3180
chrome.exe
delete key
HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
3180
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
3180
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
1
3180
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
failed_count
0
3180
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BLBeacon
state
2
3180
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\ThirdParty
StatusCodes
01000000
3180
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
dr
1
3180
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
metricsid
3180
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
metricsid_installdate
0
3180
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome
UsageStatsInSample
0
3180
chrome.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
usagestats
0
3180
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
metricsid_enableddate
0
3180
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96}
lastrun
13217707737628250
3180
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\StabilityMetrics
user_experience_metrics.stability.exited_cleanly
0
3180
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
LanguageList
en-US
3180
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
3180
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
3180
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
3180
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000092000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
3180
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}\Enum
Implementing
1C00000001000000E3070B000500080011001D002000650300000000
3180
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Discardable\PostSetup\Component Categories\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}\Enum
Implementing
1C00000001000000E3070B000500080011001D002000670300000000
3180
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Common\Rlz\PTimes
C
3AEA10365A96D501
3180
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Common\Rlz\RLZs
C1
1C1GCEA_enUA812UA812
3180
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Common\Rlz\RLZs
C2
1C2GCEA_enUA812
3180
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Common\Rlz\RLZs
C7
1C7GCEA_enUA812
1944
chrome.exe
write
HKEY_CURRENT_USER\Software\Google\Chrome\BrowserExitCodes
3180-13217707736159500
259
748
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
LanguageList
en-US
748
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
@%SystemRoot%\system32\p2pcollab.dll,-8042
Peer to Peer Trust
748
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
@%SystemRoot%\system32\qagentrt.dll,-10
System Health Authentication
748
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
@%SystemRoot%\System32\fveui.dll,-844
BitLocker Data Recovery Agent
748
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
@%SystemRoot%\system32\dnsapi.dll,-103
Domain Name System (DNS) Server Trust
748
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
@%SystemRoot%\System32\fveui.dll,-843
BitLocker Drive Encryption
748
chrome.exe
write
HKEY_CURRENT_USER\Software\Microsoft\SystemCertificates\CA\Certificates\EAB040689A0D805B5D6FD654FC168CFF00B78BE3
Blob
030000000100000014000000EAB040689A0D805B5D6FD654FC168CFF00B78BE31400000001000000140000005379BF5AAA2B4ACF5480E1D89BC09DF2B20366CB040000000100000010000000DB78CBD190952735D940BC80AC2432C00F0000000100000030000000435FE6564241D6B3828352EF9BE443D511C21F0AFB325C4038A5820F00D87774A8EF2193DDAAE065B2572FAF2BF0EE63190000000100000010000000EA6089055218053DD01E37E1D806EEDF18000000010000001000000045ED9BBC5E43D3B9ECD63C060DB78E5C4B0000000100000044000000350034003500370041003800430045003400420032004100370034003900390046003800320039003900410030003100330042003600450031004300370043005F00000020000000010000007B050000308205773082045FA003020102021013EA28705BF4ECED0C36630980614336300D06092A864886F70D01010C0500306F310B300906035504061302534531143012060355040A130B416464547275737420414231263024060355040B131D41646454727573742045787465726E616C20545450204E6574776F726B312230200603550403131941646454727573742045787465726E616C20434120526F6F74301E170D3030303533303130343833385A170D3230303533303130343833385A308188310B3009060355040613025553311330110603550408130A4E6577204A6572736579311430120603550407130B4A65727365792043697479311E301C060355040A131554686520555345525452555354204E6574776F726B312E302C06035504031325555345525472757374205253412043657274696669636174696F6E20417574686F7269747930820222300D06092A864886F70D01010105000382020F003082020A028202010080126517360EC3DB08B3D0AC570D76EDCD27D34CAD508361E2AA204D092D6409DCCE899FCC3DA9ECF6CFC1DCF1D3B1D67B3728112B47DA39C6BC3A19B45FA6BD7D9DA36342B676F2A93B2B91F8E26FD0EC162090093EE2E874C918B491D46264DB7FA306F188186A90223CBCFE13F087147BF6E41F8ED4E451C61167460851CB8614543FBC33FE7E6C9CFF169D18BD518E35A6A766C87267DB2166B1D49B7803C0503AE8CCF0DCBC9E4CFEAF0596351F575AB7FFCEF93DB72CB6F654DDC8E7123A4DAE4C8AB75C9AB4B7203DCA7F2234AE7E3B68660144E7014E46539B3360F794BE5337907343F332C353EFDBAAFE744E69C76B8C6093DEC4C70CDFE132AECC933B517895678BEE3D56FE0CD0690F1B0FF325266B336DF76E47FA7343E57E0EA566B1297C3284635589C40DC19354301913ACD37D37A7EB5D3A6C355CDB41D712DAA9490BDFD8808A0993628EB566CF2588CD84B8B13FA4390FD9029EEB124C957CF36B05A95E1683CCB867E2E8139DCC5B82D34CB3ED5BFFDEE573AC233B2D00BF3555740949D849581A7F9236E651920EF3267D1C4D17BCC9EC4326D0BF415F40A94444F499E757879E501F5754A83EFD74632FB1506509E658422E431A4CB4F0254759FA041E93D426464A5081B2DEBE78B7FC6715E1C957841E0F63D6E962BAD65F552EEA5CC62808042539B80E2BA9F24C971C073F0D52F5EDEF2F820F0203010001A381F43081F1301F0603551D23041830168014ADBD987A34B426F7FAC42654EF03BDE024CB541A301D0603551D0E041604145379BF5AAA2B4ACF5480E1D89BC09DF2B20366CB300E0603551D0F0101FF040403020186300F0603551D130101FF040530030101FF30110603551D20040A300830060604551D200030440603551D1F043D303B3039A037A0358633687474703A2F2F63726C2E7573657274727573742E636F6D2F416464547275737445787465726E616C4341526F6F742E63726C303506082B0601050507010104293027302506082B060105050730018619687474703A2F2F6F6373702E7573657274727573742E636F6D300D06092A864886F70D01010C050003820101009365F63783950F5EC3821C1FD677E73C8AC0AA09F0E90B26F1E0C26A75A1C779C9B95260C829120EF0AD03D609C476DFE5A68195A746DA8257A99592C5B68F03226C3377C17B32176E07CE5A14413A05241BF614063BA825240EBBCC2A75DDB970413F7CD0633621071F46FF60A491E167BCDE1F7E1914C9636791EA67076BB48F8BC06E437DC3A1806CB21EBC53857DDC90A1A4BC2DEF4672573505BFBB46BB6E6D3799B6FF239291C66E40F88F2956EA5FD55F1453ACF04F61EAF722CCA7560BE2B8341F26D97B1905683FBA3CD43806A2D3E68F0EE3B4716D4042C584B440952BF465A04879F61D8163969D4F75E0F87CE48EA9D1F2AD8AB38CC721CDC2EF
2420
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
LanguageList
en-US
2420
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
@sendmail.dll,-4
Mail recipient
2420
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
@sendmail.dll,-21
Desktop (create shortcut)
2420
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
@zipfldr.dll,-10148
Compressed (zipped) folder
2420
chrome.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
@C:\Windows\system32\FXSRESM.dll,-120
Fax recipient
1448
msiexec.exe
delete key
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000_CLASSES\Local Settings\MuiCache\12B\52C64B7E
1448
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
1448
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback
1448
msiexec.exe
delete key
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
1448
msiexec.exe
delete key
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000_CLASSES\Local Settings\MuiCache\12B
1448
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress
1448
msiexec.exe
delete key
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\TempPackages
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppCreate (Enter)
40000000000000005D2AB0205A96D501A8050000C80C0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppGatherWriterMetadata (Enter)
400000000000000075373F215A96D501A8050000C80C0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
IDENTIFY (Enter)
4000000000000000CF9941215A96D501A8050000BC040000E803000001000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
IDENTIFY (Leave)
400000000000000095F3FD215A96D501A8050000BC040000E803000000000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
LastIndex
33
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
SrCreateRp (Enter)
40000000000000005D2AB0205A96D501A8050000C80C0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppGatherWriterMetadata (Leave)
4000000000000000D5C6DD275A96D501A8050000C80C0000D3070000010000000000000000000000000000000000000000000000000000000000000000000000
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppAddInterestingComponents (Enter)
4000000000000000D5C6DD275A96D501A8050000C80C0000D4070000000000000000000000000000000000000000000000000000000000000000000000000000
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppAddInterestingComponents (Leave)
4000000000000000A5D9F0275A96D501A8050000C80C0000D4070000010000000000000000000000000000000000000000000000000000000000000000000000
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
PREPAREBACKUP (Leave)
400000000000000007EB22285A96D501A8050000B8000000E903000000000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
PREPAREBACKUP (Enter)
400000000000000029B108285A96D501A8050000B8000000E903000001000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
FirstRun
0
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
DOSNAPSHOT (Leave)
4000000000000000496DC7285A96D501A8050000780900000A04000000000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
LastIndex
33
1448
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
SessionHash
90D8F16405E4B53E544A82C4F8B2D55EA8A30EC6AFEBE4607E7A0C625FC17543
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppCreate (Leave)
4000000000000000A3CFC9285A96D501A8050000C80C0000D0070000010000000000000000000000000000000000000000000000000000000000000000000000
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\Volatile
StartNesting
5D2AB0205A96D501
1448
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Sequence
1
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Config.Msi\
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress
C:\Windows\Installer\3ab146.ipi
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\3ab147.rbsLow
697279296
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
GETSTATE (Enter)
400000000000000007EB22285A96D501A805000018070000F903000001000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
GETSTATE (Leave)
4000000000000000BBAF27285A96D501A805000018070000F903000000000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
DOSNAPSHOT (Enter)
4000000000000000C9D62E285A96D501A8050000C80C00000A04000001000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts
C:\Config.Msi\3ab147.rbs
30774874
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
SrCreateRp (Leave)
4000000000000000A3CFC9285A96D501A8050000C80C0000D5070000010000000000000000000000000000000000000000000000000000000000000000000000
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\Volatile
NestingLevel
1
1448
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000
Owner
A8050000A8B4551B5A96D501
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Components\110CA4A8451179D4D8BA88BDF99B4A8D
42BFC51759BAC184291C853A947430D4
C:\ProgramData\
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Components\B51358D19DAA8CB4FBD80B76CBD85401
42BFC51759BAC184291C853A947430D4
C:\Users\admin\AppData\Roaming\Reservationless-Plus VoIP\
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Components\09C11E4CD08364D4381356E59977458C
42BFC51759BAC184291C853A947430D4
C:\Users\admin\AppData\Roaming\Reservationless-Plus VoIP\
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Components\CE872EE9F2DAAC641A803400263CAD8D
42BFC51759BAC184291C853A947430D4
C:\Users\admin\AppData\Roaming\Reservationless-Plus VoIP\SoftphoneAPI.dll
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Components\C2F873E95D4F59145A6C5B4D229FDB6C
42BFC51759BAC184291C853A947430D4
C:\Users\admin\AppData\Roaming\Reservationless-Plus VoIP\TSPHybridSDK.dll
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Components\4A5B515273B42C2448A444C6C8FB6863
42BFC51759BAC184291C853A947430D4
C:\Users\admin\AppData\Roaming\Reservationless-Plus VoIP\dvconference_client-2.dll
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Components\6B61FA2508C26B64CB07C58F0D1A9483
42BFC51759BAC184291C853A947430D4
C:\Users\admin\AppData\Roaming\Reservationless-Plus VoIP\dvsipclient-2.dll
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Components\E123669A0F6CBDE4A99F3105AAF6138F
42BFC51759BAC184291C853A947430D4
C:\Users\admin\AppData\Roaming\Reservationless-Plus VoIP\itcsoftphone.dll
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Components\218915EFB0068D64BADA25EC19D630CE
42BFC51759BAC184291C853A947430D4
C:\Users\admin\AppData\Roaming\Reservationless-Plus VoIP\
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Components\3AEEAD92CBD58884CB429A941A4D3AF2
42BFC51759BAC184291C853A947430D4
C:\Users\admin\AppData\Roaming\Reservationless-Plus VoIP\libeay32.dll
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Components\B07E551A2FC0E0743BC19F576E48BF3B
42BFC51759BAC184291C853A947430D4
C:\Users\admin\AppData\Roaming\Reservationless-Plus VoIP\msvcp90.dll
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Components\089FDFC0CB8BE044B94F8DBA4DC3127C
42BFC51759BAC184291C853A947430D4
C:\Users\admin\AppData\Roaming\Reservationless-Plus VoIP\msvcr90.dll
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Components\BC88B4619A94CF844A2F9AFBE449B07F
42BFC51759BAC184291C853A947430D4
C:\Users\admin\AppData\Roaming\Reservationless-Plus VoIP\rpvoip.exe
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Components\83C0668B4D897784D947F7CA6A4A197E
42BFC51759BAC184291C853A947430D4
C:\Users\admin\AppData\Roaming\Reservationless-Plus VoIP\
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Components\279251DB3B88CCF4DB215990742AFEC4
42BFC51759BAC184291C853A947430D4
C:\Users\admin\AppData\Roaming\Reservationless-Plus VoIP\ssleay32.dll
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Users\admin\AppData\Roaming\Reservationless-Plus VoIP\
1
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Users\admin\AppData\Roaming\Microsoft\Installer\
1448
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\WebEx\TSPSDK
ConferenceSoftphone
C:\Users\admin\AppData\Roaming\Reservationless-Plus VoIP\rpvoip.exe
1448
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\RPVoIP
ConferenceSoftphone
C:\Users\admin\AppData\Roaming\Reservationless-Plus VoIP\rpvoip.exe
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Products\42BFC51759BAC184291C853A947430D4\InstallProperties
RegOwner
admin
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Products\42BFC51759BAC184291C853A947430D4\InstallProperties
RegCompany
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Products\42BFC51759BAC184291C853A947430D4\InstallProperties
ProductID
none
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Products\42BFC51759BAC184291C853A947430D4\InstallProperties
LocalPackage
C:\Windows\Installer\3ab148.msi
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Products\42BFC51759BAC184291C853A947430D4\InstallProperties
AuthorizedCDFPrefix
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Products\42BFC51759BAC184291C853A947430D4\InstallProperties
Comments
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Products\42BFC51759BAC184291C853A947430D4\InstallProperties
Contact
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Products\42BFC51759BAC184291C853A947430D4\InstallProperties
DisplayVersion
5.19.07.004
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Products\42BFC51759BAC184291C853A947430D4\InstallProperties
HelpLink
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Products\42BFC51759BAC184291C853A947430D4\InstallProperties
HelpTelephone
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Products\42BFC51759BAC184291C853A947430D4\InstallProperties
InstallDate
20191108
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Products\42BFC51759BAC184291C853A947430D4\InstallProperties
InstallLocation
C:\Users\admin\AppData\Roaming\Reservationless-Plus VoIP\
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Products\42BFC51759BAC184291C853A947430D4\InstallProperties
InstallSource
C:\Users\admin\AppData\Local\Temp\{7451FFBE-E9C0-421B-B18E-0F1EC96EB7DE}\
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Products\42BFC51759BAC184291C853A947430D4\InstallProperties
Readme
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Products\42BFC51759BAC184291C853A947430D4\InstallProperties
EstimatedSize
18377
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Products\42BFC51759BAC184291C853A947430D4\InstallProperties
URLInfoAbout
http://www.intercall.com
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Products\42BFC51759BAC184291C853A947430D4\InstallProperties
VersionMajor
5
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Products\42BFC51759BAC184291C853A947430D4\InstallProperties
WindowsInstaller
1
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Products\42BFC51759BAC184291C853A947430D4\InstallProperties
Language
0
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{715CFB24-AB95-481C-92C1-58A34947034D}
VersionMinor
19
1448
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Installer\UpgradeCodes\56D10F68BBEAE4A429689CC30F8DDF91
42BFC51759BAC184291C853A947430D4
1448
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Installer\Products\42BFC51759BAC184291C853A947430D4\SourceList\Net
1
C:\Users\admin\AppData\Local\Temp\{7451FFBE-E9C0-421B-B18E-0F1EC96EB7DE}\
1448
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Installer\Products\42BFC51759BAC184291C853A947430D4\SourceList\Media
DiskPrompt
[1]
1448
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Installer\Products\42BFC51759BAC184291C853A947430D4\SourceList\Media
1
DISK1;1
1448
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Installer\Products\42BFC51759BAC184291C853A947430D4
Clients
:
1448
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Installer\Products\42BFC51759BAC184291C853A947430D4\SourceList
LastUsedSource
n;1;C:\Users\admin\AppData\Local\Temp\{7451FFBE-E9C0-421B-B18E-0F1EC96EB7DE}\
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\TempPackages
C:\Windows\Installer\3ab145.mst
0
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\Volatile
NestingLevel
0
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders
C:\Users\admin\AppData\Roaming\Microsoft\Installer\{715CFB24-AB95-481C-92C1-58A34947034D}\
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Products\42BFC51759BAC184291C853A947430D4\InstallProperties
ModifyPath
MsiExec.exe /I{715CFB24-AB95-481C-92C1-58A34947034D}
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Products\42BFC51759BAC184291C853A947430D4\InstallProperties
Publisher
InterCall, Inc.
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Products\42BFC51759BAC184291C853A947430D4\InstallProperties
Size
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Products\42BFC51759BAC184291C853A947430D4\InstallProperties
UninstallString
MsiExec.exe /I{715CFB24-AB95-481C-92C1-58A34947034D}
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Products\42BFC51759BAC184291C853A947430D4\InstallProperties
URLUpdateInfo
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Products\42BFC51759BAC184291C853A947430D4\InstallProperties
VersionMinor
19
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Products\42BFC51759BAC184291C853A947430D4\InstallProperties
Version
85131271
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{715CFB24-AB95-481C-92C1-58A34947034D}
AuthorizedCDFPrefix
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{715CFB24-AB95-481C-92C1-58A34947034D}
Comments
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{715CFB24-AB95-481C-92C1-58A34947034D}
Contact
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{715CFB24-AB95-481C-92C1-58A34947034D}
DisplayVersion
5.19.07.004
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{715CFB24-AB95-481C-92C1-58A34947034D}
HelpLink
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{715CFB24-AB95-481C-92C1-58A34947034D}
HelpTelephone
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{715CFB24-AB95-481C-92C1-58A34947034D}
InstallDate
20191108
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{715CFB24-AB95-481C-92C1-58A34947034D}
InstallLocation
C:\Users\admin\AppData\Roaming\Reservationless-Plus VoIP\
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{715CFB24-AB95-481C-92C1-58A34947034D}
InstallSource
C:\Users\admin\AppData\Local\Temp\{7451FFBE-E9C0-421B-B18E-0F1EC96EB7DE}\
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{715CFB24-AB95-481C-92C1-58A34947034D}
ModifyPath
MsiExec.exe /I{715CFB24-AB95-481C-92C1-58A34947034D}
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{715CFB24-AB95-481C-92C1-58A34947034D}
Publisher
InterCall, Inc.
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{715CFB24-AB95-481C-92C1-58A34947034D}
Readme
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{715CFB24-AB95-481C-92C1-58A34947034D}
Size
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{715CFB24-AB95-481C-92C1-58A34947034D}
EstimatedSize
18377
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{715CFB24-AB95-481C-92C1-58A34947034D}
UninstallString
MsiExec.exe /I{715CFB24-AB95-481C-92C1-58A34947034D}
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{715CFB24-AB95-481C-92C1-58A34947034D}
URLInfoAbout
http://www.intercall.com
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{715CFB24-AB95-481C-92C1-58A34947034D}
URLUpdateInfo
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{715CFB24-AB95-481C-92C1-58A34947034D}
VersionMajor
5
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{715CFB24-AB95-481C-92C1-58A34947034D}
WindowsInstaller
1
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{715CFB24-AB95-481C-92C1-58A34947034D}
Version
85131271
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{715CFB24-AB95-481C-92C1-58A34947034D}
Language
0
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\56D10F68BBEAE4A429689CC30F8DDF91
42BFC51759BAC184291C853A947430D4
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Products\42BFC51759BAC184291C853A947430D4\InstallProperties
DisplayName
Reservationless-Plus VoIP
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{715CFB24-AB95-481C-92C1-58A34947034D}
DisplayName
Reservationless-Plus VoIP
1448
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Installer\Features\42BFC51759BAC184291C853A947430D4
Reservationless_Plus_VoIP
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Products\42BFC51759BAC184291C853A947430D4\Features
Reservationless_Plus_VoIP
1448
msiexec.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-1302019708-1500728564-335382590-1000\Products\42BFC51759BAC184291C853A947430D4\Patches
AllPatches
1448
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Installer\Products\42BFC51759BAC184291C853A947430D4
ProductName
Reservationless-Plus VoIP
1448
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Installer\Products\42BFC51759BAC184291C853A947430D4
PackageCode
561522447EFAF92478C68C362577219F
1448
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Installer\Products\42BFC51759BAC184291C853A947430D4
Language
0
1448
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Installer\Products\42BFC51759BAC184291C853A947430D4
Version
85131271
1448
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Installer\Products\42BFC51759BAC184291C853A947430D4
Transforms
*26*Microsoft\Installer\{715CFB24-AB95-481C-92C1-58A34947034D}\1033.MST
1448
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Installer\Products\42BFC51759BAC184291C853A947430D4
Assignment
0
1448
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Installer\Products\42BFC51759BAC184291C853A947430D4
AdvertiseFlags
388
1448
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Installer\Products\42BFC51759BAC184291C853A947430D4
ProductIcon
%APPDATA%\Microsoft\Installer\{715CFB24-AB95-481C-92C1-58A34947034D}\ARPPRODUCTICON.exe
1448
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Installer\Products\42BFC51759BAC184291C853A947430D4
InstanceType
0
1448
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Installer\Products\42BFC51759BAC184291C853A947430D4
AuthorizedLUAApp
0
1448
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Installer\Products\42BFC51759BAC184291C853A947430D4
DeploymentFlags
2
1448
msiexec.exe
write
HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Installer\Products\42BFC51759BAC184291C853A947430D4\SourceList
PackageName
Reservationless-Plus VoIP.msi
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
IDENTIFY (Enter)
4000000000000000F90E57215A96D501F00F00008C080000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
IDENTIFY (Leave)
400000000000000007365E215A96D501F00F00006C090000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
IDENTIFY (Leave)
40000000000000006FBF67215A96D501F00F0000A0080000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
IDENTIFY (Enter)
4000000000000000F90E57215A96D501F00F00006C090000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
IDENTIFY (Leave)
4000000000000000BBFA62215A96D501F00F00006C090000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
IDENTIFY (Enter)
4000000000000000F90E57215A96D501F00F0000A0080000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
IDENTIFY (Leave)
4000000000000000155D65215A96D501F00F00008C080000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
IDENTIFY (Enter)
400000000000000007365E215A96D501F00F00006C090000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_BEGINPREPARE (Leave)
400000000000000029B108285A96D501F00F0000A00800000104000000000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_STABLE (SetCurrentState)
4000000000000000913A12285A96D501F00F00006C0900000100000001000000010000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_STABLE (SetCurrentState)
4000000000000000913A12285A96D501F00F0000A00800000100000001000000010000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
GETSTATE (Enter)
4000000000000000BBAF27285A96D501F00F0000A0080000F903000001000000010000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
GETSTATE (Leave)
4000000000000000BBAF27285A96D501F00F0000A0080000F903000000000000010000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_ENDPREPARE (Leave)
40000000000000002BE860285A96D501F00F0000580800000204000000000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPARESNAPSHOT (Leave)
4000000000000000BDE67F285A96D501F00F0000FC090000EA03000000000000010000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
PREPARESNAPSHOT (Leave)
40000000000000004FE59E285A96D501F00F000058080000EA03000000000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_FRONT (Enter)
40000000000000004FE59E285A96D501F00F000058080000EC03000001000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
GETSTATE (Leave)
4000000000000000BBAF27285A96D501F00F00008C080000F903000000000000010000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_BEGINPREPARE (Enter)
400000000000000029B108285A96D501F00F0000A00800000104000001000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPAREBACKUP (Enter)
4000000000000000DD750D285A96D501F00F00008C080000E903000001000000010000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPAREBACKUP (Leave)
400000000000000037D80F285A96D501F00F00008C080000E903000000000000010000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_STABLE (SetCurrentState)
400000000000000037D80F285A96D501F00F00008C0800000100000001000000010000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPAREBACKUP (Leave)
4000000000000000913A12285A96D501F00F00006C090000E903000000000000010000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_WAITING_FOR_THAW (SetCurrentState)
400000000000000003AAA3285A96D501F00F0000E00300000300000001000000020000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_BACK (Leave)
40000000000000005D0CA6285A96D501F00F000058080000ED03000000000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_WAITING_FOR_THAW (SetCurrentState)
4000000000000000B76EA8285A96D501F00F00007C0900000300000001000000020000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_KTM (Leave)
400000000000000011D1AA285A96D501F00F000058080000F003000000000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_WAITING_FOR_THAW (SetCurrentState)
40000000000000001FF8B1285A96D501F00F00007C0900000300000001000000020000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_PRECOMMIT (Enter)
40000000000000001FF8B1285A96D501F00F0000580800000304000001000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
OPEN_VOLUME_HANDLE (Leave)
40000000000000008781BB285A96D501F00F00007C070000FD03000000000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
IOCTL_RELEASE (Enter)
4000000000000000496DC7285A96D501F00F00007C070000FF03000001000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
IOCTL_RELEASE (Enter)
4000000000000000496DC7285A96D501F00F000058080000FF030000010000000000000000000000000000000000000000000000000000000000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_POSTCOMMIT (Enter)
4000000000000000496DC7285A96D501F00F0000580800000504000001000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
THAW (Enter)
4000000000000000FD31CC285A96D501F00F0000FC090000F203000001000000030000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
THAW (Enter)
40000000000000005794CE285A96D501F00F000000090000F203000001000000030000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
THAW (Leave)
40000000000000005794CE285A96D501F00F000000090000F203000000000000030000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
BKGND_FREEZE_THREAD (Leave)
40000000000000005794CE285A96D501F00F000048010000FC03000000000000030000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
THAW (Leave)
40000000000000005794CE285A96D501F00F0000E0030000F203000000000000030000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
THAW (Leave)
40000000000000005794CE285A96D501F00F0000FC090000F203000000000000030000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
THAW (Leave)
40000000000000005794CE285A96D501F00F000058080000F203000000000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
BKGND_FREEZE_THREAD (Enter)
400000000000000003AAA3285A96D501F00F000048010000FC03000001000000030000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_SYSTEM (Enter)
40000000000000005D0CA6285A96D501F00F000058080000EE03000001000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
BKGND_FREEZE_THREAD (Enter)
4000000000000000B76EA8285A96D501F00F0000A8090000FC03000001000000030000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_RM (Enter)
400000000000000011D1AA285A96D501F00F000058080000EF03000001000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
BKGND_FREEZE_THREAD (Enter)
40000000000000001FF8B1285A96D501F00F0000EC010000FC03000001000000030000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_PRECOMMIT (Leave)
40000000000000001FF8B1285A96D501F00F0000580800000304000000000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
OPEN_VOLUME_HANDLE (Leave)
40000000000000008781BB285A96D501F00F000058080000FD03000000000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
IOCTL_RELEASE (Leave)
4000000000000000496DC7285A96D501F00F00007C070000FF03000000000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
IOCTL_RELEASE (Leave)
4000000000000000496DC7285A96D501F00F000058080000FF030000000000000000000000000000000000000000000000000000000000000000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_POSTCOMMIT (Leave)
4000000000000000496DC7285A96D501F00F0000580800000504000000000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
THAW (Enter)
4000000000000000496DC7285A96D501F00F000058080000F203000001000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
BKGND_FREEZE_THREAD (Leave)
4000000000000000FD31CC285A96D501F00F0000A8090000FC03000000000000030000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_WAITING_FOR_POST_SNAPSHOT (SetCurrentState)
40000000000000005794CE285A96D501F00F0000000900000400000001000000030000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_WAITING_FOR_POST_SNAPSHOT (SetCurrentState)
40000000000000005794CE285A96D501F00F0000E00300000400000001000000030000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_WAITING_FOR_POST_SNAPSHOT (SetCurrentState)
40000000000000005794CE285A96D501F00F0000FC0900000400000001000000030000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_PREFINALCOMMIT (Enter)
40000000000000005794CE285A96D501F00F0000580800000604000001000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
GETSTATE (Enter)
4000000000000000BBAF27285A96D501F00F00008C080000F903000001000000010000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_ENDPREPARE (Enter)
4000000000000000C9D62E285A96D501F00F0000580800000204000001000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPARESNAPSHOT (Leave)
400000000000000063847D285A96D501F00F00007C090000EA03000000000000010000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)
4000000000000000BDE67F285A96D501F00F0000FC0900000200000001000000010000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
FREEZE (Enter)
400000000000000003AAA3285A96D501F00F0000E0030000EB03000001000000020000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_FRONT (Leave)
400000000000000003AAA3285A96D501F00F000058080000EC03000000000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
FREEZE (Enter)
4000000000000000B76EA8285A96D501F00F00007C090000EB03000001000000020000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_SYSTEM (Leave)
400000000000000011D1AA285A96D501F00F000058080000EE03000000000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
FREEZE (Enter)
40000000000000006B33AD285A96D501F00F00007C090000EB03000001000000020000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_RM (Leave)
40000000000000001FF8B1285A96D501F00F000058080000EF03000000000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
OPEN_VOLUME_HANDLE (Enter)
40000000000000001FF8B1285A96D501F00F000058080000FD03000001000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
IOCTL_FLUSH_AND_HOLD (Enter)
40000000000000008781BB285A96D501F00F00007C070000FE03000001000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
IOCTL_FLUSH_AND_HOLD (Enter)
40000000000000008781BB285A96D501F00F000058080000FE03000001000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_COMMIT (Enter)
4000000000000000496DC7285A96D501F00F0000900300000404000001000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
THAW_KTM (Enter)
4000000000000000496DC7285A96D501F00F000058080000F403000001000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
BKGND_FREEZE_THREAD (Leave)
40000000000000005794CE285A96D501F00F0000EC010000FC03000000000000030000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
POSTSNAPSHOT (Enter)
4000000000000000212F0A295A96D501F00F000058080000F503000001000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
POSTSNAPSHOT (Enter)
4000000000000000D5F30E295A96D501F00F0000E0030000F503000001000000040000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
POSTSNAPSHOT (Leave)
4000000000000000D5F30E295A96D501F00F0000E0030000F503000000000000040000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_WAITING_FOR_BACKUP_COMPLETE (SetCurrentState)
4000000000000000D5F30E295A96D501F00F0000E00300000500000001000000040000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
POSTSNAPSHOT (Leave)
4000000000000000D5F30E295A96D501F00F00007C090000F503000000000000040000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_WAITING_FOR_BACKUP_COMPLETE (SetCurrentState)
4000000000000000D5F30E295A96D501F00F00007C0900000500000001000000040000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
POSTSNAPSHOT (Enter)
4000000000000000D5F30E295A96D501F00F00007C090000F503000001000000040000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPAREBACKUP (Enter)
4000000000000000DD750D285A96D501F00F0000A0080000E903000001000000010000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPAREBACKUP (Enter)
4000000000000000DD750D285A96D501F00F00006C090000E903000001000000010000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPAREBACKUP (Leave)
4000000000000000913A12285A96D501F00F0000A0080000E903000000000000010000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
GETSTATE (Enter)
4000000000000000BBAF27285A96D501F00F00006C090000F903000001000000010000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
GETSTATE (Leave)
4000000000000000BBAF27285A96D501F00F00006C090000F903000000000000010000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
PREPARESNAPSHOT (Enter)
40000000000000002BE860285A96D501F00F000058080000EA03000001000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPARESNAPSHOT (Enter)
4000000000000000DFAC65285A96D501F00F00007C090000EA03000001000000010000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPARESNAPSHOT (Enter)
4000000000000000DFAC65285A96D501F00F000028090000EA03000001000000010000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPARESNAPSHOT (Enter)
4000000000000000DFAC65285A96D501F00F0000FC090000EA03000001000000010000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPARESNAPSHOT (Leave)
4000000000000000AFBF78285A96D501F00F000028090000EA03000000000000010000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)
4000000000000000AFBF78285A96D501F00F0000280900000200000001000000010000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)
400000000000000063847D285A96D501F00F00007C0900000200000001000000010000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE (Enter)
40000000000000004FE59E285A96D501F00F000058080000EB03000001000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_PREFINALCOMMIT (Leave)
4000000000000000212F0A295A96D501F00F0000580800000604000000000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
POSTSNAPSHOT (Enter)
4000000000000000D5F30E295A96D501F00F000000090000F503000001000000040000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
FREEZE (Leave)
400000000000000003AAA3285A96D501F00F0000E0030000EB03000000000000020000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_BACK (Enter)
400000000000000003AAA3285A96D501F00F000058080000ED03000001000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
FREEZE (Leave)
4000000000000000B76EA8285A96D501F00F00007C090000EB03000000000000020000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_KTM (Enter)
400000000000000011D1AA285A96D501F00F000058080000F003000001000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
FREEZE (Leave)
40000000000000001FF8B1285A96D501F00F00007C090000EB03000000000000020000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE (Leave)
40000000000000001FF8B1285A96D501F00F000058080000EB03000000000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
OPEN_VOLUME_HANDLE (Enter)
40000000000000001FF8B1285A96D501F00F00007C070000FD03000001000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
IOCTL_FLUSH_AND_HOLD (Leave)
4000000000000000496DC7285A96D501F00F00007C070000FE03000000000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
IOCTL_FLUSH_AND_HOLD (Leave)
4000000000000000496DC7285A96D501F00F000058080000FE03000000000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_COMMIT (Leave)
4000000000000000496DC7285A96D501F00F0000900300000404000000000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
THAW_KTM (Leave)
4000000000000000496DC7285A96D501F00F000058080000F403000000000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
THAW (Enter)
40000000000000005794CE285A96D501F00F0000E0030000F203000001000000030000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
POSTSNAPSHOT (Leave)
40000000000000002B1592295A96D501F00F000000090000F503000000000000040000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_WAITING_FOR_BACKUP_COMPLETE (SetCurrentState)
40000000000000002B1592295A96D501F00F0000000900000500000001000000040000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
POSTSNAPSHOT (Leave)
40000000000000002B1592295A96D501F00F000058080000F503000000000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_POSTFINALCOMMIT (Enter)
40000000000000002B1592295A96D501F00F0000580800000704000001000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_POSTFINALCOMMIT (Leave)
4000000000000000558AA7295A96D501F00F0000580800000704000000000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
BACKUPSHUTDOWN (Enter)
40000000000000007FFFBC295A96D501F00F000058080000FB03000001000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
BACKUPSHUTDOWN (Enter)
4000000000000000D961BF295A96D501F00F000000090000FB03000001000000050000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
BACKUPSHUTDOWN (Leave)
4000000000000000D961BF295A96D501F00F000000090000FB03000000000000050000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
BACKUPSHUTDOWN (Enter)
4000000000000000D961BF295A96D501F00F000000090000FB03000001000000050000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
BACKUPSHUTDOWN (Leave)
4000000000000000D961BF295A96D501F00F000000090000FB03000000000000050000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
BACKUPSHUTDOWN (Enter)
400000000000000033C4C1295A96D501F00F0000FC090000FB03000001000000050000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
BACKUPSHUTDOWN (Leave)
400000000000000033C4C1295A96D501F00F0000FC090000FB03000000000000050000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000
4080
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
BACKUPSHUTDOWN (Leave)
400000000000000033C4C1295A96D501F00F000058080000FB03000000000000000000000000000051666589E9B72C47BDFCF94C0F49AAE20000000000000000