
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057\InstallProperties
VersionMinor
0
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057\InstallProperties
WindowsInstaller
1
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057\InstallProperties
Version
151025673
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057\InstallProperties
Language
1033
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9A25302D-30C0-39D9-BD6F-21E6EC160475}
AuthorizedCDFPrefix
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Comments
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Contact
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9A25302D-30C0-39D9-BD6F-21E6EC160475}
DisplayVersion
9.0.30729
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9A25302D-30C0-39D9-BD6F-21E6EC160475}
HelpLink
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9A25302D-30C0-39D9-BD6F-21E6EC160475}
HelpTelephone
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9A25302D-30C0-39D9-BD6F-21E6EC160475}
InstallDate
20190813
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9A25302D-30C0-39D9-BD6F-21E6EC160475}
InstallLocation
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9A25302D-30C0-39D9-BD6F-21E6EC160475}
InstallSource
c:\a64949a19f6d1a42e24d09b2a3d844\
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9A25302D-30C0-39D9-BD6F-21E6EC160475}
ModifyPath
MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9A25302D-30C0-39D9-BD6F-21E6EC160475}
NoModify
1
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9A25302D-30C0-39D9-BD6F-21E6EC160475}
NoRepair
1
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Publisher
Microsoft Corporation
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Readme
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Size
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9A25302D-30C0-39D9-BD6F-21E6EC160475}
EstimatedSize
240
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9A25302D-30C0-39D9-BD6F-21E6EC160475}
UninstallString
MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9A25302D-30C0-39D9-BD6F-21E6EC160475}
URLInfoAbout
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9A25302D-30C0-39D9-BD6F-21E6EC160475}
URLUpdateInfo
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9A25302D-30C0-39D9-BD6F-21E6EC160475}
VersionMajor
9
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9A25302D-30C0-39D9-BD6F-21E6EC160475}
VersionMinor
0
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9A25302D-30C0-39D9-BD6F-21E6EC160475}
WindowsInstaller
1
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Version
151025673
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Language
1033
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\41A387AA3A7A33D3590FA953D1350011
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057\InstallProperties
DisplayName
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9A25302D-30C0-39D9-BD6F-21E6EC160475}
DisplayName
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Win32Assemblies\Global
Microsoft.VC90.ATL,version="9.0.30729.1",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32"
E`)VY'-FZ6^bvzrORh[MFT_VC_Redist_ATL_x86>yYg%afJWd78p8mrW5+Mf
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Win32Assemblies\Global
policy.9.0.Microsoft.VC90.ATL,version="9.0.30729.1",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32-policy"
E`)VY'-FZ6^bvzrORh[MFT_VC_Redist_ATL_x86>eri-.8TRF4tm1Sjm5Y]8
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Win32Assemblies\Global
Microsoft.VC90.CRT,version="9.0.30729.1",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32"
E`)VY'-FZ6^bvzrORh[MFT_VC_Redist_CRT_x86>92,+Kn$9.7m$ofpy!Ktb
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Win32Assemblies\Global
policy.9.0.Microsoft.VC90.CRT,version="9.0.30729.1",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32-policy"
E`)VY'-FZ6^bvzrORh[MFT_VC_Redist_CRT_x86>k'VI7oRP~7U=o)ms&,3B
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Win32Assemblies\Global
Microsoft.VC90.MFC,version="9.0.30729.1",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32"
E`)VY'-FZ6^bvzrORh[MFT_VC_Redist_MFC_x86>[email protected]'brE4q0LDoYL~fX
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Win32Assemblies\Global
policy.9.0.Microsoft.VC90.MFC,version="9.0.30729.1",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32-policy"
E`)VY'-FZ6^bvzrORh[MFT_VC_Redist_MFC_x86>MrNuGte}[email protected]
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Win32Assemblies\Global
Microsoft.VC90.MFCLOC,version="9.0.30729.1",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32"
E`)VY'-FZ6^bvzrORh[MFT_VC_Redist_MFCLOC_x86>@ee4I`4ki5YGeYQc4%wx
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Win32Assemblies\Global
policy.9.0.Microsoft.VC90.MFCLOC,version="9.0.30729.1",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32-policy"
E`)VY'-FZ6^bvzrORh[MFT_VC_Redist_MFCLOC_x86>c.Ax?}X2q49SEhGrK8t6
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Win32Assemblies\Global
Microsoft.VC90.OpenMP,version="9.0.21022.8",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32"
E`)VY'-FZ6^bvzrORh[MFT_VC_Redist_OpenMP_x86>MOpPm6x+D4pamfX1o92z
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Win32Assemblies\Global
policy.9.0.Microsoft.VC90.OpenMP,version="9.0.21022.8",publicKeyToken="1fc8b3b9a1e18e3b",processorArchitecture="x86",type="win32-policy"
E`)VY'-FZ6^bvzrORh[MFT_VC_Redist_OpenMP_x86>M9,[email protected]{0!DH
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\D20352A90C039D93DBF6126ECE614057
VC_RED_enu_x86_net_SETUP
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057\Features
VC_RED_enu_x86_net_SETUP
5`c]JiaZ6?P)l9)Iv!9H?A]0bijiu8c(GgTG19a]x^0z+HQ([email protected]!!QmQt3Vi+)V]Gyo?lwWXuam3)llJu?E[[email protected]@FE`'-qt^gO1P[E[-!T7Au(C?32=}KCv~vr%I&[email protected]{usS$s=bdn?,em&$.C=&-j_avj0)7i,]x`_Q`)9^=utkKv2k((]$k`H2K?=a9JgQeu$M3.CDo?gE%[email protected]$G4%[email protected]_8taH3S=1sGLO``q*[email protected]}Txa*znYQE[[email protected]_nDX9!4'+Hmt3Tb)^[@[email protected]_j8gXtkqpV%tpP=l.hN%[email protected]?xcPF^BcLWv~7HiO]@*hBVAnsv4E.PVQvj9nf?(j%a8ko~k3-*qFagQ.r=v4jT-f4V01!'[email protected]](_=v}OljWfu`4-JSSWJWnc9unIC42cfbq^[=brkm}r8DW{=[email protected]]@80YxxiESU&7ynQs+5Wo90037abAJ)P
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\D20352A90C039D93DBF6126ECE614057
Servicing_Key
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057\Features
Servicing_Key
N~=CS6YuR?JaKO&hd{u98h5xw2NY$?uhS]5u_i6N
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\D20352A90C039D93DBF6126ECE614057
VC_Redist_12222_x86_enu
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057\Features
VC_Redist_12222_x86_enu
]$i8f{cUCAL6PArlXIvF
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\D20352A90C039D93DBF6126ECE614057
FT_VC_Redist_ATL_x86
VC_Redist_12222_x86_enu
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057\Features
FT_VC_Redist_ATL_x86
3i?bBN[RM6!F'^'91k54yYg%afJWd78p8mrW5+Mfob10{[email protected]!f][email protected]%wDahDKW3'eri-.8TRF4tm1Sjm5Y]8h}vG*(M(F5}OA{IO_n*ZVC_Redist_12222_x86_enu
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\D20352A90C039D93DBF6126ECE614057
FT_VC_Redist_CRT_x86
VC_Redist_12222_x86_enu
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057\Features
FT_VC_Redist_CRT_x86
uvp~C_vaG6-r!&+C3I%]92,+Kn$9.7m$ofpy!Ktbq&vXf9!-V4(Z[O^[&Xr'd5w)%SU$o4t`JHOr9DC0k'VI7oRP~7U=o)ms&,3B=.hw9$aEc7G{lyy(CzF0VC_Redist_12222_x86_enu
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\D20352A90C039D93DBF6126ECE614057
FT_VC_Redist_MFC_x86
VC_Redist_12222_x86_enu
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057\Features
FT_VC_Redist_MFC_x86
-EnVx*}4B8{{l=[email protected]@yCj'brE4q0LDoYL~fX^+NYK4w?(7+e=i(MTt%-g[m0%C!}[email protected]'NMrNuGte}[email protected]~NpMp$[Dm4HGyYz=3~&xVC_Redist_12222_x86_enu
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\D20352A90C039D93DBF6126ECE614057
FT_VC_Redist_MFCLOC_x86
VC_Redist_12222_x86_enu
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057\Features
FT_VC_Redist_MFCLOC_x86
H{a5U.k._4M64aH.Z!4&@ee4I`4ki5YGeYQc4%wxy.p'nXbN65^1mNF8r$?(FoSTglQqj7&[email protected]*c.Ax?}X2q49SEhGrK8t6a1LIH,3G.77PpD^[email protected]VC_Redist_12222_x86_enu
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Features\D20352A90C039D93DBF6126ECE614057
FT_VC_Redist_OpenMP_x86
VC_Redist_12222_x86_enu
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057\Features
FT_VC_Redist_OpenMP_x86
'FU,_s8e~3Kvnz+ryF82MOpPm6x+D4pamfX1o92zxIE%bPQ(h3)m'~_*pfXNpH9*1-6~P34&{Kw47F).M9,[email protected]{0!DHvIDDHos144%{sNt=LR3xVC_Redist_12222_x86_enu
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\D20352A90C039D93DBF6126ECE614057\Patches
AllPatches
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\D20352A90C039D93DBF6126ECE614057
ProductName
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\D20352A90C039D93DBF6126ECE614057
PackageCode
6C7E9C94F9A4F6E4EA39E910D4A1AC39
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\D20352A90C039D93DBF6126ECE614057
Language
1033
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\D20352A90C039D93DBF6126ECE614057
Version
151025673
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\D20352A90C039D93DBF6126ECE614057
Assignment
1
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\D20352A90C039D93DBF6126ECE614057
AdvertiseFlags
388
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\D20352A90C039D93DBF6126ECE614057
InstanceType
0
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\D20352A90C039D93DBF6126ECE614057
AuthorizedLUAApp
1
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\D20352A90C039D93DBF6126ECE614057
DeploymentFlags
3
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\UpgradeCodes\41A387AA3A7A33D3590FA953D1350011
D20352A90C039D93DBF6126ECE614057
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\D20352A90C039D93DBF6126ECE614057\SourceList
PackageName
vc_red.msi
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\D20352A90C039D93DBF6126ECE614057\SourceList\Net
1
c:\a64949a19f6d1a42e24d09b2a3d844\
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\D20352A90C039D93DBF6126ECE614057\SourceList\Media
DiskPrompt
[1]
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\D20352A90C039D93DBF6126ECE614057\SourceList\Media
1
;1
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\D20352A90C039D93DBF6126ECE614057
Clients
:
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\D20352A90C039D93DBF6126ECE614057\SourceList
LastUsedSource
n;1;c:\a64949a19f6d1a42e24d09b2a3d844\
3420
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MUI\StringCacheSettings
StringCacheGeneration
115

Files activity

Executable files
29
Suspicious files
3
Text files
27
Unknown types
20

Dropped files

PID
Process
Filename
Type
2944
PVPubgVIP8.2 (di' cu~).EXE
C:\Users\admin\AppData\Local\Temp\4E8EDF95.EXE
executable
MD5: e065d23e2d11ba7aebf58ebdb5a14931
SHA256: 3847f998dc005f1f2e6608e4aaa694a334e9d935ee2927fb5c6bd29f3c6c8cd2
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353111.3\mfcm90.dll
executable
MD5: c38774421c7b64d2c23129a200c60f47
SHA256: 57b6ff7f254ef62b2e7277ce4438ba21e7b92cdb5066bc6615ada65dc3ce6fd8
360
VC2008.EXE
C:\a64949a19f6d1a42e24d09b2a3d844\install.res.1040.dll
executable
MD5: dcca7196203d338b41ead5e1418c6a92
SHA256: c2a81077da2201d180bd5496129ea6bcfc5930d8a6d256babdb9a552b1a597d2
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353111.2\msvcm90.dll
executable
MD5: 7b37f8ec25c9ad853e8126c1d0992201
SHA256: 866f51d4416b6a0bfbe8442cc8c1716152e4c3ee3137c375d05185e8171096a7
360
VC2008.EXE
C:\a64949a19f6d1a42e24d09b2a3d844\install.res.3082.dll
executable
MD5: 55a9b25fa0d768fb902842439d041b1f
SHA256: 8f826dba565fc464395ed24219da946f55692705de9f61f501dcfebf338970a3
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353111.3\mfcm90u.dll
executable
MD5: db59cce916665d8c9a8a87198daede34
SHA256: fb7beea50b6404f3be9567041f294469195c7378106ef39e85b5b950ebf93eff
360
VC2008.EXE
C:\a64949a19f6d1a42e24d09b2a3d844\install.exe
executable
MD5: 33c9213ff5849ef7346799cae4d8ac80
SHA256: 3377e31d233ff41aea253e6221815820997763acdf40b005f8791400366cb8ff
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353111.2\msvcp90.dll
executable
MD5: 871f979d70414c900b35e56222932daf
SHA256: 91fd46d7335c9990a20f215b9f6f53bc59551420a9c99ad8110ae2f9ff7598f0
360
VC2008.EXE
C:\a64949a19f6d1a42e24d09b2a3d844\install.res.1042.dll
executable
MD5: d276d0c01bf44cb781ff5d293676674b
SHA256: d6f45cb0308e3790b0d819cae9d87e61d79468414ce7f78bd41e7289fc832945
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353111.2\msvcr90.dll
executable
MD5: 4d03ca609e68f4c90cf66515218017f8
SHA256: cf420aced0d810e1d75f6811dd986f2d9fded2fbb8d61fc9a7024520c475febb
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353111.3\mfc90u.dll
executable
MD5: a76104d8d9aba3670fd3cea603d70ada
SHA256: 443fd2e5fce845e3e682f6057081b8209e4b7d1f50e2938f7cfc003f2a6b1a01
360
VC2008.EXE
C:\a64949a19f6d1a42e24d09b2a3d844\install.res.1033.dll
executable
MD5: 8e97ea8a1ed69806232e8743f9a28706
SHA256: 2893b1b9751f833d4a3ded7c1fba1a96cada2927a2349c5d751365eed647c100
360
VC2008.EXE
C:\a64949a19f6d1a42e24d09b2a3d844\install.res.1049.dll
executable
MD5: 2e57ae4186f17be4148077ffe8212a27
SHA256: ac9ef02d54eb87a5bc2bc8c77a6497853072ff37e7e82495ef8d79f6a5af07e3
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353111.0\vcomp90.dll
executable
MD5: f6a85f3b0e30c96c993c69da6da6079e
SHA256: ffc774f6f055b1a9a899ab76dac3e141f582ce19dae0b3d4dff9d93916b42d09
360
VC2008.EXE
C:\a64949a19f6d1a42e24d09b2a3d844\install.res.1036.dll
executable
MD5: cbf6e77d932688970a28328ca5263501
SHA256: 3ffe888bc0bbe9bb81369b49171d532839fbea931d8553371e857df6ef815c13
1480
453BE91F.EXE
C:\Users\admin\AppData\Local\Temp\LIB\VC2008.EXE
executable
MD5: 5689d43c3b201dd3810fa3bba4a6476a
SHA256: 41f45a46ee56626ff2699d525bb56a3bb4718c5ca5f4fb5b3b38add64584026b
360
VC2008.EXE
C:\a64949a19f6d1a42e24d09b2a3d844\install.res.1028.dll
executable
MD5: 5e7e93fb7b9d36665b10be97703dafe5
SHA256: b8f0f576199e32fd906538537c8da052ee666a91ef971c577a53fd715e544604
3420
msiexec.exe
C:\Windows\Installer\$PatchCache$\Managed\D20352A90C039D93DBF6126ECE614057\9.0.30729\FL_msdia71_dll_2_60035_x86_ln.3643236F_FC70_11D3_A536_0090278A1BB8
executable
MD5: 7acc250699dc39644e84718f46277429
SHA256: 149f0b0df850c8aac3b30fb8cf3e3c7437ab46b4b23d5f4a27ad9bce777e6d5f
360
VC2008.EXE
C:\a64949a19f6d1a42e24d09b2a3d844\install.res.1031.dll
executable
MD5: a1157142485b86985c03e26add533201
SHA256: 94779d2272a18a0340156225485aab95d0473aef478442dfe392d11b7e6f41db
1480
453BE91F.EXE
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JGRR2OYX\vcredist_x86[1].exe
executable
MD5: 5689d43c3b201dd3810fa3bba4a6476a
SHA256: 41f45a46ee56626ff2699d525bb56a3bb4718c5ca5f4fb5b3b38add64584026b
360
VC2008.EXE
C:\a64949a19f6d1a42e24d09b2a3d844\install.res.2052.dll
executable
MD5: 4b8d230ccfadf8a2d3ea4b1512238292
SHA256: 8fec53f664217f624ec8229425abde74225eccf6b55e41d4c12c9d9789f4159c
3420
msiexec.exe
C:\Windows\Installer\385bb0.msi
executable
MD5: 6e17361f8e53b47656bcf0ed90ade095
SHA256: 8811e5fe167223d906701bc8deb789de0a731e888e285834bcae164b03d43c96
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353111.3\mfc90.dll
executable
MD5: 361a47591fd31ec99a9794b6541360a6
SHA256: 33aaad746f1873a862cdb8c4ae6002bf3503144681422ee2b5d3742e437d751e
2580
4E8EDF95.EXE
C:\Users\admin\AppData\Local\Temp\453BE91F.EXE
executable
MD5: abcf987683356e0696619d9a85233367
SHA256: b3c9486d539990491a9ed7bdd03d07e2fc7f41f182f6fbd76fdd3be59addf4ff
3420
msiexec.exe
C:\Windows\Installer\385bac.msi
executable
MD5: 6e17361f8e53b47656bcf0ed90ade095
SHA256: 8811e5fe167223d906701bc8deb789de0a731e888e285834bcae164b03d43c96
360
VC2008.EXE
C:\a64949a19f6d1a42e24d09b2a3d844\install.res.1041.dll
executable
MD5: 0fcc2f2bf7c18392514413a3c2a5ec5a
SHA256: 11c111b3f24ba7d197007fb572b9f77e7d6f58c290de239a08f287c2aeb3b89d
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353095.0\atl90.dll
executable
MD5: 47857df83c1bd9755afd1c7f0ae65465
SHA256: 967ad7c178348fce215f2ad1fcf19676cb0a483288cd155a8899d1af3469f6bc
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353127.0\mfc90cht.dll
executable
MD5: 3460a87d70e659c44b9fec195345ac2e
SHA256: 4914ca7dd8845a383da1c7051edb7042b8fbfe242e02d66aad907e58948b6326
360
VC2008.EXE
C:\a64949a19f6d1a42e24d09b2a3d844\vc_red.msi
executable
MD5: 6e17361f8e53b47656bcf0ed90ade095
SHA256: 8811e5fe167223d906701bc8deb789de0a731e888e285834bcae164b03d43c96
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353127.0\mfc90enu.dll
rll
MD5: 2229324ce0374811ca64a19ee62f130b
SHA256: 93c30edc405879ea6b7367308d04ccfa67a1c150c7b11b740a7659668449e28b
3368
install.exe
C:\Users\admin\AppData\Local\Temp\dd_vcredistMSI09BD.txt
text
MD5: 6af681b95eb9851e4c0e9509c2c97a28
SHA256: a5f9ae0a6e753fc8e6ac0266bc1d9761cc8da70afa535a36599f59e6e6867b80
3368
install.exe
C:\Users\admin\AppData\Local\Temp\VWL6A71.tmp
––
MD5:  ––
SHA256:  ––
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353127.0\mfc90esn.dll
rll
MD5: 154b11cc93fc5a4a03e21d3dedfb5879
SHA256: 6824f96be1718d1a9d2e5e904b65d5181ad92bf855e273d00dd578d3089b7e2f
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353127.0\mfc90chs.dll
rll
MD5: b02f2fc742d87f54a94fcd5f4ce71d52
SHA256: 9da83c8801301d413e209c6859610f116f18b74e3b4e48d5d6f82f693515ed38
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353127.0\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03.manifest
xml
MD5: 823d93a01f27798691c25179f7e71c15
SHA256: 14eb112384d59cadf48b16174e77f8cd74b79a05bbfe8a2e634636e89976131c
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353111.3\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943.manifest
xml
MD5: 5ab0dfaf0a5a7d292b0aa07332bd3b13
SHA256: 682d718e55623b86a945489ec88bbc963b66175f069960d2f8e064c4ae71d5e9
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353111.0\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_ecc42bd1.manifest
xml
MD5: 1b2b5a8fa0ab8c76ec505f786a74cdb2
SHA256: b189460384701bcc280c0ac3c9e007e705106d6b8ac8ee52e118036f496b3c1d
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353142.0\9.0.30729.1.cat
cat
MD5: 60721cfe769e64775c94828b766b350a
SHA256: 0b7d20c26830f61b09683634e70076f8395a95b114efef7d33c593b8b4137bf6
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353127.3\9.0.30729.1.cat
cat
MD5: 21bfbd0c2822a96ecd8d8785ee5801fb
SHA256: 64bbe4a95b9c7b212f5cb46b7d55fd3c8319c2288a97bb83cf01fdd9ffc242c8
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353111.2\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e.manifest
xml
MD5: c1eda860810e6299f690459006e4c655
SHA256: df2e70333883fa14f1ab0eb04665a26dbd5334edd5c5a886a72075fbebc57ea3
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353095.0\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_d01483b2.manifest
xml
MD5: 8f6a86317fb7dee8a4b9fe5666053f85
SHA256: 0040edb85c7561e428f94df5e58636efac48763f5a39a77353c2af741fd8bf96
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353127.0\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03.cat
cat
MD5: ef117e26663a297b7cb6fdd582d4405d
SHA256: 2fdc0212e1f094427dd375e350bf1f5d0cc51ac33f12145bc304f80cf6a0ffcd
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353127.1\9.0.30729.1.cat
cat
MD5: 0387f0c1fadff7356f829f71eb012cba
SHA256: 1265c65845e1309c6193e0746cf3cfad6b5572071b335268ba1be94820869820
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353127.2\9.0.30729.1.cat
cat
MD5: f7f3e808d91e0bc63919a67310fabd91
SHA256: e1f1fc853eb9ae0cbf7de6045dec226212d01eed7badabc1b8622a3dd4b4ca92
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353111.3\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943.cat
cat
MD5: c8ad3bbbbb7531abe171f6c0c5ada8d2
SHA256: 40d9b9c15bb2242d665acacc7b2478ffc47b4c876e759d8a49536f0af1c4b649
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353111.0\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_ecc42bd1.cat
cat
MD5: 73a73ff5c01397068cfa693e679224ba
SHA256: 3108308d2cbc329124c9fc3168f271af92613bfb0ad3119586e78fb5476ef964
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353111.1\9.0.21022.8.cat
cat
MD5: 7dd06d2b1cadde6cf57d2a605729303a
SHA256: 774f42f7fabf0255531907023e64c91de57a1ae8fb564fa707244e41c215a542
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353111.1\9.0.21022.8.policy
xml
MD5: 6a862b008e87d447cd900dc6a793b2d3
SHA256: c1da105c2da39ce425867dabf5d06ff62df2535ae82be4e9c37299991a8c8f02
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353111.2\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e.cat
cat
MD5: 685f02081e7399a3b723c45f1ab7d37b
SHA256: bd46fa78cdc74e9e017594868fa421c4f10ad80ec37cf0856bafd38718296228
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353095.0\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_d01483b2.cat
cat
MD5: c27425cf55dc97de8a821e84afed69ae
SHA256: 9989fd7161367ec8b411b094a25b929152e319c82bd9f1e78767a7c5fe91c086
3420
msiexec.exe
C:\Windows\Installer\MSI5D04.tmp
binary
MD5: 50f494bcfae3696f23248673e025c044
SHA256: 213a54e3b3cb20658a05ddc0ad2d103904bba8fba3fe7f6a6d6dc9b540966dd2
3420
msiexec.exe
C:\Windows\Installer\385bae.ipi
binary
MD5: e912aa67f8643f08637a97813db5b115
SHA256: da8d3a8953c4cc741b11d01080817acb2b47e67d3b68ff2f45aa3677119c98e4
3420
msiexec.exe
C:\Users\admin\AppData\Local\Temp\~DF6D247EF594637CDC.TMP
––
MD5:  ––
SHA256:  ––
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353127.1\9.0.30729.1.policy
xml
MD5: 69f202deefb11df116110f4119961061
SHA256: 9088bfccfad2754784ee4d562711b6a764b56cfad33eedf65c8bc081101ba01d
360
VC2008.EXE
C:\a64949a19f6d1a42e24d09b2a3d844\eula.1028.txt
text
MD5: f187c4924020065b61ec9ef8eb482415
SHA256: cfa4f2c6c2a8f86896c5a6f9a16e81932734136c3dfde6b4ed44735e9c8115c2
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353127.2\9.0.30729.1.policy
xml
MD5: cd7851c71796d284f746b12cba5c43a8
SHA256: 90bb88f1c66161ffc3c9e0600af86fff20b9234c970e97111d41f056eecebbe1
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353127.3\9.0.30729.1.policy
xml
MD5: f02ba6922aa03c1225103851b026c157
SHA256: 08de298fb8d57a2b4d164082654a8448022a02a12a6b630938bbd1223aa05723
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353142.0\9.0.30729.1.policy
xml
MD5: 1c872d4a097e663340cdd4fccc40eba0
SHA256: 954eff60574aa503ae8d67e6532910e843b3a92c452c52b014de4a572ad20ecd
3420
msiexec.exe
C:\Users\admin\AppData\Local\Temp\~DFF435CB56D56EC9E7.TMP
––
MD5:  ––
SHA256:  ––
360
VC2008.EXE
C:\a64949a19f6d1a42e24d09b2a3d844\globdata.ini
text
MD5: 0a6b586fabd072bd7382b5e24194eac7
SHA256: 7912e3fcf2698cf4f8625e563cd8215c6668739cae18bd6f27af2d25bec5c951
3420
msiexec.exe
C:\Windows\Installer\385bae.ipi
––
MD5:  ––
SHA256:  ––
3420
msiexec.exe
C:\Config.Msi\385baf.rbs
––
MD5:  ––
SHA256:  ––
360
VC2008.EXE
C:\a64949a19f6d1a42e24d09b2a3d844\install.ini
text
MD5: 5feaa6a36fea7dfdb88c18d69ba6d6a9
SHA256: 67a50ffbb8a1d500eaa4d9f0227d6a8595a2750154e6b31662fc4f51286e47fc
360
VC2008.EXE
C:\a64949a19f6d1a42e24d09b2a3d844\eula.1031.txt
text
MD5: 3168ed3b48c1dc8d373c2abc036574cf
SHA256: 3e4d78fcc11eecb23af12a4eaa316114bb36d39561f6062a3921c08a43261321
360
VC2008.EXE
C:\a64949a19f6d1a42e24d09b2a3d844\eula.1040.txt
text
MD5: 04b833156f39fcc4cee4ae7a0e7224a1
SHA256: ebafaeb37464ed00e579dab5b573908e026cd0e3444079f398aada13fa9a6f66
360
VC2008.EXE
C:\a64949a19f6d1a42e24d09b2a3d844\vcredist.bmp
image
MD5: 06fba95313f26e300917c6cea4480890
SHA256: 594884a8006e24ad5b1578cd7c75aca21171bb079ebdc4f6518905bcf2237ba1
360
VC2008.EXE
C:\a64949a19f6d1a42e24d09b2a3d844\eula.1036.txt
text
MD5: c360851dfdf51b6ddc9cfcc62c584898
SHA256: 3456ebc9c6decef8b27b10d97f7f6d30a73b5da0024e1b8a0657e3b9a1cc93d9
360
VC2008.EXE
C:\a64949a19f6d1a42e24d09b2a3d844\eula.2052.txt
text
MD5: ec4b365a67e7d7db46f095f1b3dcb046
SHA256: 744275c515354ece1a997dd510f0b3ea607147bbf2b7d73f8fca61839675ba27
360
VC2008.EXE
C:\a64949a19f6d1a42e24d09b2a3d844\eula.1041.txt
text
MD5: 031fab3fb14a85334e7e49d62a5179fe
SHA256: 467773ddffdb3f31027595313b70d1ea934c828b124d1063a4aa4dbe90f15961
360
VC2008.EXE
C:\a64949a19f6d1a42e24d09b2a3d844\$shtdwn$.req
––
MD5:  ––
SHA256:  ––
3420
msiexec.exe
C:\Users\admin\AppData\Local\Temp\dd_vcredistMSI09BD.txt
text
MD5: 6af681b95eb9851e4c0e9509c2c97a28
SHA256: a5f9ae0a6e753fc8e6ac0266bc1d9761cc8da70afa535a36599f59e6e6867b80
360
VC2008.EXE
C:\a64949a19f6d1a42e24d09b2a3d844\eula.1042.txt
text
MD5: 6fcd6b5ef928a75655d6be51555288c7
SHA256: 3d45f022996cd6d9ebb659a202fbfd099795f9a39ed4e6bbd62ac6f6ed5f8c7b
360
VC2008.EXE
C:\a64949a19f6d1a42e24d09b2a3d844\eula.1049.txt
text
MD5: bc3a8865b60ec692293679e3e400fd58
SHA256: f82bca639841fa7387ae9bbf9eca33295fab20fade57496e458152068c06f8a3
360
VC2008.EXE
C:\a64949a19f6d1a42e24d09b2a3d844\eula.1033.txt
text
MD5: 162fc8231b1bd62f1d24024bb70140d5
SHA256: c68a0fd93e8c64139a42af4fcd4670c6faea3a5d5d1e9dd35b197f7d5268d92b
360
VC2008.EXE
C:\a64949a19f6d1a42e24d09b2a3d844\eula.3082.txt
text
MD5: c2d1221cd1c783b5d58b150f2d51aebf
SHA256: c79ff7b9e67aed57f939343a3d5fd4fb01aa7412530693464571148b893b7132
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353127.0\mfc90kor.dll
rll
MD5: 6574e30c091c2ac5c99db460094f19a0
SHA256: 16464d641d2fc02235a99d6e16fbb1b553dd4362940c58c02bc34976a5a905e0
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353127.0\mfc90fra.dll
rll
MD5: 3c26a63c73eb4d6bda72815fcad79ef2
SHA256: feeeaffc98575c6573c7c271ab1ae090e097044fa5ce92472b28ece51e7eed14
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353127.0\mfc90rus.dll
rll
MD5: c1e0a8ab46902ee0e15e02931efcb885
SHA256: 8609cadd4bc0b494e094f23e8a120bb931c676c14bf504fd463fda29c42997f4
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353127.0\mfc90ita.dll
rll
MD5: 25b61d43310128c1467c1d51397b5342
SHA256: 81f0cb29ad255878e78db1963123002be130b84ddc7167d098f8b988ffcf7e3d
360
VC2008.EXE
C:\a64949a19f6d1a42e24d09b2a3d844\vc_red.cab
compressed
MD5: ecca3c1acb74cb73c600eabdd3f9c9d9
SHA256: 43b7648183347374236296f2176c7c7da920da9c1a08adda761e12614efb299e
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353127.0\mfc90jpn.dll
rll
MD5: be48c834229e153ab89bcca1f8309315
SHA256: 6945a3dcb091df8c465af99d38c4ab28d94b8a1fa157b6d780485dfb6a095edf
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353127.0\mfc90deu.dll
rll
MD5: d727f282a20ebff629f26e13ce8fcac9
SHA256: 3fd6a452b1040e7952f2db248a2f33e50fe1c58326ea93a62cde932047ddb707
1480
453BE91F.EXE
C:\Users\admin\AppData\Local\Temp\3E31.tmp
––
MD5:  ––
SHA256:  ––
2580
4E8EDF95.EXE
C:\Users\admin\AppData\Local\Temp\~DF4E295C566A12F73A.TMP
––
MD5:  ––
SHA256:  ––
3420
msiexec.exe
C:\Windows\WinSxS\InstallTemp\20190813170353127.0\mfc90esp.dll
rll
MD5: 0f70ab283544f8dd3e5c7b2c27c34bbf
SHA256: 2ed5867e77e01c0d41eb1ba3069d0daff827c02d31b2f518c8afea6dbf322f95
2944
PVPubgVIP8.2 (di' cu~).EXE
C:\Users\admin\AppData\Local\Temp\~DF13AD4598A10EF06B.TMP
––
MD5:  ––
SHA256:  ––
3368
install.exe
C:\Users\admin\AppData\Local\Temp\dd_vcredistUI09BD.txt
text
MD5: 9f786764e6802361f0df371add7a988b
SHA256: 7e5302d82ccb3eb5ce39e16cfb6bdc95c848cd1916d1835b878919dcd6dd19ef

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
1
TCP/UDP connections
2
DNS requests
1
Threats
1

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
1480 453BE91F.EXE GET –– 2.18.233.19:80 http://download.microsoft.com/download/8/4/A/84A35BF1-DAFE-4AE8-82AF-AD2AE20B6B14/directx_Jun2010_redist.exe unknown
––
––
whitelisted

Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID Process IP ASN CN Reputation
1480 453BE91F.EXE 2.18.233.19:443 Akamai International B.V. –– whitelisted
1480 453BE91F.EXE 2.18.233.19:80 Akamai International B.V. –– whitelisted

DNS requests

Domain IP Reputation
download.microsoft.com 2.18.233.19
whitelisted

Threats

PID Process Class Message
1480 453BE91F.EXE Potential Corporate Privacy Violation ET POLICY PE EXE or DLL Windows file download HTTP

Debug output strings

Process Message
453BE91F.EXE %s------------------------------------------------ --- Themida Professional --- --- (c)2012 Oreans Technologies --- ------------------------------------------------
453BE91F.EXE %s------------------------------------------------ --- Themida Professional --- --- (c)2012 Oreans Technologies --- ------------------------------------------------
453BE91F.EXE %s------------------------------------------------ --- Themida Professional --- --- (c)2012 Oreans Technologies --- ------------------------------------------------