General Info Watch the FULL Interactive Analysis at ANY.RUN!

File name

5e2b3771c665c2538cde7cbd4e5595793044adeaaad853ab5a8d9f4260b1460f

Verdict
Malicious activity
Analysis date
2/11/2019, 09:25:02
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows, MS CAB-Installer self-extracting archive
MD5

a157a168e6ec68743ccd84129958f07b

SHA1

823957d5d9dea9c0da5d92066f447eae690f78ec

SHA256

5e2b3771c665c2538cde7cbd4e5595793044adeaaad853ab5a8d9f4260b1460f

SSDEEP

12288:FGvjp5cj35kDB9hrs3zARBSaJSXi15mN9bFm3LIIh:KukDF4zARUwSXImNZUxh

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads dropped or rewritten executable
  • explorer.exe (PID: 284)
  • dwm.exe (PID: 1988)
  • 5e2b3771c665c2538cde7cbd4e5595793044adeaaad853ab5a8d9f4260b1460f.exe (PID: 3492)
  • dxwsetup.exe (PID: 2664)
  • DllHost.exe (PID: 3892)
Changes the autorun value in the registry
  • 5e2b3771c665c2538cde7cbd4e5595793044adeaaad853ab5a8d9f4260b1460f.exe (PID: 3492)
Application was dropped or rewritten from another process
  • dxwsetup.exe (PID: 2664)
Executable content was dropped or overwritten
  • 5e2b3771c665c2538cde7cbd4e5595793044adeaaad853ab5a8d9f4260b1460f.exe (PID: 3492)
  • dxwsetup.exe (PID: 2664)
Creates COM task schedule object
  • dxwsetup.exe (PID: 2664)
Searches for installed software
  • DllHost.exe (PID: 3892)
  • dxwsetup.exe (PID: 2664)
Removes files from Windows directory
  • dxwsetup.exe (PID: 2664)
Creates files in the Windows directory
  • dxwsetup.exe (PID: 2664)
Low-level read access rights to disk partition
  • vssvc.exe (PID: 2892)
Reads settings of System Certificates
  • dxwsetup.exe (PID: 2664)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable MS Visual C++ (generic) (42.2%)
.exe
|   Win64 Executable (generic) (37.3%)
.dll
|   Win32 Dynamic Link Library (generic) (8.8%)
.exe
|   Win32 Executable (generic) (6%)
.exe
|   Generic Win/DOS Executable (2.7%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2001:08:18 03:42:57+02:00
PEType:
PE32
LinkerVersion:
7
CodeSize:
34816
InitializedDataSize:
246272
UninitializedDataSize:
null
EntryPoint:
0x48000
OSVersion:
5.1
ImageVersion:
5.1
SubsystemVersion:
4
Subsystem:
Windows GUI
FileVersionNumber:
6.0.2600.0
ProductVersionNumber:
6.0.2600.0
FileFlagsMask:
0x003f
FileFlags:
(none)
FileOS:
Windows NT 32-bit
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
English (U.S.)
CharacterSet:
Unicode
CompanyName:
Microsoft Corporation
FileDescription:
DirectX 9.0 Web setup
FileVersion:
9.29.1962.0
InternalName:
DXWebSetup
LegalCopyright:
Copyright (c) Microsoft Corporation. All rights reserved.
OriginalFileName:
dxwebsetup.exe
ProductName:
Microsoft® Windows® Operating System
ProductVersion:
9.29.1962.0
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
18-Aug-2001 01:42:57
Detected languages
English - United States
Debug artifacts
.pdb
CompanyName:
Microsoft Corporation
FileDescription:
DirectX 9.0 Web setup
FileVersion:
9.29.1962.0
InternalName:
DXWebSetup
LegalCopyright:
Copyright (c) Microsoft Corporation. All rights reserved.
OriginalFilename:
dxwebsetup.exe
ProductName:
Microsoft® Windows® Operating System
ProductVersion:
9.29.1962.0
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x000000C8
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
4
Time date stamp:
18-Aug-2001 01:42:57
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x0000861A 0x00008800 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 6.55103
.data 0x0000A000 0x00001BE4 0x00000400 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 4.18428
.rsrc 0x0000C000 0x0003C000 0x0003BE00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 7.82577
.mjg\x07 0x00048000 0x00001000 0x00000600 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 6.96134
Resources
1

2

63

76

77

80

83

85

2001

2002

2003

2004

2005

2006

3000

3001

ADMQCMD

CABINET

EXTRACTOPT

FILESIZES

FINISHMSG

LICENSE

PACKINSTSPACE

POSTRUNPROGRAM

REBOOT

RUNPROGRAM

SHOWWINDOW

TITLE

UPROMPT

USRQCMD

Imports
    ADVAPI32.dll

    KERNEL32.dll

    GDI32.dll

    USER32.dll

    COMCTL32.dll

    VERSION.dll

Exports

    No exports.

Screenshots

Processes

Total processes
39
Monitored processes
8
Malicious processes
3
Suspicious processes
0

Behavior graph

+
drop and start start 5e2b3771c665c2538cde7cbd4e5595793044adeaaad853ab5a8d9f4260b1460f.exe no specs 5e2b3771c665c2538cde7cbd4e5595793044adeaaad853ab5a8d9f4260b1460f.exe dxwsetup.exe explorer.exe no specs vssvc.exe no specs SPPSurrogate no specs dwm.exe no specs drvinst.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
1988
CMD
"C:\Windows\system32\Dwm.exe"
Path
C:\Windows\System32\dwm.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Desktop Window Manager
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\dwm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\dwmredir.dll
c:\windows\system32\dwmcore.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\ole32.dll
c:\windows\system32\d3d10_1.dll
c:\windows\system32\d3d10_1core.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\users\admin\appdata\local\temp\ixded52.tmp
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\mpr.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll

PID
284
CMD
C:\Windows\Explorer.EXE
Path
C:\Windows\explorer.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Windows Explorer
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\slc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\profapi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\iconcodecservice.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sndvolsso.dll
c:\windows\system32\hid.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\timedate.cpl
c:\windows\system32\atl.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\actxprxy.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\userenv.dll
c:\windows\system32\shacct.dll
c:\windows\system32\samlib.dll
c:\windows\system32\samcli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\msftedit.dll
c:\windows\system32\msls31.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\authui.dll
c:\windows\system32\cryptui.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\gameux.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\wer.dll
c:\windows\system32\msiltcfg.dll
c:\windows\system32\version.dll
c:\windows\system32\msi.dll
c:\windows\system32\winsta.dll
c:\windows\system32\psapi.dll
c:\windows\system32\networkexplorer.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wdmaud.drv
c:\windows\system32\ksuser.dll
c:\windows\system32\avrt.dll
c:\windows\system32\audioses.dll
c:\windows\system32\msacm32.drv
c:\windows\system32\msacm32.dll
c:\windows\system32\midimap.dll
c:\windows\system32\stobject.dll
c:\windows\system32\batmeter.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\es.dll
c:\windows\system32\prnfldr.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dxp.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\syncreg.dll
c:\windows\ehome\ehsso.dll
c:\windows\system32\netshell.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\alttab.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
c:\program files\filezilla ftp client\fzshellext.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\pnidui.dll
c:\windows\system32\qutil.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\npmproxy.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\wlanapi.dll
c:\windows\system32\wlanutil.dll
c:\windows\system32\wwanapi.dll
c:\windows\system32\wwapi.dll
c:\windows\system32\qagent.dll
c:\windows\system32\srchadmin.dll
c:\windows\system32\sxs.dll
c:\windows\system32\bthprops.cpl
c:\windows\system32\winanr.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\synccenter.dll
c:\windows\system32\actioncenter.dll
c:\windows\system32\imapi2.dll
c:\windows\system32\hgcpl.dll
c:\windows\system32\provsvc.dll
c:\windows\system32\netprofm.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\fxsst.dll
c:\windows\system32\fxsapi.dll
c:\windows\system32\fxsresm.dll
c:\windows\system32\wscinterop.dll
c:\windows\system32\wscapi.dll
c:\windows\system32\wscui.cpl
c:\windows\system32\werconcpl.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\wercplsupport.dll
c:\windows\system32\msxml6.dll
c:\windows\system32\hcproviders.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\mpr.dll
c:\windows\system32\drprov.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\thumbcache.dll
c:\users\admin\appdata\local\temp\5e2b3771c665c2538cde7cbd4e5595793044adeaaad853ab5a8d9f4260b1460f.exe
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\users\admin\appdata\local\temp\ixded52.tmp
c:\windows\system32\wsock32.dll
c:\users\admin\appdata\local\temp\ixp000.tmp\dxwsetup.exe

PID
3092
CMD
"C:\Users\admin\AppData\Local\Temp\5e2b3771c665c2538cde7cbd4e5595793044adeaaad853ab5a8d9f4260b1460f.exe"
Path
C:\Users\admin\AppData\Local\Temp\5e2b3771c665c2538cde7cbd4e5595793044adeaaad853ab5a8d9f4260b1460f.exe
Indicators
No indicators
Parent process
explorer.exe
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
Microsoft Corporation
Description
DirectX 9.0 Web setup
Version
9.29.1962.0
Modules
Image
c:\users\admin\appdata\local\temp\5e2b3771c665c2538cde7cbd4e5595793044adeaaad853ab5a8d9f4260b1460f.exe
c:\systemroot\system32\ntdll.dll

PID
3492
CMD
"C:\Users\admin\AppData\Local\Temp\5e2b3771c665c2538cde7cbd4e5595793044adeaaad853ab5a8d9f4260b1460f.exe"
Path
C:\Users\admin\AppData\Local\Temp\5e2b3771c665c2538cde7cbd4e5595793044adeaaad853ab5a8d9f4260b1460f.exe
Indicators
Parent process
explorer.exe
User
admin
Integrity Level
HIGH
Version:
Company
Microsoft Corporation
Description
DirectX 9.0 Web setup
Version
9.29.1962.0
Modules
Image
c:\users\admin\appdata\local\temp\5e2b3771c665c2538cde7cbd4e5595793044adeaaad853ab5a8d9f4260b1460f.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\version.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\users\admin\appdata\local\temp\ixded52.tmp
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\advpack.dll
c:\users\admin\appdata\local\temp\ixp000.tmp\dxwsetup.exe

PID
2664
CMD
C:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxwsetup.exe
Path
C:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxwsetup.exe
Indicators
Parent process
5e2b3771c665c2538cde7cbd4e5595793044adeaaad853ab5a8d9f4260b1460f.exe
User
admin
Integrity Level
HIGH
Version:
Company
Microsoft Corporation
Description
DirectX Setup
Version
4.9.0.0904
Modules
Image
c:\users\admin\appdata\local\temp\ixp000.tmp\dxwsetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\version.dll
c:\windows\system32\ole32.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advpack.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\spinf.dll
c:\windows\system32\spfileq.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\cryptbase.dll
c:\users\admin\appdata\local\temp\ixded52.tmp
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\directx\websetup\dsetup.dll
c:\windows\system32\directx\websetup\dsetup32.dll
c:\windows\system32\ntkrnlpa.exe
c:\windows\system32\clbcatq.dll
c:\windows\system32\inseng.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\users\admin\appdata\local\temp\ixp000.tmp\dxupdate.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll
c:\windows\microsoft.net\framework\v2.0.50727\fusion.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\srclient.dll
c:\windows\system32\spp.dll
c:\windows\system32\vssapi.dll
c:\windows\system32\atl.dll
c:\windows\system32\vsstrace.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\vss_ps.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\es.dll
c:\windows\system32\sxs.dll
c:\windows\system32\propsys.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll
c:\windows\system32\sxproxy.dll
c:\users\admin\appdata\local\temp\dxae70.tmp\dxupdate.dll
c:\users\admin\appdata\local\temp\dxae70.tmp\microsoft.directx.direct3dx.dll
c:\windows\system32\xactengine2_0.dll
c:\windows\system32\dsound.dll
c:\windows\system32\powrprof.dll
c:\users\admin\appdata\local\temp\dxae70.tmp\microsoft.directx.dll
c:\users\admin\appdata\local\temp\dxae70.tmp\microsoft.directx.audiovideoplayback.dll
c:\users\admin\appdata\local\temp\dxae70.tmp\microsoft.directx.diagnostics.dll
c:\users\admin\appdata\local\temp\dxae70.tmp\microsoft.directx.direct3d.dll
c:\users\admin\appdata\local\temp\dxae70.tmp\microsoft.directx.directdraw.dll
c:\users\admin\appdata\local\temp\dxae70.tmp\microsoft.directx.directinput.dll
c:\users\admin\appdata\local\temp\dxae70.tmp\microsoft.directx.directplay.dll
c:\users\admin\appdata\local\temp\dxae70.tmp\microsoft.directx.directsound.dll
c:\windows\system32\x3daudio1_0.dll
c:\users\admin\appdata\local\temp\dxae70.tmp\x3daudio1_0.dll
c:\windows\system32\xactengine2_1.dll
c:\windows\system32\xactengine2_2.dll
c:\windows\system32\xactengine2_3.dll
c:\windows\system32\xactengine2_4.dll
c:\windows\system32\x3daudio1_1.dll
c:\users\admin\appdata\local\temp\dxae70.tmp\x3daudio1_1.dll
c:\windows\system32\setc569.tmp
c:\windows\system32\xactengine2_5.dll
c:\windows\system32\x3daudio1_1
c:\windows\system32\setc5e8.tmp
c:\windows\system32\xactengine2_6.dll
c:\windows\system32\setc725.tmp
c:\windows\system32\xactengine2_7.dll
c:\windows\system32\xactengine2_8.dll
c:\windows\system32\x3daudio1_2.dll
c:\users\admin\appdata\local\temp\dxae70.tmp\x3daudio1_2.dll
c:\windows\system32\setc963.tmp
c:\windows\system32\xactengine2_9.dll
c:\windows\system32\x3daudio1_2
c:\windows\system32\setca80.tmp
c:\windows\system32\xactengine2_10.dll
c:\windows\system32\xactengine3_0.dll
c:\windows\system32\xaudio2_0.dll
c:\windows\system32\xactengine3_1.dll
c:\windows\system32\xaudio2_1.dll
c:\windows\system32\xactengine3_2.dll
c:\windows\system32\xaudio2_2.dll
c:\windows\system32\xactengine3_3.dll
c:\windows\system32\xaudio2_3.dll

PID
2892
CMD
C:\Windows\system32\vssvc.exe
Path
C:\Windows\system32\vssvc.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Microsoft® Volume Shadow Copy Service
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\vssvc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\atl.dll
c:\windows\system32\ole32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\vssapi.dll
c:\windows\system32\vsstrace.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\clusapi.dll
c:\windows\system32\cryptdll.dll
c:\windows\system32\xolehlp.dll
c:\windows\system32\version.dll
c:\windows\system32\resutils.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\authz.dll
c:\windows\system32\virtdisk.dll
c:\windows\system32\fltlib.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\vss_ps.dll
c:\windows\system32\samlib.dll
c:\windows\system32\es.dll
c:\windows\system32\propsys.dll
c:\windows\system32\catsrvut.dll
c:\windows\system32\mfcsubs.dll
c:\windows\system32\sxs.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll

PID
3892
CMD
C:\Windows\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801}
Path
C:\Windows\system32\DllHost.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
COM Surrogate
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\dllhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\users\admin\appdata\local\temp\ixded52.tmp
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\mpr.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\spp.dll
c:\windows\system32\vssapi.dll
c:\windows\system32\atl.dll
c:\windows\system32\vsstrace.dll
c:\windows\system32\sxproxy.dll
c:\windows\system32\vss_ps.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\es.dll
c:\windows\system32\sxs.dll
c:\windows\system32\propsys.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll

PID
3840
CMD
DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot18" "" "" "6792c44eb" "00000000" "000003C0" "000005BC"
Path
C:\Windows\system32\DrvInst.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Driver Installation Module
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\spinf.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\spfileq.dll

Registry activity

Total events
938
Read events
529
Write events
409
Delete events
0

Modification events

PID
Process
Operation
Key
Name
Value
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer
PINF
0700433A5C55736572735C61646D696E5C417070446174615C4C6F63616C5C54656D705C697864454435322E746D7000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\NccQngn\Ybpny\Grzc\VKC000.GZC\qkjfrghc.rkr
00000000000000000000000000000000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002E0000003D00000085431500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\NccQngn\Ybpny\Grzc\VKC000.GZC\qkjfrghc.rkr
000000000000000000000000E3090000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002E0000003D000000684D1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
3492
5e2b3771c665c2538cde7cbd4e5595793044adeaaad853ab5a8d9f4260b1460f.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
wextract_cleanup0
rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\admin\AppData\Local\Temp\IXP000.TMP\"
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SetupapiLogStatus
setupapi.app.log
4096
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dxwsetup_RASAPI32
EnableFileTracing
0
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dxwsetup_RASAPI32
EnableConsoleTracing
0
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dxwsetup_RASAPI32
FileTracingMask
4294901760
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dxwsetup_RASAPI32
ConsoleTracingMask
4294901760
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dxwsetup_RASAPI32
MaxFileSize
1048576
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dxwsetup_RASAPI32
FileDirectory
%windir%\tracing
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dxwsetup_RASMANCS
EnableFileTracing
0
2664
dxwsetup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dxwsetup_RASMANCS
EnableConsoleTracing
0
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dxwsetup_RASMANCS
FileTracingMask
4294901760
2664
dxwsetup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dxwsetup_RASMANCS
ConsoleTracingMask
4294901760
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dxwsetup_RASMANCS
MaxFileSize
1048576
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dxwsetup_RASMANCS
FileDirectory
%windir%\tracing
2664
dxwsetup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2664
dxwsetup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2664
dxwsetup.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
SrCreateRp (Enter)
400000000000000088DFC669E3C1D401680A00005C0A0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppCreate (Enter)
400000000000000088DFC669E3C1D401680A00005C0A0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
LastIndex
20
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppGatherWriterMetadata (Enter)
4000000000000000063F076AE3C1D401680A00005C0A0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
IDENTIFY (Enter)
400000000000000060A1096AE3C1D401680A000020090000E8030000010000000000000000000000CFC4F3FCE7B54242A51FCF76B3360A950000000000000000
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
IDENTIFY (Leave)
4000000000000000F29F286AE3C1D401680A000020090000E8030000000000000000000000000000CFC4F3FCE7B54242A51FCF76B3360A950000000000000000
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppGatherWriterMetadata (Leave)
4000000000000000A6642D6AE3C1D401680A00005C0A0000D3070000010000000000000000000000000000000000000000000000000000000000000000000000
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppCreate (Leave)
4000000000000000A6642D6AE3C1D401680A00005C0A0000D007000001000000000000000A010081CFC4F3FCE7B54242A51FCF76B3360A950000000000000000
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
SrCreateRp (Leave)
4000000000000000A6642D6AE3C1D401680A00005C0A0000D507000001000000000000000A010081000000000000000000000000000000000000000000000000
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
SrCreateRp (Enter)
4000000000000000A6642D6AE3C1D401680A00005C0A0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
SrCreateRp (Leave)
4000000000000000C0890A71E3C1D401680A00005C0A0000D5070000010000000000000000000000000000000000000000000000000000000000000000000000
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
FirstRun
0
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
LastIndex
21
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\Volatile
NestingLevel
0
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\Volatile
StartNesting
0000000000000000
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
582
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
73
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
582
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.DirectX.Direct3DX,1.0.2902.0,,31bf3856ad364e35
8610F872E3C1D401
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
SystemStoreChangeId
582
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\References\Microsoft.DirectX.Direct3DX, Version=1.0.2902.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35\{2EC93463-B0C3-45E1-8364-327E96AEA856}
{75339C8C-B4BA-463B-BAC7-975FCA2F89D9}
DirectX for Managed Code
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AssemblyFolders\DX_1.0.2902.0
C:\Windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
583
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
74
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
583
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.DirectX.Direct3DX,1.0.2903.0,,31bf3856ad364e35
180F1773E3C1D401
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
SystemStoreChangeId
583
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\References\Microsoft.DirectX.Direct3DX, Version=1.0.2903.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35\{2EC93463-B0C3-45E1-8364-327E96AEA856}
{75339C8C-B4BA-463B-BAC7-975FCA2F89D9}
DirectX for Managed Code
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AssemblyFolders\DX_1.0.2903.0
C:\Windows\Microsoft.NET\DirectX for Managed Code\1.0.2903.0\
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
584
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
75
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
584
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.DirectX.Direct3DX,1.0.2904.0,,31bf3856ad364e35
80982073E3C1D401
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
SystemStoreChangeId
584
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\References\Microsoft.DirectX.Direct3DX, Version=1.0.2904.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35\{2EC93463-B0C3-45E1-8364-327E96AEA856}
{75339C8C-B4BA-463B-BAC7-975FCA2F89D9}
DirectX for Managed Code
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AssemblyFolders\DX_1.0.2904.0
C:\Windows\Microsoft.NET\DirectX for Managed Code\1.0.2904.0\
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
585
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
76
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
585
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.DirectX.Direct3DX,1.0.2905.0,,31bf3856ad364e35
E8212A73E3C1D401
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
SystemStoreChangeId
585
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\References\Microsoft.DirectX.Direct3DX, Version=1.0.2905.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35\{2EC93463-B0C3-45E1-8364-327E96AEA856}
{75339C8C-B4BA-463B-BAC7-975FCA2F89D9}
DirectX for Managed Code
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AssemblyFolders\DX_1.0.2905.0
C:\Windows\Microsoft.NET\DirectX for Managed Code\1.0.2905.0\
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
586
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
77
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
586
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.DirectX.Direct3DX,1.0.2906.0,,31bf3856ad364e35
C65B4473E3C1D401
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
SystemStoreChangeId
586
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\References\Microsoft.DirectX.Direct3DX, Version=1.0.2906.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35\{2EC93463-B0C3-45E1-8364-327E96AEA856}
{75339C8C-B4BA-463B-BAC7-975FCA2F89D9}
DirectX for Managed Code
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AssemblyFolders\DX_1.0.2906.0
C:\Windows\Microsoft.NET\DirectX for Managed Code\1.0.2906.0\
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
587
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
78
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
587
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.DirectX.Direct3DX,1.0.2907.0,,31bf3856ad364e35
88475073E3C1D401
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
SystemStoreChangeId
587
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\References\Microsoft.DirectX.Direct3DX, Version=1.0.2907.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35\{2EC93463-B0C3-45E1-8364-327E96AEA856}
{75339C8C-B4BA-463B-BAC7-975FCA2F89D9}
DirectX for Managed Code
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AssemblyFolders\DX_1.0.2907.0
C:\Windows\Microsoft.NET\DirectX for Managed Code\1.0.2907.0\
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
588
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
79
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
588
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.DirectX.Direct3DX,1.0.2908.0,,31bf3856ad364e35
FEF76073E3C1D401
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
SystemStoreChangeId
588
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\References\Microsoft.DirectX.Direct3DX, Version=1.0.2908.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35\{2EC93463-B0C3-45E1-8364-327E96AEA856}
{75339C8C-B4BA-463B-BAC7-975FCA2F89D9}
DirectX for Managed Code
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AssemblyFolders\DX_1.0.2908.0
C:\Windows\Microsoft.NET\DirectX for Managed Code\1.0.2908.0\
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
589
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
80
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
589
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.DirectX.Direct3DX,1.0.2909.0,,31bf3856ad364e35
66816A73E3C1D401
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
SystemStoreChangeId
589
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\References\Microsoft.DirectX.Direct3DX, Version=1.0.2909.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35\{2EC93463-B0C3-45E1-8364-327E96AEA856}
{75339C8C-B4BA-463B-BAC7-975FCA2F89D9}
DirectX for Managed Code
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AssemblyFolders\DX_1.0.2909.0
C:\Windows\Microsoft.NET\DirectX for Managed Code\1.0.2909.0\
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
590
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
81
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
590
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.DirectX.Direct3DX,1.0.2910.0,,31bf3856ad364e35
CE0A7473E3C1D401
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
SystemStoreChangeId
590
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\References\Microsoft.DirectX.Direct3DX, Version=1.0.2910.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35\{2EC93463-B0C3-45E1-8364-327E96AEA856}
{75339C8C-B4BA-463B-BAC7-975FCA2F89D9}
DirectX for Managed Code
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AssemblyFolders\DX_1.0.2910.0
C:\Windows\Microsoft.NET\DirectX for Managed Code\1.0.2910.0\
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0aa000aa-f404-11d9-bd7a-0010dc4f8f81}
XACT Engine
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0aa000aa-f404-11d9-bd7a-0010dc4f8f81}\InProcServer32
C:\Windows\system32\xactengine2_0.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0aa000aa-f404-11d9-bd7a-0010dc4f8f81}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
591
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
82
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
591
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.DirectX,1.0.2902.0,,31bf3856ad364e35
BCA2ED73E3C1D401
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
SystemStoreChangeId
591
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\References\Microsoft.DirectX, Version=1.0.2902.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35\{2EC93463-B0C3-45E1-8364-327E96AEA856}
{75339C8C-B4BA-463B-BAC7-975FCA2F89D9}
DirectX for Managed Code
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
592
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
83
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
592
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.DirectX.AudioVideoPlayback,1.0.2902.0,,31bf3856ad364e35
7067F273E3C1D401
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
SystemStoreChangeId
592
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\References\Microsoft.DirectX.AudioVideoPlayback, Version=1.0.2902.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35\{2EC93463-B0C3-45E1-8364-327E96AEA856}
{75339C8C-B4BA-463B-BAC7-975FCA2F89D9}
DirectX for Managed Code
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
593
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
84
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
593
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.DirectX.Diagnostics,1.0.2902.0,,31bf3856ad364e35
242CF773E3C1D401
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
SystemStoreChangeId
593
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\References\Microsoft.DirectX.Diagnostics, Version=1.0.2902.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35\{2EC93463-B0C3-45E1-8364-327E96AEA856}
{75339C8C-B4BA-463B-BAC7-975FCA2F89D9}
DirectX for Managed Code
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
594
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
85
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
594
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.DirectX.Direct3D,1.0.2902.0,,31bf3856ad364e35
7E8EF973E3C1D401
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
SystemStoreChangeId
594
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\References\Microsoft.DirectX.Direct3D, Version=1.0.2902.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35\{2EC93463-B0C3-45E1-8364-327E96AEA856}
{75339C8C-B4BA-463B-BAC7-975FCA2F89D9}
DirectX for Managed Code
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
595
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
86
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
595
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.DirectX.Direct3DX,1.0.2911.0,,31bf3856ad364e35
3253FE73E3C1D401
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
SystemStoreChangeId
595
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\References\Microsoft.DirectX.Direct3DX, Version=1.0.2911.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35\{2EC93463-B0C3-45E1-8364-327E96AEA856}
{75339C8C-B4BA-463B-BAC7-975FCA2F89D9}
DirectX for Managed Code
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AssemblyFolders\DX_1.0.2911.0
C:\Windows\Microsoft.NET\DirectX for Managed Code\1.0.2911.0\
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
596
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
87
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
596
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.DirectX.DirectDraw,1.0.2902.0,,31bf3856ad364e35
E6170374E3C1D401
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
SystemStoreChangeId
596
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\References\Microsoft.DirectX.DirectDraw, Version=1.0.2902.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35\{2EC93463-B0C3-45E1-8364-327E96AEA856}
{75339C8C-B4BA-463B-BAC7-975FCA2F89D9}
DirectX for Managed Code
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
597
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1f1b577e-5e5a-4e8a-ba73-c657ea8e8598}
XACT Engine
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1f1b577e-5e5a-4e8a-ba73-c657ea8e8598}\InProcServer32
C:\Windows\system32\xactengine2_1.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1f1b577e-5e5a-4e8a-ba73-c657ea8e8598}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c60fae90-4183-4a3f-b2f7-ac1dc49b0e5c}
XACT Engine
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c60fae90-4183-4a3f-b2f7-ac1dc49b0e5c}\InProcServer32
C:\Windows\system32\xactengine2_2.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c60fae90-4183-4a3f-b2f7-ac1dc49b0e5c}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1138472b-d187-44e9-81f2-ae1b0e7785f1}
XACT Engine
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1138472b-d187-44e9-81f2-ae1b0e7785f1}\InProcServer32
C:\Windows\system32\xactengine2_3.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1138472b-d187-44e9-81f2-ae1b0e7785f1}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bc3e0fc6-2e0d-4c45-bc61-d9c328319bd8}
XACT Engine
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bc3e0fc6-2e0d-4c45-bc61-d9c328319bd8}\InProcServer32
C:\Windows\system32\xactengine2_4.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bc3e0fc6-2e0d-4c45-bc61-d9c328319bd8}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
88
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
597
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.DirectX.DirectInput,1.0.2902.0,,31bf3856ad364e35
F43E0A74E3C1D401
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
SystemStoreChangeId
597
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\References\Microsoft.DirectX.DirectInput, Version=1.0.2902.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35\{2EC93463-B0C3-45E1-8364-327E96AEA856}
{75339C8C-B4BA-463B-BAC7-975FCA2F89D9}
DirectX for Managed Code
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
598
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
89
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
598
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.DirectX.DirectPlay,1.0.2902.0,,31bf3856ad364e35
02661174E3C1D401
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
SystemStoreChangeId
598
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\References\Microsoft.DirectX.DirectPlay, Version=1.0.2902.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35\{2EC93463-B0C3-45E1-8364-327E96AEA856}
{75339C8C-B4BA-463B-BAC7-975FCA2F89D9}
DirectX for Managed Code
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
599
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
90
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
599
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.DirectX.DirectSound,1.0.2902.0,,31bf3856ad364e35
B62A1674E3C1D401
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
SystemStoreChangeId
599
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\References\Microsoft.DirectX.DirectSound, Version=1.0.2902.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35\{2EC93463-B0C3-45E1-8364-327E96AEA856}
{75339C8C-B4BA-463B-BAC7-975FCA2F89D9}
DirectX for Managed Code
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{cd0d66ec-8057-43f5-acbd-66dfb36fd78c}
XACT Engine
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{cd0d66ec-8057-43f5-acbd-66dfb36fd78c}\InProcServer32
C:\Windows\system32\xactengine2_7.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{cd0d66ec-8057-43f5-acbd-66dfb36fd78c}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{77c56bf4-18a1-42b0-88af-5072ce814949}
XACT Engine
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{77c56bf4-18a1-42b0-88af-5072ce814949}\InProcServer32
C:\Windows\system32\xactengine2_8.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{77c56bf4-18a1-42b0-88af-5072ce814949}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{54b68bc7-3a45-416b-a8c9-19bf19ec1df5}
XACT Engine
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{54b68bc7-3a45-416b-a8c9-19bf19ec1df5}\InProcServer32
C:\Windows\system32\xactengine2_5.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{54b68bc7-3a45-416b-a8c9-19bf19ec1df5}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3a2495ce-31d0-435b-8ccf-e9f0843fd960}
XACT Engine
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3a2495ce-31d0-435b-8ccf-e9f0843fd960}\InProcServer32
C:\Windows\system32\xactengine2_6.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3a2495ce-31d0-435b-8ccf-e9f0843fd960}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{343e68e6-8f82-4a8d-a2da-6e9a944b378c}
XACT Engine
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{343e68e6-8f82-4a8d-a2da-6e9a944b378c}\InProcServer32
C:\Windows\system32\xactengine2_9.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{343e68e6-8f82-4a8d-a2da-6e9a944b378c}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{65d822a4-4799-42c6-9b18-d26cf66dd320}
XACT Engine
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{65d822a4-4799-42c6-9b18-d26cf66dd320}\InProcServer32
C:\Windows\system32\xactengine2_10.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{65d822a4-4799-42c6-9b18-d26cf66dd320}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3b80ee2a-b0f5-4780-9e30-90cb39685b03}
XACT Engine
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3b80ee2a-b0f5-4780-9e30-90cb39685b03}\InProcServer32
C:\Windows\system32\xactengine3_0.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3b80ee2a-b0f5-4780-9e30-90cb39685b03}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fac23f48-31f5-45a8-b49b-5225d61401aa}
XAudio2
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fac23f48-31f5-45a8-b49b-5225d61401aa}\InProcServer32
C:\Windows\system32\XAudio2_0.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fac23f48-31f5-45a8-b49b-5225d61401aa}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c0c56f46-29b1-44e9-9939-a32ce86867e2}
AudioVolumeMeter
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c0c56f46-29b1-44e9-9939-a32ce86867e2}\InProcServer32
C:\Windows\system32\XAudio2_0.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c0c56f46-29b1-44e9-9939-a32ce86867e2}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6f6ea3a9-2cf5-41cf-91c1-2170b1540063}
AudioReverb
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6f6ea3a9-2cf5-41cf-91c1-2170b1540063}\InProcServer32
C:\Windows\system32\XAudio2_0.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6f6ea3a9-2cf5-41cf-91c1-2170b1540063}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{962f5027-99be-4692-a468-85802cf8de61}
XACT Engine
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{962f5027-99be-4692-a468-85802cf8de61}\InProcServer32
C:\Windows\system32\xactengine3_1.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{962f5027-99be-4692-a468-85802cf8de61}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e21a7345-eb21-468e-be50-804db97cf708}
XAudio2
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e21a7345-eb21-468e-be50-804db97cf708}\InProcServer32
C:\Windows\system32\XAudio2_1.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e21a7345-eb21-468e-be50-804db97cf708}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c1e3f122-a2ea-442c-854f-20d98f8357a1}
AudioVolumeMeter
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c1e3f122-a2ea-442c-854f-20d98f8357a1}\InProcServer32
C:\Windows\system32\XAudio2_1.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c1e3f122-a2ea-442c-854f-20d98f8357a1}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f4769300-b949-4df9-b333-00d33932e9a6}
AudioReverb
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f4769300-b949-4df9-b333-00d33932e9a6}\InProcServer32
C:\Windows\system32\XAudio2_1.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f4769300-b949-4df9-b333-00d33932e9a6}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d3332f02-3dd0-4de9-9aec-20d85c4111b6}
XACT Engine
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d3332f02-3dd0-4de9-9aec-20d85c4111b6}\InProcServer32
C:\Windows\system32\xactengine3_2.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d3332f02-3dd0-4de9-9aec-20d85c4111b6}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b802058a-464a-42db-bc10-b650d6f2586a}
XAudio2
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b802058a-464a-42db-bc10-b650d6f2586a}\InProcServer32
C:\Windows\system32\XAudio2_2.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b802058a-464a-42db-bc10-b650d6f2586a}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f5ca7b34-8055-42c0-b836-216129eb7e30}
AudioVolumeMeter
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f5ca7b34-8055-42c0-b836-216129eb7e30}\InProcServer32
C:\Windows\system32\XAudio2_2.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f5ca7b34-8055-42c0-b836-216129eb7e30}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{629cf0de-3ecc-41e7-9926-f7e43eebec51}
AudioReverb
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{629cf0de-3ecc-41e7-9926-f7e43eebec51}\InProcServer32
C:\Windows\system32\XAudio2_2.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{629cf0de-3ecc-41e7-9926-f7e43eebec51}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{94c1affa-66e7-4961-9521-cfdef3128d4f}
XACT Engine
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{94c1affa-66e7-4961-9521-cfdef3128d4f}\InProcServer32
C:\Windows\system32\xactengine3_3.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{94c1affa-66e7-4961-9521-cfdef3128d4f}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4c5e637a-16c7-4de3-9c46-5ed22181962d}
XAudio2
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4c5e637a-16c7-4de3-9c46-5ed22181962d}\InProcServer32
C:\Windows\system32\XAudio2_3.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4c5e637a-16c7-4de3-9c46-5ed22181962d}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e180344b-ac83-4483-959e-18a5c56a5e19}
AudioVolumeMeter
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e180344b-ac83-4483-959e-18a5c56a5e19}\InProcServer32
C:\Windows\system32\XAudio2_3.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e180344b-ac83-4483-959e-18a5c56a5e19}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9cab402c-1d37-44b4-886d-fa4f36170a4c}
AudioReverb
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9cab402c-1d37-44b4-886d-fa4f36170a4c}\InProcServer32
C:\Windows\system32\XAudio2_3.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9cab402c-1d37-44b4-886d-fa4f36170a4c}\InProcServer32
ThreadingModel
Both
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
IDENTIFY (Enter)
4000000000000000D6511A6AE3C1D4014C0B0000980D0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
IDENTIFY (Enter)
4000000000000000D6511A6AE3C1D4014C0B0000940D0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
IDENTIFY (Enter)
4000000000000000D6511A6AE3C1D4014C0B0000A8090000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
IDENTIFY (Enter)
400000000000000030B41C6AE3C1D4014C0B0000B0090000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
IDENTIFY (Leave)
4000000000000000983D266AE3C1D4014C0B0000A8090000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
IDENTIFY (Leave)
4000000000000000983D266AE3C1D4014C0B0000B0090000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
IDENTIFY (Leave)
4000000000000000F29F286AE3C1D4014C0B0000980D0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
IDENTIFY (Leave)
4000000000000000F29F286AE3C1D4014C0B0000940D0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
IDENTIFY (Enter)
400000000000000038634C6AE3C1D4014C0B0000980D0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
IDENTIFY (Enter)
400000000000000038634C6AE3C1D4014C0B0000B0090000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
IDENTIFY (Enter)
400000000000000038634C6AE3C1D4014C0B0000A8090000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
IDENTIFY (Enter)
400000000000000038634C6AE3C1D4014C0B0000940D0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
IDENTIFY (Leave)
4000000000000000EC27516AE3C1D4014C0B0000940D0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
IDENTIFY (Leave)
4000000000000000EC27516AE3C1D4014C0B0000A8090000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
IDENTIFY (Leave)
4000000000000000EC27516AE3C1D4014C0B0000980D0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
IDENTIFY (Leave)
4000000000000000468A536AE3C1D4014C0B0000B0090000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_BEGINPREPARE (Enter)
40000000000000008248E56FE3C1D4014C0B0000B009000001040000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_BEGINPREPARE (Leave)
40000000000000008248E56FE3C1D4014C0B0000B009000001040000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPAREBACKUP (Enter)
4000000000000000360DEA6FE3C1D4014C0B0000A8090000E9030000010000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPAREBACKUP (Enter)
4000000000000000360DEA6FE3C1D4014C0B0000B0090000E9030000010000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPAREBACKUP (Enter)
4000000000000000360DEA6FE3C1D4014C0B0000980D0000E9030000010000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPAREBACKUP (Leave)
4000000000000000906FEC6FE3C1D4014C0B0000A8090000E9030000000000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_STABLE (SetCurrentState)
4000000000000000906FEC6FE3C1D4014C0B0000A809000001000000010000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPAREBACKUP (Leave)
4000000000000000906FEC6FE3C1D4014C0B0000B0090000E9030000000000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_STABLE (SetCurrentState)
4000000000000000906FEC6FE3C1D4014C0B0000B009000001000000010000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPAREBACKUP (Leave)
4000000000000000EAD1EE6FE3C1D4014C0B0000980D0000E9030000000000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_STABLE (SetCurrentState)
4000000000000000EAD1EE6FE3C1D4014C0B0000980D000001000000010000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
GETSTATE (Enter)
40000000000000006082FF6FE3C1D4014C0B0000980D0000F9030000010000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
GETSTATE (Enter)
40000000000000006082FF6FE3C1D4014C0B0000B0090000F9030000010000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
GETSTATE (Enter)
40000000000000006082FF6FE3C1D4014C0B0000A8090000F9030000010000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
GETSTATE (Leave)
40000000000000006082FF6FE3C1D4014C0B0000B0090000F9030000000000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
GETSTATE (Leave)
40000000000000006082FF6FE3C1D4014C0B0000A8090000F9030000000000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
GETSTATE (Leave)
40000000000000006082FF6FE3C1D4014C0B0000980D0000F9030000000000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_ENDPREPARE (Enter)
40000000000000006EA90670E3C1D4014C0B00004C0E000002040000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_ENDPREPARE (Leave)
4000000000000000B6A38270E3C1D4014C0B00004C0E000002040000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
PREPARESNAPSHOT (Enter)
400000000000000010068570E3C1D4014C0B00004C0E0000EA030000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPARESNAPSHOT (Enter)
40000000000000002C549370E3C1D4014C0B0000780E0000EA030000010000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPARESNAPSHOT (Enter)
40000000000000002C549370E3C1D4014C0B0000880E0000EA030000010000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPARESNAPSHOT (Enter)
40000000000000002C549370E3C1D4014C0B00009C0E0000EA030000010000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPARESNAPSHOT (Leave)
4000000000000000EE3F9F70E3C1D4014C0B0000780E0000EA030000000000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)
4000000000000000EE3F9F70E3C1D4014C0B0000780E000002000000010000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPARESNAPSHOT (Leave)
400000000000000048A2A170E3C1D4014C0B0000880E0000EA030000000000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)
400000000000000048A2A170E3C1D4014C0B0000880E000002000000010000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPARESNAPSHOT (Leave)
400000000000000048A2A170E3C1D4014C0B00009C0E0000EA030000000000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)
400000000000000048A2A170E3C1D4014C0B00009C0E000002000000010000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
PREPARESNAPSHOT (Leave)
40000000000000003403C370E3C1D4014C0B00004C0E0000EA030000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE (Enter)
40000000000000003403C370E3C1D4014C0B00004C0E0000EB030000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_FRONT (Enter)
40000000000000003403C370E3C1D4014C0B00004C0E0000EC030000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
FREEZE (Enter)
40000000000000009C8CCC70E3C1D4014C0B0000980E0000EB030000010000000200000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
FREEZE (Leave)
40000000000000009C8CCC70E3C1D4014C0B0000980E0000EB030000000000000200000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_WAITING_FOR_THAW (SetCurrentState)
40000000000000009C8CCC70E3C1D4014C0B0000980E000003000000010000000200000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
BKGND_FREEZE_THREAD (Enter)
40000000000000009C8CCC70E3C1D4014C0B0000DC0F0000FC030000010000000300000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_FRONT (Leave)
4000000000000000F6EECE70E3C1D4014C0B00004C0E0000EC030000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_BACK (Enter)
4000000000000000F6EECE70E3C1D4014C0B00004C0E0000ED030000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_BACK (Leave)
40000000000000005E78D870E3C1D4014C0B00004C0E0000ED030000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_SYSTEM (Enter)
40000000000000005E78D870E3C1D4014C0B00004C0E0000EE030000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
FREEZE (Enter)
40000000000000006C9FDF70E3C1D4014C0B0000980E0000EB030000010000000200000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
FREEZE (Leave)
40000000000000006C9FDF70E3C1D4014C0B0000980E0000EB030000000000000200000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_WAITING_FOR_THAW (SetCurrentState)
40000000000000006C9FDF70E3C1D4014C0B0000980E000003000000010000000200000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
BKGND_FREEZE_THREAD (Enter)
40000000000000006C9FDF70E3C1D4014C0B000020080000FC030000010000000300000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_SYSTEM (Leave)
4000000000000000C601E270E3C1D4014C0B00004C0E0000EE030000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_KTM (Enter)
4000000000000000C601E270E3C1D4014C0B00004C0E0000F0030000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_KTM (Leave)
4000000000000000C601E270E3C1D4014C0B00004C0E0000F0030000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_RM (Enter)
4000000000000000C601E270E3C1D4014C0B00004C0E0000EF030000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
FREEZE (Enter)
40000000000000002E8BEB70E3C1D4014C0B0000B40E0000EB030000010000000200000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
FREEZE (Leave)
40000000000000003CB2F270E3C1D4014C0B0000B40E0000EB030000000000000200000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_WAITING_FOR_THAW (SetCurrentState)
40000000000000003CB2F270E3C1D4014C0B0000B40E000003000000010000000200000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
BKGND_FREEZE_THREAD (Enter)
40000000000000003CB2F270E3C1D4014C0B00006C090000FC030000010000000300000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_RM (Leave)
40000000000000003CB2F270E3C1D4014C0B00004C0E0000EF030000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE (Leave)
40000000000000003CB2F270E3C1D4014C0B00004C0E0000EB030000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_PRECOMMIT (Enter)
40000000000000003CB2F270E3C1D4014C0B00004C0E000003040000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_PRECOMMIT (Leave)
40000000000000003CB2F270E3C1D4014C0B00004C0E000003040000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
OPEN_VOLUME_HANDLE (Enter)
40000000000000003CB2F270E3C1D4014C0B00004C0E0000FD030000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
OPEN_VOLUME_HANDLE (Enter)
40000000000000003CB2F270E3C1D4014C0B000078090000FD030000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
OPEN_VOLUME_HANDLE (Leave)
400000000000000058000171E3C1D4014C0B000078090000FD030000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
OPEN_VOLUME_HANDLE (Leave)
400000000000000058000171E3C1D4014C0B00004C0E0000FD030000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
IOCTL_FLUSH_AND_HOLD (Enter)
400000000000000058000171E3C1D4014C0B000078090000FE030000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
IOCTL_FLUSH_AND_HOLD (Leave)
400000000000000066270871E3C1D4014C0B000078090000FE030000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
IOCTL_RELEASE (Enter)
400000000000000066270871E3C1D4014C0B000078090000FF030000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
IOCTL_RELEASE (Leave)
400000000000000066270871E3C1D4014C0B000078090000FF030000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
IOCTL_FLUSH_AND_HOLD (Enter)
400000000000000058000171E3C1D4014C0B00004C0E0000FE030000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
IOCTL_FLUSH_AND_HOLD (Leave)
400000000000000066270871E3C1D4014C0B00004C0E0000FE030000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
IOCTL_RELEASE (Enter)
400000000000000066270871E3C1D4014C0B00004C0E0000FF030000010000000000000000000000000000000000000000000000000000000000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
IOCTL_RELEASE (Leave)
400000000000000066270871E3C1D4014C0B00004C0E0000FF030000000000000000000000000000000000000000000000000000000000000000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_COMMIT (Enter)
400000000000000066270871E3C1D4014C0B00008809000004040000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_COMMIT (Leave)
400000000000000066270871E3C1D4014C0B00008809000004040000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000