General Info

File name

5e2b3771c665c2538cde7cbd4e5595793044adeaaad853ab5a8d9f4260b1460f

Full analysis
https://app.any.run/tasks/67e4b8b1-6f2d-4a8f-90c9-f59989a7bc3a
Verdict
Malicious activity
Analysis date
2/11/2019, 09:25:02
OS:
Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:

MIME:
application/x-dosexec
File info:
PE32 executable (GUI) Intel 80386, for MS Windows, MS CAB-Installer self-extracting archive
MD5

a157a168e6ec68743ccd84129958f07b

SHA1

823957d5d9dea9c0da5d92066f447eae690f78ec

SHA256

5e2b3771c665c2538cde7cbd4e5595793044adeaaad853ab5a8d9f4260b1460f

SSDEEP

12288:FGvjp5cj35kDB9hrs3zARBSaJSXi15mN9bFm3LIIh:KukDF4zARUwSXImNZUxh

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distored by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.

Software environment set and analysis options

Launch configuration

Task duration
60 seconds
Additional time used
none
Fakenet option
off
Heavy Evaision option
off
MITM proxy
off
Route via Tor
off
Network geolocation
off
Privacy
Public submission
Autoconfirmation of UAC
on

Software preset

  • Internet Explorer 8.0.7601.17514
  • Adobe Acrobat Reader DC MUI (15.023.20070)
  • Adobe Flash Player 26 ActiveX (26.0.0.131)
  • Adobe Flash Player 26 NPAPI (26.0.0.131)
  • Adobe Flash Player 26 PPAPI (26.0.0.131)
  • Adobe Refresh Manager (1.8.0)
  • CCleaner (5.35)
  • FileZilla Client 3.36.0 (3.36.0)
  • Google Chrome (68.0.3440.106)
  • Google Update Helper (1.3.33.17)
  • Java 8 Update 92 (8.0.920.14)
  • Java Auto Updater (2.8.92.14)
  • Microsoft .NET Framework 4.6.1 (4.6.01055)
  • Microsoft Office Access MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Access Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Excel MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office OneNote MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Outlook MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office PowerPoint MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Professional 2010 (14.0.6029.1000)
  • Microsoft Office Proof (English) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (French) 2010 (14.0.6029.1000)
  • Microsoft Office Proof (Spanish) 2010 (14.0.6029.1000)
  • Microsoft Office Proofing (English) 2010 (14.0.6029.1000)
  • Microsoft Office Publisher MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Shared Setup Metadata MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Office Single Image 2010 (14.0.6029.1000)
  • Microsoft Office Word MUI (English) 2010 (14.0.6029.1000)
  • Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (9.0.30729.6161)
  • Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (10.0.40219)
  • Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (12.0.30501.0)
  • Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 (12.0.21005)
  • Microsoft Visual C++ 2017 Redistributable (x86) - 14.15.26706 (14.15.26706.0)
  • Microsoft Visual C++ 2017 x86 Additional Runtime - 14.15.26706 (14.15.26706)
  • Microsoft Visual C++ 2017 x86 Minimum Runtime - 14.15.26706 (14.15.26706)
  • Mozilla Firefox 61.0.2 (x86 en-US) (61.0.2)
  • Notepad++ (32-bit x86) (7.5.1)
  • Opera 12.15 (12.15.1748)
  • Skype version 8.29 (8.29)
  • VLC media player (2.2.6)
  • WinRAR 5.60 (32-bit) (5.60.0)

Hotfixes

  • Client LanguagePack Package
  • Client Refresh LanguagePack Package
  • CodecPack Basic Package
  • Foundation Package
  • IE Troubleshooters Package
  • InternetExplorer Optional Package
  • KB2534111
  • KB2999226
  • KB976902
  • LocalPack AU Package
  • LocalPack CA Package
  • LocalPack GB Package
  • LocalPack US Package
  • LocalPack ZA Package
  • ProfessionalEdition
  • UltimateEdition

Behavior activities

MALICIOUS SUSPICIOUS INFO
Loads dropped or rewritten executable
  • DllHost.exe (PID: 3892)
  • dwm.exe (PID: 1988)
  • 5e2b3771c665c2538cde7cbd4e5595793044adeaaad853ab5a8d9f4260b1460f.exe (PID: 3492)
  • dxwsetup.exe (PID: 2664)
  • explorer.exe (PID: 284)
Application was dropped or rewritten from another process
  • dxwsetup.exe (PID: 2664)
Changes the autorun value in the registry
  • 5e2b3771c665c2538cde7cbd4e5595793044adeaaad853ab5a8d9f4260b1460f.exe (PID: 3492)
Creates COM task schedule object
  • dxwsetup.exe (PID: 2664)
Searches for installed software
  • dxwsetup.exe (PID: 2664)
  • DllHost.exe (PID: 3892)
Executable content was dropped or overwritten
  • 5e2b3771c665c2538cde7cbd4e5595793044adeaaad853ab5a8d9f4260b1460f.exe (PID: 3492)
  • dxwsetup.exe (PID: 2664)
Removes files from Windows directory
  • dxwsetup.exe (PID: 2664)
Creates files in the Windows directory
  • dxwsetup.exe (PID: 2664)
Low-level read access rights to disk partition
  • vssvc.exe (PID: 2892)
Reads settings of System Certificates
  • dxwsetup.exe (PID: 2664)

Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Static information

TRiD
.exe
|   Win32 Executable MS Visual C++ (generic) (42.2%)
.exe
|   Win64 Executable (generic) (37.3%)
.dll
|   Win32 Dynamic Link Library (generic) (8.8%)
.exe
|   Win32 Executable (generic) (6%)
.exe
|   Generic Win/DOS Executable (2.7%)
EXIF
EXE
MachineType:
Intel 386 or later, and compatibles
TimeStamp:
2001:08:18 03:42:57+02:00
PEType:
PE32
LinkerVersion:
7
CodeSize:
34816
InitializedDataSize:
246272
UninitializedDataSize:
null
EntryPoint:
0x48000
OSVersion:
5.1
ImageVersion:
5.1
SubsystemVersion:
4
Subsystem:
Windows GUI
FileVersionNumber:
6.0.2600.0
ProductVersionNumber:
6.0.2600.0
FileFlagsMask:
0x003f
FileFlags:
(none)
FileOS:
Windows NT 32-bit
ObjectFileType:
Executable application
FileSubtype:
null
LanguageCode:
English (U.S.)
CharacterSet:
Unicode
CompanyName:
Microsoft Corporation
FileDescription:
DirectX 9.0 Web setup
FileVersion:
9.29.1962.0
InternalName:
DXWebSetup
LegalCopyright:
Copyright (c) Microsoft Corporation. All rights reserved.
OriginalFileName:
dxwebsetup.exe
ProductName:
Microsoft® Windows® Operating System
ProductVersion:
9.29.1962.0
Summary
Architecture:
IMAGE_FILE_MACHINE_I386
Subsystem:
IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date:
18-Aug-2001 01:42:57
Detected languages
English - United States
Debug artifacts
.pdb
CompanyName:
Microsoft Corporation
FileDescription:
DirectX 9.0 Web setup
FileVersion:
9.29.1962.0
InternalName:
DXWebSetup
LegalCopyright:
Copyright (c) Microsoft Corporation. All rights reserved.
OriginalFilename:
dxwebsetup.exe
ProductName:
Microsoft® Windows® Operating System
ProductVersion:
9.29.1962.0
DOS Header
Magic number:
MZ
Bytes on last page of file:
0x0090
Pages in file:
0x0003
Relocations:
0x0000
Size of header:
0x0004
Min extra paragraphs:
0x0000
Max extra paragraphs:
0xFFFF
Initial SS value:
0x0000
Initial SP value:
0x00B8
Checksum:
0x0000
Initial IP value:
0x0000
Initial CS value:
0x0000
Overlay number:
0x0000
OEM identifier:
0x0000
OEM information:
0x0000
Address of NE header:
0x000000C8
PE Headers
Signature:
PE
Machine:
IMAGE_FILE_MACHINE_I386
Number of sections:
4
Time date stamp:
18-Aug-2001 01:42:57
Pointer to Symbol Table:
0x00000000
Number of symbols:
0
Size of Optional Header:
0x00E0
Characteristics
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
Sections
Name Virtual Address Virtual Size Raw Size Charateristics Entropy
.text 0x00001000 0x0000861A 0x00008800 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 6.55103
.data 0x0000A000 0x00001BE4 0x00000400 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 4.18428
.rsrc 0x0000C000 0x0003C000 0x0003BE00 IMAGE_SCN_CNT_INITIALIZED_DATA,IMAGE_SCN_MEM_READ 7.82577
.mjg\x07 0x00048000 0x00001000 0x00000600 IMAGE_SCN_CNT_CODE,IMAGE_SCN_MEM_EXECUTE,IMAGE_SCN_MEM_READ,IMAGE_SCN_MEM_WRITE 6.96134
Resources
1

2

63

76

77

80

83

85

2001

2002

2003

2004

2005

2006

3000

3001

ADMQCMD

CABINET

EXTRACTOPT

FILESIZES

FINISHMSG

LICENSE

PACKINSTSPACE

POSTRUNPROGRAM

REBOOT

RUNPROGRAM

SHOWWINDOW

TITLE

UPROMPT

USRQCMD

Imports
    ADVAPI32.dll

    KERNEL32.dll

    GDI32.dll

    USER32.dll

    COMCTL32.dll

    VERSION.dll

Exports

    No exports.

Screenshots

Processes

Total processes
39
Monitored processes
8
Malicious processes
3
Suspicious processes
0

Behavior graph

+
drop and start start 5e2b3771c665c2538cde7cbd4e5595793044adeaaad853ab5a8d9f4260b1460f.exe no specs 5e2b3771c665c2538cde7cbd4e5595793044adeaaad853ab5a8d9f4260b1460f.exe dxwsetup.exe explorer.exe no specs vssvc.exe no specs SPPSurrogate no specs dwm.exe no specs drvinst.exe no specs
Specs description
Program did not start
Integrity level elevation
Task сontains an error or was rebooted
Process has crashed
Task contains several apps running
Executable file was dropped
Debug information is available
Process was injected
Network attacks were detected
Application downloaded the executable file
Actions similar to stealing personal data
Behavior similar to exploiting the vulnerability
Inspected object has sucpicious PE structure
File is detected by antivirus software
CPU overrun
RAM overrun
Process starts the services
Process was added to the startup
Behavior similar to spam
Low-level access to the HDD
Probably Tor was used
System was rebooted
Connects to the network
Known threat

Process information

Click at the process to see the details.

PID
1988
CMD
"C:\Windows\system32\Dwm.exe"
Path
C:\Windows\System32\dwm.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Desktop Window Manager
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\dwm.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\dwmredir.dll
c:\windows\system32\dwmcore.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\ole32.dll
c:\windows\system32\d3d10_1.dll
c:\windows\system32\d3d10_1core.dll
c:\windows\system32\dxgi.dll
c:\windows\system32\version.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\users\admin\appdata\local\temp\ixded52.tmp
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\mpr.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll

PID
284
CMD
C:\Windows\Explorer.EXE
Path
C:\Windows\explorer.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
MEDIUM
Version:
Company
Microsoft Corporation
Description
Windows Explorer
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\explorerframe.dll
c:\windows\system32\duser.dll
c:\windows\system32\dui70.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\slc.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll
c:\windows\system32\secur32.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\propsys.dll
c:\windows\system32\cryptbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\windowscodecs.dll
c:\windows\system32\profapi.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\ehstorshell.dll
c:\windows\system32\cscui.dll
c:\windows\system32\cscdll.dll
c:\windows\system32\cscapi.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\iconcodecservice.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\sndvolsso.dll
c:\windows\system32\hid.dll
c:\windows\system32\mmdevapi.dll
c:\windows\system32\timedate.cpl
c:\windows\system32\atl.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\actxprxy.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shdocvw.dll
c:\windows\system32\linkinfo.dll
c:\windows\system32\userenv.dll
c:\windows\system32\shacct.dll
c:\windows\system32\samlib.dll
c:\windows\system32\samcli.dll
c:\windows\system32\netutils.dll
c:\windows\system32\msftedit.dll
c:\windows\system32\msls31.dll
c:\program files\common files\microsoft shared\ink\tiptsf.dll
c:\windows\system32\authui.dll
c:\windows\system32\cryptui.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\gameux.dll
c:\windows\system32\xmllite.dll
c:\windows\system32\wer.dll
c:\windows\system32\msiltcfg.dll
c:\windows\system32\version.dll
c:\windows\system32\msi.dll
c:\windows\system32\winsta.dll
c:\windows\system32\psapi.dll
c:\windows\system32\networkexplorer.dll
c:\windows\system32\winmm.dll
c:\windows\system32\wdmaud.drv
c:\windows\system32\ksuser.dll
c:\windows\system32\avrt.dll
c:\windows\system32\audioses.dll
c:\windows\system32\msacm32.drv
c:\windows\system32\msacm32.dll
c:\windows\system32\midimap.dll
c:\windows\system32\stobject.dll
c:\windows\system32\batmeter.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\es.dll
c:\windows\system32\prnfldr.dll
c:\windows\system32\winspool.drv
c:\windows\system32\dxp.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\syncreg.dll
c:\windows\ehome\ehsso.dll
c:\windows\system32\netshell.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\alttab.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
c:\program files\filezilla ftp client\fzshellext.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\taskschd.dll
c:\windows\system32\pnidui.dll
c:\windows\system32\qutil.dll
c:\windows\system32\wevtapi.dll
c:\windows\system32\dhcpcsvc6.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\dhcpcsvc.dll
c:\windows\system32\npmproxy.dll
c:\windows\system32\mssprxy.dll
c:\windows\system32\wlanapi.dll
c:\windows\system32\wlanutil.dll
c:\windows\system32\wwanapi.dll
c:\windows\system32\wwapi.dll
c:\windows\system32\qagent.dll
c:\windows\system32\srchadmin.dll
c:\windows\system32\sxs.dll
c:\windows\system32\bthprops.cpl
c:\windows\system32\winanr.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\oleacc.dll
c:\windows\system32\synccenter.dll
c:\windows\system32\actioncenter.dll
c:\windows\system32\imapi2.dll
c:\windows\system32\hgcpl.dll
c:\windows\system32\provsvc.dll
c:\windows\system32\netprofm.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\fxsst.dll
c:\windows\system32\fxsapi.dll
c:\windows\system32\fxsresm.dll
c:\windows\system32\wscinterop.dll
c:\windows\system32\wscapi.dll
c:\windows\system32\wscui.cpl
c:\windows\system32\werconcpl.dll
c:\windows\system32\framedynos.dll
c:\windows\system32\wercplsupport.dll
c:\windows\system32\msxml6.dll
c:\windows\system32\hcproviders.dll
c:\program files\internet explorer\ieproxy.dll
c:\windows\system32\mpr.dll
c:\windows\system32\drprov.dll
c:\windows\system32\ntlanman.dll
c:\windows\system32\davclnt.dll
c:\windows\system32\davhlpr.dll
c:\windows\system32\thumbcache.dll
c:\users\admin\appdata\local\temp\5e2b3771c665c2538cde7cbd4e5595793044adeaaad853ab5a8d9f4260b1460f.exe
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\devrtl.dll
c:\users\admin\appdata\local\temp\ixded52.tmp
c:\windows\system32\wsock32.dll
c:\users\admin\appdata\local\temp\ixp000.tmp\dxwsetup.exe

PID
3092
CMD
"C:\Users\admin\AppData\Local\Temp\5e2b3771c665c2538cde7cbd4e5595793044adeaaad853ab5a8d9f4260b1460f.exe"
Path
C:\Users\admin\AppData\Local\Temp\5e2b3771c665c2538cde7cbd4e5595793044adeaaad853ab5a8d9f4260b1460f.exe
Indicators
No indicators
Parent process
explorer.exe
User
admin
Integrity Level
MEDIUM
Exit code
3221226540
Version:
Company
Microsoft Corporation
Description
DirectX 9.0 Web setup
Version
9.29.1962.0
Modules
Image
c:\users\admin\appdata\local\temp\5e2b3771c665c2538cde7cbd4e5595793044adeaaad853ab5a8d9f4260b1460f.exe
c:\systemroot\system32\ntdll.dll

PID
3492
CMD
"C:\Users\admin\AppData\Local\Temp\5e2b3771c665c2538cde7cbd4e5595793044adeaaad853ab5a8d9f4260b1460f.exe"
Path
C:\Users\admin\AppData\Local\Temp\5e2b3771c665c2538cde7cbd4e5595793044adeaaad853ab5a8d9f4260b1460f.exe
Indicators
Parent process
explorer.exe
User
admin
Integrity Level
HIGH
Version:
Company
Microsoft Corporation
Description
DirectX 9.0 Web setup
Version
9.29.1962.0
Modules
Image
c:\users\admin\appdata\local\temp\5e2b3771c665c2538cde7cbd4e5595793044adeaaad853ab5a8d9f4260b1460f.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\version.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\ole32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\shell32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\users\admin\appdata\local\temp\ixded52.tmp
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\advpack.dll
c:\users\admin\appdata\local\temp\ixp000.tmp\dxwsetup.exe

PID
2664
CMD
C:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxwsetup.exe
Path
C:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxwsetup.exe
Indicators
Parent process
5e2b3771c665c2538cde7cbd4e5595793044adeaaad853ab5a8d9f4260b1460f.exe
User
admin
Integrity Level
HIGH
Version:
Company
Microsoft Corporation
Description
DirectX Setup
Version
4.9.0.0904
Modules
Image
c:\users\admin\appdata\local\temp\ixp000.tmp\dxwsetup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
c:\windows\system32\version.dll
c:\windows\system32\ole32.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\winmm.dll
c:\windows\system32\samcli.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msacm32.dll
c:\windows\system32\sfc.dll
c:\windows\system32\sfc_os.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\dwmapi.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\wininet.dll
c:\windows\system32\iertutil.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\mpr.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\advpack.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\spinf.dll
c:\windows\system32\spfileq.dll
c:\windows\system32\cabinet.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\cryptbase.dll
c:\users\admin\appdata\local\temp\ixded52.tmp
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\directx\websetup\dsetup.dll
c:\windows\system32\directx\websetup\dsetup32.dll
c:\windows\system32\ntkrnlpa.exe
c:\windows\system32\clbcatq.dll
c:\windows\system32\inseng.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rasapi32.dll
c:\windows\system32\rasman.dll
c:\windows\system32\rtutils.dll
c:\windows\system32\sensapi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\system32\normaliz.dll
c:\windows\system32\nlaapi.dll
c:\windows\system32\rasadhlp.dll
c:\windows\system32\wship6.dll
c:\windows\system32\fwpuclnt.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\gpapi.dll
c:\users\admin\appdata\local\temp\ixp000.tmp\dxupdate.dll
c:\windows\system32\mscoree.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\microsoft.net\framework\v2.0.50727\mscorwks.dll
c:\windows\microsoft.net\framework\v2.0.50727\fusion.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\srclient.dll
c:\windows\system32\spp.dll
c:\windows\system32\vssapi.dll
c:\windows\system32\atl.dll
c:\windows\system32\vsstrace.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\vss_ps.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\es.dll
c:\windows\system32\sxs.dll
c:\windows\system32\propsys.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll
c:\windows\system32\sxproxy.dll
c:\users\admin\appdata\local\temp\dxae70.tmp\dxupdate.dll
c:\users\admin\appdata\local\temp\dxae70.tmp\microsoft.directx.direct3dx.dll
c:\windows\system32\xactengine2_0.dll
c:\windows\system32\dsound.dll
c:\windows\system32\powrprof.dll
c:\users\admin\appdata\local\temp\dxae70.tmp\microsoft.directx.dll
c:\users\admin\appdata\local\temp\dxae70.tmp\microsoft.directx.audiovideoplayback.dll
c:\users\admin\appdata\local\temp\dxae70.tmp\microsoft.directx.diagnostics.dll
c:\users\admin\appdata\local\temp\dxae70.tmp\microsoft.directx.direct3d.dll
c:\users\admin\appdata\local\temp\dxae70.tmp\microsoft.directx.directdraw.dll
c:\users\admin\appdata\local\temp\dxae70.tmp\microsoft.directx.directinput.dll
c:\users\admin\appdata\local\temp\dxae70.tmp\microsoft.directx.directplay.dll
c:\users\admin\appdata\local\temp\dxae70.tmp\microsoft.directx.directsound.dll
c:\windows\system32\x3daudio1_0.dll
c:\users\admin\appdata\local\temp\dxae70.tmp\x3daudio1_0.dll
c:\windows\system32\xactengine2_1.dll
c:\windows\system32\xactengine2_2.dll
c:\windows\system32\xactengine2_3.dll
c:\windows\system32\xactengine2_4.dll
c:\windows\system32\x3daudio1_1.dll
c:\users\admin\appdata\local\temp\dxae70.tmp\x3daudio1_1.dll
c:\windows\system32\setc569.tmp
c:\windows\system32\xactengine2_5.dll
c:\windows\system32\x3daudio1_1
c:\windows\system32\setc5e8.tmp
c:\windows\system32\xactengine2_6.dll
c:\windows\system32\setc725.tmp
c:\windows\system32\xactengine2_7.dll
c:\windows\system32\xactengine2_8.dll
c:\windows\system32\x3daudio1_2.dll
c:\users\admin\appdata\local\temp\dxae70.tmp\x3daudio1_2.dll
c:\windows\system32\setc963.tmp
c:\windows\system32\xactengine2_9.dll
c:\windows\system32\x3daudio1_2
c:\windows\system32\setca80.tmp
c:\windows\system32\xactengine2_10.dll
c:\windows\system32\xactengine3_0.dll
c:\windows\system32\xaudio2_0.dll
c:\windows\system32\xactengine3_1.dll
c:\windows\system32\xaudio2_1.dll
c:\windows\system32\xactengine3_2.dll
c:\windows\system32\xaudio2_2.dll
c:\windows\system32\xactengine3_3.dll
c:\windows\system32\xaudio2_3.dll

PID
2892
CMD
C:\Windows\system32\vssvc.exe
Path
C:\Windows\system32\vssvc.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Version:
Company
Microsoft Corporation
Description
Microsoft® Volume Shadow Copy Service
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\vssvc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\atl.dll
c:\windows\system32\ole32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\vssapi.dll
c:\windows\system32\vsstrace.dll
c:\windows\system32\netapi32.dll
c:\windows\system32\netutils.dll
c:\windows\system32\srvcli.dll
c:\windows\system32\wkscli.dll
c:\windows\system32\samcli.dll
c:\windows\system32\clusapi.dll
c:\windows\system32\cryptdll.dll
c:\windows\system32\xolehlp.dll
c:\windows\system32\version.dll
c:\windows\system32\resutils.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\authz.dll
c:\windows\system32\virtdisk.dll
c:\windows\system32\fltlib.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\vss_ps.dll
c:\windows\system32\samlib.dll
c:\windows\system32\es.dll
c:\windows\system32\propsys.dll
c:\windows\system32\catsrvut.dll
c:\windows\system32\mfcsubs.dll
c:\windows\system32\sxs.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll

PID
3892
CMD
C:\Windows\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801}
Path
C:\Windows\system32\DllHost.exe
Indicators
No indicators
Parent process
––
User
admin
Integrity Level
HIGH
Exit code
0
Version:
Company
Microsoft Corporation
Description
COM Surrogate
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\dllhost.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\clbcatq.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\rpcrtremote.dll
c:\users\admin\appdata\local\temp\ixded52.tmp
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
c:\windows\system32\mpr.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
c:\windows\system32\spp.dll
c:\windows\system32\vssapi.dll
c:\windows\system32\atl.dll
c:\windows\system32\vsstrace.dll
c:\windows\system32\sxproxy.dll
c:\windows\system32\vss_ps.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\msxml3.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\es.dll
c:\windows\system32\sxs.dll
c:\windows\system32\propsys.dll
c:\windows\system32\samcli.dll
c:\windows\system32\samlib.dll
c:\windows\system32\netutils.dll

PID
3840
CMD
DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot18" "" "" "6792c44eb" "00000000" "000003C0" "000005BC"
Path
C:\Windows\system32\DrvInst.exe
Indicators
No indicators
Parent process
––
User
SYSTEM
Integrity Level
SYSTEM
Exit code
0
Version:
Company
Microsoft Corporation
Description
Driver Installation Module
Version
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Image
c:\windows\system32\drvinst.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\devobj.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\imm32.dll
c:\windows\system32\msctf.dll
c:\windows\system32\spinf.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\cryptsp.dll
c:\windows\system32\rsaenh.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ncrypt.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\gpapi.dll
c:\windows\system32\cryptnet.dll
c:\windows\system32\wldap32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\spfileq.dll

Registry activity

Total events
938
Read events
529
Write events
409
Delete events
0

Modification events

PID
Process
Operation
Key
Name
Value
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer
PINF
0700433A5C55736572735C61646D696E5C417070446174615C4C6F63616C5C54656D705C697864454435322E746D7000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\NccQngn\Ybpny\Grzc\VKC000.GZC\qkjfrghc.rkr
00000000000000000000000000000000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002E0000003D00000085431500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
P:\Hfref\nqzva\NccQngn\Ybpny\Grzc\VKC000.GZC\qkjfrghc.rkr
000000000000000000000000E3090000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
284
explorer.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
HRZR_PGYFRFFVBA
000000002E0000003D000000684D1500090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802000000000E0000005DEC04007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B006D00670072002E0065007800650000003702000008023CE23702350100C082BAD075B048D4750200000001000000A048D4750100000068E23702C5B8D075A848D47501000000C81008000000000090E237026BB9D07500000000350100C001000000B0E23702973CB8779C3CB877F58CF77501000000350100C00000000088E23702FFFFFFFFF8E23702EDE0B47745727800FEFFFFFFC0E237020D6BD075A0E737028CE8370200000000F8E23702973CB8779C3CB877BD8CF775000000008CE83702A0E73702D0E237020100000070E73702EDE0B47745727800FEFFFFFF08E337020D6BD0757E0000008CE8370280E73702F36BD075E186D0752794C6128CE8370210000000570104003E0040008CE83702A0E73702000000000000000000000000000008025CE537020000080254E33702350100C000000000D8E637023200000018000000000000000000000088E3370211000000B8450B00B0450B0032000000D8E63702F0E300009B1EC112A0E3370282919576F0E33702A4E3370227959576000000006C155002CCE33702CD9495766C15500278E43702E0105002E194957600000000E010500278E43702D4E33702090000000B000000DCC402007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E0065007800650000000000D09866060000000034E82802C05D5A740200000002000000000C00940F000000E8E82802010000000400000001000000010000006B001001D098660605000000D098660602020000E20101AE2B51EA0088E7280239B58D76E20101AE24E82802130000000400000030000000120000001D000000130000001D0000000E00000012000000020000003200000014000000E387EE7A38E82802F3AE5B7400574100E20101AE010000000000000011000000F0443500E8443500A14A52740000000020E800001F51EA7AD0E728028291917520E828028CD800006B51EA7AE4E72802B69C917590D8D4035C0000000401000084F2280244F228026B4E317411000000F0443500E8443500A8EAD403FA4F31740000000074E80000AB5EEA7A24E828028291917574E8280228E8280227959175000000008CD8D40350E82802CD9491758CD8D403FCE8280200D4D403E19491750000000000D4D403FCE8280258E82802
3492
5e2b3771c665c2538cde7cbd4e5595793044adeaaad853ab5a8d9f4260b1460f.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
wextract_cleanup0
rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\admin\AppData\Local\Temp\IXP000.TMP\"
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\Setup\SetupapiLogStatus
setupapi.app.log
4096
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dxwsetup_RASAPI32
EnableFileTracing
0
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dxwsetup_RASAPI32
EnableConsoleTracing
0
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dxwsetup_RASAPI32
FileTracingMask
4294901760
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dxwsetup_RASAPI32
ConsoleTracingMask
4294901760
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dxwsetup_RASAPI32
MaxFileSize
1048576
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dxwsetup_RASAPI32
FileDirectory
%windir%\tracing
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dxwsetup_RASMANCS
EnableFileTracing
0
2664
dxwsetup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
ProxyEnable
0
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dxwsetup_RASMANCS
EnableConsoleTracing
0
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dxwsetup_RASMANCS
FileTracingMask
4294901760
2664
dxwsetup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
SavedLegacySettings
4600000069000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dxwsetup_RASMANCS
ConsoleTracingMask
4294901760
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dxwsetup_RASMANCS
MaxFileSize
1048576
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\dxwsetup_RASMANCS
FileDirectory
%windir%\tracing
2664
dxwsetup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
UNCAsIntranet
0
2664
dxwsetup.exe
write
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
AutoDetect
1
2664
dxwsetup.exe
write
HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
SrCreateRp (Enter)
400000000000000088DFC669E3C1D401680A00005C0A0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppCreate (Enter)
400000000000000088DFC669E3C1D401680A00005C0A0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
LastIndex
20
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppGatherWriterMetadata (Enter)
4000000000000000063F076AE3C1D401680A00005C0A0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
IDENTIFY (Enter)
400000000000000060A1096AE3C1D401680A000020090000E8030000010000000000000000000000CFC4F3FCE7B54242A51FCF76B3360A950000000000000000
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
IDENTIFY (Leave)
4000000000000000F29F286AE3C1D401680A000020090000E8030000000000000000000000000000CFC4F3FCE7B54242A51FCF76B3360A950000000000000000
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppGatherWriterMetadata (Leave)
4000000000000000A6642D6AE3C1D401680A00005C0A0000D3070000010000000000000000000000000000000000000000000000000000000000000000000000
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppCreate (Leave)
4000000000000000A6642D6AE3C1D401680A00005C0A0000D007000001000000000000000A010081CFC4F3FCE7B54242A51FCF76B3360A950000000000000000
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
SrCreateRp (Leave)
4000000000000000A6642D6AE3C1D401680A00005C0A0000D507000001000000000000000A010081000000000000000000000000000000000000000000000000
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
SrCreateRp (Enter)
4000000000000000A6642D6AE3C1D401680A00005C0A0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
SrCreateRp (Leave)
4000000000000000C0890A71E3C1D401680A00005C0A0000D5070000010000000000000000000000000000000000000000000000000000000000000000000000
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
FirstRun
0
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
LastIndex
21
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\Volatile
NestingLevel
0
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore\Volatile
StartNesting
0000000000000000
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
582
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
73
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
582
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.DirectX.Direct3DX,1.0.2902.0,,31bf3856ad364e35
8610F872E3C1D401
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
SystemStoreChangeId
582
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\References\Microsoft.DirectX.Direct3DX, Version=1.0.2902.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35\{2EC93463-B0C3-45E1-8364-327E96AEA856}
{75339C8C-B4BA-463B-BAC7-975FCA2F89D9}
DirectX for Managed Code
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AssemblyFolders\DX_1.0.2902.0
C:\Windows\Microsoft.NET\DirectX for Managed Code\1.0.2902.0\
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
583
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
74
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
583
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.DirectX.Direct3DX,1.0.2903.0,,31bf3856ad364e35
180F1773E3C1D401
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
SystemStoreChangeId
583
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\References\Microsoft.DirectX.Direct3DX, Version=1.0.2903.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35\{2EC93463-B0C3-45E1-8364-327E96AEA856}
{75339C8C-B4BA-463B-BAC7-975FCA2F89D9}
DirectX for Managed Code
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AssemblyFolders\DX_1.0.2903.0
C:\Windows\Microsoft.NET\DirectX for Managed Code\1.0.2903.0\
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
584
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
75
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
584
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.DirectX.Direct3DX,1.0.2904.0,,31bf3856ad364e35
80982073E3C1D401
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
SystemStoreChangeId
584
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\References\Microsoft.DirectX.Direct3DX, Version=1.0.2904.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35\{2EC93463-B0C3-45E1-8364-327E96AEA856}
{75339C8C-B4BA-463B-BAC7-975FCA2F89D9}
DirectX for Managed Code
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AssemblyFolders\DX_1.0.2904.0
C:\Windows\Microsoft.NET\DirectX for Managed Code\1.0.2904.0\
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
585
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
76
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
585
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.DirectX.Direct3DX,1.0.2905.0,,31bf3856ad364e35
E8212A73E3C1D401
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
SystemStoreChangeId
585
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\References\Microsoft.DirectX.Direct3DX, Version=1.0.2905.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35\{2EC93463-B0C3-45E1-8364-327E96AEA856}
{75339C8C-B4BA-463B-BAC7-975FCA2F89D9}
DirectX for Managed Code
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AssemblyFolders\DX_1.0.2905.0
C:\Windows\Microsoft.NET\DirectX for Managed Code\1.0.2905.0\
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
586
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
77
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
586
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.DirectX.Direct3DX,1.0.2906.0,,31bf3856ad364e35
C65B4473E3C1D401
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
SystemStoreChangeId
586
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\References\Microsoft.DirectX.Direct3DX, Version=1.0.2906.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35\{2EC93463-B0C3-45E1-8364-327E96AEA856}
{75339C8C-B4BA-463B-BAC7-975FCA2F89D9}
DirectX for Managed Code
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AssemblyFolders\DX_1.0.2906.0
C:\Windows\Microsoft.NET\DirectX for Managed Code\1.0.2906.0\
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
587
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
78
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
587
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.DirectX.Direct3DX,1.0.2907.0,,31bf3856ad364e35
88475073E3C1D401
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
SystemStoreChangeId
587
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\References\Microsoft.DirectX.Direct3DX, Version=1.0.2907.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35\{2EC93463-B0C3-45E1-8364-327E96AEA856}
{75339C8C-B4BA-463B-BAC7-975FCA2F89D9}
DirectX for Managed Code
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AssemblyFolders\DX_1.0.2907.0
C:\Windows\Microsoft.NET\DirectX for Managed Code\1.0.2907.0\
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
588
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
79
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
588
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.DirectX.Direct3DX,1.0.2908.0,,31bf3856ad364e35
FEF76073E3C1D401
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
SystemStoreChangeId
588
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\References\Microsoft.DirectX.Direct3DX, Version=1.0.2908.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35\{2EC93463-B0C3-45E1-8364-327E96AEA856}
{75339C8C-B4BA-463B-BAC7-975FCA2F89D9}
DirectX for Managed Code
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AssemblyFolders\DX_1.0.2908.0
C:\Windows\Microsoft.NET\DirectX for Managed Code\1.0.2908.0\
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
589
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
80
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
589
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.DirectX.Direct3DX,1.0.2909.0,,31bf3856ad364e35
66816A73E3C1D401
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
SystemStoreChangeId
589
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\References\Microsoft.DirectX.Direct3DX, Version=1.0.2909.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35\{2EC93463-B0C3-45E1-8364-327E96AEA856}
{75339C8C-B4BA-463B-BAC7-975FCA2F89D9}
DirectX for Managed Code
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AssemblyFolders\DX_1.0.2909.0
C:\Windows\Microsoft.NET\DirectX for Managed Code\1.0.2909.0\
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
590
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
81
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
590
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.DirectX.Direct3DX,1.0.2910.0,,31bf3856ad364e35
CE0A7473E3C1D401
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
SystemStoreChangeId
590
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\References\Microsoft.DirectX.Direct3DX, Version=1.0.2910.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35\{2EC93463-B0C3-45E1-8364-327E96AEA856}
{75339C8C-B4BA-463B-BAC7-975FCA2F89D9}
DirectX for Managed Code
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AssemblyFolders\DX_1.0.2910.0
C:\Windows\Microsoft.NET\DirectX for Managed Code\1.0.2910.0\
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0aa000aa-f404-11d9-bd7a-0010dc4f8f81}
XACT Engine
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0aa000aa-f404-11d9-bd7a-0010dc4f8f81}\InProcServer32
C:\Windows\system32\xactengine2_0.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0aa000aa-f404-11d9-bd7a-0010dc4f8f81}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
591
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
82
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
591
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.DirectX,1.0.2902.0,,31bf3856ad364e35
BCA2ED73E3C1D401
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
SystemStoreChangeId
591
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\References\Microsoft.DirectX, Version=1.0.2902.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35\{2EC93463-B0C3-45E1-8364-327E96AEA856}
{75339C8C-B4BA-463B-BAC7-975FCA2F89D9}
DirectX for Managed Code
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
592
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
83
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
592
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.DirectX.AudioVideoPlayback,1.0.2902.0,,31bf3856ad364e35
7067F273E3C1D401
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
SystemStoreChangeId
592
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\References\Microsoft.DirectX.AudioVideoPlayback, Version=1.0.2902.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35\{2EC93463-B0C3-45E1-8364-327E96AEA856}
{75339C8C-B4BA-463B-BAC7-975FCA2F89D9}
DirectX for Managed Code
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
593
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
84
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
593
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.DirectX.Diagnostics,1.0.2902.0,,31bf3856ad364e35
242CF773E3C1D401
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
SystemStoreChangeId
593
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\References\Microsoft.DirectX.Diagnostics, Version=1.0.2902.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35\{2EC93463-B0C3-45E1-8364-327E96AEA856}
{75339C8C-B4BA-463B-BAC7-975FCA2F89D9}
DirectX for Managed Code
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
594
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
85
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
594
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.DirectX.Direct3D,1.0.2902.0,,31bf3856ad364e35
7E8EF973E3C1D401
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
SystemStoreChangeId
594
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\References\Microsoft.DirectX.Direct3D, Version=1.0.2902.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35\{2EC93463-B0C3-45E1-8364-327E96AEA856}
{75339C8C-B4BA-463B-BAC7-975FCA2F89D9}
DirectX for Managed Code
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
595
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
86
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
595
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.DirectX.Direct3DX,1.0.2911.0,,31bf3856ad364e35
3253FE73E3C1D401
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
SystemStoreChangeId
595
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\References\Microsoft.DirectX.Direct3DX, Version=1.0.2911.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35\{2EC93463-B0C3-45E1-8364-327E96AEA856}
{75339C8C-B4BA-463B-BAC7-975FCA2F89D9}
DirectX for Managed Code
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\AssemblyFolders\DX_1.0.2911.0
C:\Windows\Microsoft.NET\DirectX for Managed Code\1.0.2911.0\
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
596
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
87
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
596
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.DirectX.DirectDraw,1.0.2902.0,,31bf3856ad364e35
E6170374E3C1D401
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
SystemStoreChangeId
596
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\References\Microsoft.DirectX.DirectDraw, Version=1.0.2902.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35\{2EC93463-B0C3-45E1-8364-327E96AEA856}
{75339C8C-B4BA-463B-BAC7-975FCA2F89D9}
DirectX for Managed Code
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
597
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1f1b577e-5e5a-4e8a-ba73-c657ea8e8598}
XACT Engine
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1f1b577e-5e5a-4e8a-ba73-c657ea8e8598}\InProcServer32
C:\Windows\system32\xactengine2_1.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1f1b577e-5e5a-4e8a-ba73-c657ea8e8598}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c60fae90-4183-4a3f-b2f7-ac1dc49b0e5c}
XACT Engine
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c60fae90-4183-4a3f-b2f7-ac1dc49b0e5c}\InProcServer32
C:\Windows\system32\xactengine2_2.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c60fae90-4183-4a3f-b2f7-ac1dc49b0e5c}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1138472b-d187-44e9-81f2-ae1b0e7785f1}
XACT Engine
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1138472b-d187-44e9-81f2-ae1b0e7785f1}\InProcServer32
C:\Windows\system32\xactengine2_3.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1138472b-d187-44e9-81f2-ae1b0e7785f1}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bc3e0fc6-2e0d-4c45-bc61-d9c328319bd8}
XACT Engine
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bc3e0fc6-2e0d-4c45-bc61-d9c328319bd8}\InProcServer32
C:\Windows\system32\xactengine2_4.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{bc3e0fc6-2e0d-4c45-bc61-d9c328319bd8}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
88
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
597
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.DirectX.DirectInput,1.0.2902.0,,31bf3856ad364e35
F43E0A74E3C1D401
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
SystemStoreChangeId
597
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\References\Microsoft.DirectX.DirectInput, Version=1.0.2902.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35\{2EC93463-B0C3-45E1-8364-327E96AEA856}
{75339C8C-B4BA-463B-BAC7-975FCA2F89D9}
DirectX for Managed Code
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
598
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
89
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
598
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.DirectX.DirectPlay,1.0.2902.0,,31bf3856ad364e35
02661174E3C1D401
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
SystemStoreChangeId
598
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\References\Microsoft.DirectX.DirectPlay, Version=1.0.2902.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35\{2EC93463-B0C3-45E1-8364-327E96AEA856}
{75339C8C-B4BA-463B-BAC7-975FCA2F89D9}
DirectX for Managed Code
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeID
599
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor64BitProcesses
90
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
StoreChangeIDFor32BitProcesses
599
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\GACChangeNotification\Default
Microsoft.DirectX.DirectSound,1.0.2902.0,,31bf3856ad364e35
B62A1674E3C1D401
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32
SystemStoreChangeId
599
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\References\Microsoft.DirectX.DirectSound, Version=1.0.2902.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35\{2EC93463-B0C3-45E1-8364-327E96AEA856}
{75339C8C-B4BA-463B-BAC7-975FCA2F89D9}
DirectX for Managed Code
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{cd0d66ec-8057-43f5-acbd-66dfb36fd78c}
XACT Engine
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{cd0d66ec-8057-43f5-acbd-66dfb36fd78c}\InProcServer32
C:\Windows\system32\xactengine2_7.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{cd0d66ec-8057-43f5-acbd-66dfb36fd78c}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{77c56bf4-18a1-42b0-88af-5072ce814949}
XACT Engine
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{77c56bf4-18a1-42b0-88af-5072ce814949}\InProcServer32
C:\Windows\system32\xactengine2_8.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{77c56bf4-18a1-42b0-88af-5072ce814949}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{54b68bc7-3a45-416b-a8c9-19bf19ec1df5}
XACT Engine
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{54b68bc7-3a45-416b-a8c9-19bf19ec1df5}\InProcServer32
C:\Windows\system32\xactengine2_5.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{54b68bc7-3a45-416b-a8c9-19bf19ec1df5}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3a2495ce-31d0-435b-8ccf-e9f0843fd960}
XACT Engine
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3a2495ce-31d0-435b-8ccf-e9f0843fd960}\InProcServer32
C:\Windows\system32\xactengine2_6.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3a2495ce-31d0-435b-8ccf-e9f0843fd960}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{343e68e6-8f82-4a8d-a2da-6e9a944b378c}
XACT Engine
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{343e68e6-8f82-4a8d-a2da-6e9a944b378c}\InProcServer32
C:\Windows\system32\xactengine2_9.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{343e68e6-8f82-4a8d-a2da-6e9a944b378c}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{65d822a4-4799-42c6-9b18-d26cf66dd320}
XACT Engine
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{65d822a4-4799-42c6-9b18-d26cf66dd320}\InProcServer32
C:\Windows\system32\xactengine2_10.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{65d822a4-4799-42c6-9b18-d26cf66dd320}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3b80ee2a-b0f5-4780-9e30-90cb39685b03}
XACT Engine
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3b80ee2a-b0f5-4780-9e30-90cb39685b03}\InProcServer32
C:\Windows\system32\xactengine3_0.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3b80ee2a-b0f5-4780-9e30-90cb39685b03}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fac23f48-31f5-45a8-b49b-5225d61401aa}
XAudio2
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fac23f48-31f5-45a8-b49b-5225d61401aa}\InProcServer32
C:\Windows\system32\XAudio2_0.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fac23f48-31f5-45a8-b49b-5225d61401aa}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c0c56f46-29b1-44e9-9939-a32ce86867e2}
AudioVolumeMeter
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c0c56f46-29b1-44e9-9939-a32ce86867e2}\InProcServer32
C:\Windows\system32\XAudio2_0.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c0c56f46-29b1-44e9-9939-a32ce86867e2}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6f6ea3a9-2cf5-41cf-91c1-2170b1540063}
AudioReverb
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6f6ea3a9-2cf5-41cf-91c1-2170b1540063}\InProcServer32
C:\Windows\system32\XAudio2_0.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6f6ea3a9-2cf5-41cf-91c1-2170b1540063}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{962f5027-99be-4692-a468-85802cf8de61}
XACT Engine
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{962f5027-99be-4692-a468-85802cf8de61}\InProcServer32
C:\Windows\system32\xactengine3_1.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{962f5027-99be-4692-a468-85802cf8de61}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e21a7345-eb21-468e-be50-804db97cf708}
XAudio2
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e21a7345-eb21-468e-be50-804db97cf708}\InProcServer32
C:\Windows\system32\XAudio2_1.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e21a7345-eb21-468e-be50-804db97cf708}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c1e3f122-a2ea-442c-854f-20d98f8357a1}
AudioVolumeMeter
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c1e3f122-a2ea-442c-854f-20d98f8357a1}\InProcServer32
C:\Windows\system32\XAudio2_1.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c1e3f122-a2ea-442c-854f-20d98f8357a1}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f4769300-b949-4df9-b333-00d33932e9a6}
AudioReverb
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f4769300-b949-4df9-b333-00d33932e9a6}\InProcServer32
C:\Windows\system32\XAudio2_1.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f4769300-b949-4df9-b333-00d33932e9a6}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d3332f02-3dd0-4de9-9aec-20d85c4111b6}
XACT Engine
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d3332f02-3dd0-4de9-9aec-20d85c4111b6}\InProcServer32
C:\Windows\system32\xactengine3_2.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d3332f02-3dd0-4de9-9aec-20d85c4111b6}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b802058a-464a-42db-bc10-b650d6f2586a}
XAudio2
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b802058a-464a-42db-bc10-b650d6f2586a}\InProcServer32
C:\Windows\system32\XAudio2_2.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b802058a-464a-42db-bc10-b650d6f2586a}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f5ca7b34-8055-42c0-b836-216129eb7e30}
AudioVolumeMeter
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f5ca7b34-8055-42c0-b836-216129eb7e30}\InProcServer32
C:\Windows\system32\XAudio2_2.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f5ca7b34-8055-42c0-b836-216129eb7e30}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{629cf0de-3ecc-41e7-9926-f7e43eebec51}
AudioReverb
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{629cf0de-3ecc-41e7-9926-f7e43eebec51}\InProcServer32
C:\Windows\system32\XAudio2_2.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{629cf0de-3ecc-41e7-9926-f7e43eebec51}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{94c1affa-66e7-4961-9521-cfdef3128d4f}
XACT Engine
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{94c1affa-66e7-4961-9521-cfdef3128d4f}\InProcServer32
C:\Windows\system32\xactengine3_3.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{94c1affa-66e7-4961-9521-cfdef3128d4f}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4c5e637a-16c7-4de3-9c46-5ed22181962d}
XAudio2
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4c5e637a-16c7-4de3-9c46-5ed22181962d}\InProcServer32
C:\Windows\system32\XAudio2_3.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4c5e637a-16c7-4de3-9c46-5ed22181962d}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e180344b-ac83-4483-959e-18a5c56a5e19}
AudioVolumeMeter
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e180344b-ac83-4483-959e-18a5c56a5e19}\InProcServer32
C:\Windows\system32\XAudio2_3.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e180344b-ac83-4483-959e-18a5c56a5e19}\InProcServer32
ThreadingModel
Both
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9cab402c-1d37-44b4-886d-fa4f36170a4c}
AudioReverb
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9cab402c-1d37-44b4-886d-fa4f36170a4c}\InProcServer32
C:\Windows\system32\XAudio2_3.dll
2664
dxwsetup.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9cab402c-1d37-44b4-886d-fa4f36170a4c}\InProcServer32
ThreadingModel
Both
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
IDENTIFY (Enter)
4000000000000000D6511A6AE3C1D4014C0B0000980D0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
IDENTIFY (Enter)
4000000000000000D6511A6AE3C1D4014C0B0000940D0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
IDENTIFY (Enter)
4000000000000000D6511A6AE3C1D4014C0B0000A8090000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
IDENTIFY (Enter)
400000000000000030B41C6AE3C1D4014C0B0000B0090000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
IDENTIFY (Leave)
4000000000000000983D266AE3C1D4014C0B0000A8090000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
IDENTIFY (Leave)
4000000000000000983D266AE3C1D4014C0B0000B0090000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
IDENTIFY (Leave)
4000000000000000F29F286AE3C1D4014C0B0000980D0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
IDENTIFY (Leave)
4000000000000000F29F286AE3C1D4014C0B0000940D0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
IDENTIFY (Enter)
400000000000000038634C6AE3C1D4014C0B0000980D0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
IDENTIFY (Enter)
400000000000000038634C6AE3C1D4014C0B0000B0090000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
IDENTIFY (Enter)
400000000000000038634C6AE3C1D4014C0B0000A8090000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
IDENTIFY (Enter)
400000000000000038634C6AE3C1D4014C0B0000940D0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
IDENTIFY (Leave)
4000000000000000EC27516AE3C1D4014C0B0000940D0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
IDENTIFY (Leave)
4000000000000000EC27516AE3C1D4014C0B0000A8090000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer
IDENTIFY (Leave)
4000000000000000EC27516AE3C1D4014C0B0000980D0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
IDENTIFY (Leave)
4000000000000000468A536AE3C1D4014C0B0000B0090000E8030000000000000100000000000000000000000000000000000000000000000000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_BEGINPREPARE (Enter)
40000000000000008248E56FE3C1D4014C0B0000B009000001040000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_BEGINPREPARE (Leave)
40000000000000008248E56FE3C1D4014C0B0000B009000001040000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPAREBACKUP (Enter)
4000000000000000360DEA6FE3C1D4014C0B0000A8090000E9030000010000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPAREBACKUP (Enter)
4000000000000000360DEA6FE3C1D4014C0B0000B0090000E9030000010000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPAREBACKUP (Enter)
4000000000000000360DEA6FE3C1D4014C0B0000980D0000E9030000010000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPAREBACKUP (Leave)
4000000000000000906FEC6FE3C1D4014C0B0000A8090000E9030000000000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_STABLE (SetCurrentState)
4000000000000000906FEC6FE3C1D4014C0B0000A809000001000000010000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPAREBACKUP (Leave)
4000000000000000906FEC6FE3C1D4014C0B0000B0090000E9030000000000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_STABLE (SetCurrentState)
4000000000000000906FEC6FE3C1D4014C0B0000B009000001000000010000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPAREBACKUP (Leave)
4000000000000000EAD1EE6FE3C1D4014C0B0000980D0000E9030000000000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_STABLE (SetCurrentState)
4000000000000000EAD1EE6FE3C1D4014C0B0000980D000001000000010000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
GETSTATE (Enter)
40000000000000006082FF6FE3C1D4014C0B0000980D0000F9030000010000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
GETSTATE (Enter)
40000000000000006082FF6FE3C1D4014C0B0000B0090000F9030000010000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
GETSTATE (Enter)
40000000000000006082FF6FE3C1D4014C0B0000A8090000F9030000010000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
GETSTATE (Leave)
40000000000000006082FF6FE3C1D4014C0B0000B0090000F9030000000000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
GETSTATE (Leave)
40000000000000006082FF6FE3C1D4014C0B0000A8090000F9030000000000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
GETSTATE (Leave)
40000000000000006082FF6FE3C1D4014C0B0000980D0000F9030000000000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_ENDPREPARE (Enter)
40000000000000006EA90670E3C1D4014C0B00004C0E000002040000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_ENDPREPARE (Leave)
4000000000000000B6A38270E3C1D4014C0B00004C0E000002040000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
PREPARESNAPSHOT (Enter)
400000000000000010068570E3C1D4014C0B00004C0E0000EA030000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPARESNAPSHOT (Enter)
40000000000000002C549370E3C1D4014C0B0000780E0000EA030000010000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPARESNAPSHOT (Enter)
40000000000000002C549370E3C1D4014C0B0000880E0000EA030000010000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPARESNAPSHOT (Enter)
40000000000000002C549370E3C1D4014C0B00009C0E0000EA030000010000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
PREPARESNAPSHOT (Leave)
4000000000000000EE3F9F70E3C1D4014C0B0000780E0000EA030000000000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)
4000000000000000EE3F9F70E3C1D4014C0B0000780E000002000000010000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
PREPARESNAPSHOT (Leave)
400000000000000048A2A170E3C1D4014C0B0000880E0000EA030000000000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)
400000000000000048A2A170E3C1D4014C0B0000880E000002000000010000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
PREPARESNAPSHOT (Leave)
400000000000000048A2A170E3C1D4014C0B00009C0E0000EA030000000000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_WAITING_FOR_FREEZE (SetCurrentState)
400000000000000048A2A170E3C1D4014C0B00009C0E000002000000010000000100000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
PREPARESNAPSHOT (Leave)
40000000000000003403C370E3C1D4014C0B00004C0E0000EA030000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE (Enter)
40000000000000003403C370E3C1D4014C0B00004C0E0000EB030000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_FRONT (Enter)
40000000000000003403C370E3C1D4014C0B00004C0E0000EC030000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
FREEZE (Enter)
40000000000000009C8CCC70E3C1D4014C0B0000980E0000EB030000010000000200000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
FREEZE (Leave)
40000000000000009C8CCC70E3C1D4014C0B0000980E0000EB030000000000000200000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_WAITING_FOR_THAW (SetCurrentState)
40000000000000009C8CCC70E3C1D4014C0B0000980E000003000000010000000200000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
BKGND_FREEZE_THREAD (Enter)
40000000000000009C8CCC70E3C1D4014C0B0000DC0F0000FC030000010000000300000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_FRONT (Leave)
4000000000000000F6EECE70E3C1D4014C0B00004C0E0000EC030000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_BACK (Enter)
4000000000000000F6EECE70E3C1D4014C0B00004C0E0000ED030000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_BACK (Leave)
40000000000000005E78D870E3C1D4014C0B00004C0E0000ED030000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_SYSTEM (Enter)
40000000000000005E78D870E3C1D4014C0B00004C0E0000EE030000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
FREEZE (Enter)
40000000000000006C9FDF70E3C1D4014C0B0000980E0000EB030000010000000200000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
FREEZE (Leave)
40000000000000006C9FDF70E3C1D4014C0B0000980E0000EB030000000000000200000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_WAITING_FOR_THAW (SetCurrentState)
40000000000000006C9FDF70E3C1D4014C0B0000980E000003000000010000000200000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
BKGND_FREEZE_THREAD (Enter)
40000000000000006C9FDF70E3C1D4014C0B000020080000FC030000010000000300000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_SYSTEM (Leave)
4000000000000000C601E270E3C1D4014C0B00004C0E0000EE030000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_KTM (Enter)
4000000000000000C601E270E3C1D4014C0B00004C0E0000F0030000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_KTM (Leave)
4000000000000000C601E270E3C1D4014C0B00004C0E0000F0030000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_RM (Enter)
4000000000000000C601E270E3C1D4014C0B00004C0E0000EF030000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
FREEZE (Enter)
40000000000000002E8BEB70E3C1D4014C0B0000B40E0000EB030000010000000200000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
FREEZE (Leave)
40000000000000003CB2F270E3C1D4014C0B0000B40E0000EB030000000000000200000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_WAITING_FOR_THAW (SetCurrentState)
40000000000000003CB2F270E3C1D4014C0B0000B40E000003000000010000000200000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
BKGND_FREEZE_THREAD (Enter)
40000000000000003CB2F270E3C1D4014C0B00006C090000FC030000010000000300000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE_RM (Leave)
40000000000000003CB2F270E3C1D4014C0B00004C0E0000EF030000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
FREEZE (Leave)
40000000000000003CB2F270E3C1D4014C0B00004C0E0000EB030000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_PRECOMMIT (Enter)
40000000000000003CB2F270E3C1D4014C0B00004C0E000003040000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_PRECOMMIT (Leave)
40000000000000003CB2F270E3C1D4014C0B00004C0E000003040000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
OPEN_VOLUME_HANDLE (Enter)
40000000000000003CB2F270E3C1D4014C0B00004C0E0000FD030000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
OPEN_VOLUME_HANDLE (Enter)
40000000000000003CB2F270E3C1D4014C0B000078090000FD030000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
OPEN_VOLUME_HANDLE (Leave)
400000000000000058000171E3C1D4014C0B000078090000FD030000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
OPEN_VOLUME_HANDLE (Leave)
400000000000000058000171E3C1D4014C0B00004C0E0000FD030000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
IOCTL_FLUSH_AND_HOLD (Enter)
400000000000000058000171E3C1D4014C0B000078090000FE030000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
IOCTL_FLUSH_AND_HOLD (Leave)
400000000000000066270871E3C1D4014C0B000078090000FE030000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
IOCTL_RELEASE (Enter)
400000000000000066270871E3C1D4014C0B000078090000FF030000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace(__?_Volume{e1a82db4-a9f0-11e7-b142-806e6f6e6963}_)
IOCTL_RELEASE (Leave)
400000000000000066270871E3C1D4014C0B000078090000FF030000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
IOCTL_FLUSH_AND_HOLD (Enter)
400000000000000058000171E3C1D4014C0B00004C0E0000FE030000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
IOCTL_FLUSH_AND_HOLD (Leave)
400000000000000066270871E3C1D4014C0B00004C0E0000FE030000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
IOCTL_RELEASE (Enter)
400000000000000066270871E3C1D4014C0B00004C0E0000FF030000010000000000000000000000000000000000000000000000000000000000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Lovelace
IOCTL_RELEASE (Leave)
400000000000000066270871E3C1D4014C0B00004C0E0000FF030000000000000000000000000000000000000000000000000000000000000000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_COMMIT (Enter)
400000000000000066270871E3C1D4014C0B00008809000004040000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_COMMIT (Leave)
400000000000000066270871E3C1D4014C0B00008809000004040000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_POSTCOMMIT (Enter)
400000000000000066270871E3C1D4014C0B00004C0E000005040000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_POSTCOMMIT (Leave)
400000000000000066270871E3C1D4014C0B00004C0E000005040000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
THAW_KTM (Enter)
400000000000000066270871E3C1D4014C0B00004C0E0000F4030000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
THAW_KTM (Leave)
400000000000000066270871E3C1D4014C0B00004C0E0000F4030000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
THAW (Enter)
400000000000000066270871E3C1D4014C0B00004C0E0000F2030000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
THAW (Enter)
4000000000000000CEB01171E3C1D4014C0B0000B40E0000F2030000010000000300000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
BKGND_FREEZE_THREAD (Leave)
4000000000000000CEB01171E3C1D4014C0B000020080000FC030000000000000300000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
THAW (Enter)
4000000000000000CEB01171E3C1D4014C0B00009C0E0000F2030000010000000300000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
BKGND_FREEZE_THREAD (Leave)
4000000000000000CEB01171E3C1D4014C0B0000DC0F0000FC030000000000000300000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
THAW (Leave)
4000000000000000CEB01171E3C1D4014C0B00009C0E0000F2030000000000000300000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_WAITING_FOR_POST_SNAPSHOT (SetCurrentState)
4000000000000000CEB01171E3C1D4014C0B00009C0E000004000000010000000300000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
THAW (Enter)
4000000000000000CEB01171E3C1D4014C0B0000780E0000F2030000010000000300000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
THAW (Leave)
4000000000000000CEB01171E3C1D4014C0B0000B40E0000F2030000000000000300000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
BKGND_FREEZE_THREAD (Leave)
4000000000000000CEB01171E3C1D4014C0B00006C090000FC030000000000000300000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_WAITING_FOR_POST_SNAPSHOT (SetCurrentState)
4000000000000000CEB01171E3C1D4014C0B0000B40E000004000000010000000300000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
THAW (Leave)
4000000000000000CEB01171E3C1D4014C0B0000780E0000F2030000000000000300000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_WAITING_FOR_POST_SNAPSHOT (SetCurrentState)
4000000000000000CEB01171E3C1D4014C0B0000780E000004000000010000000300000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
THAW (Leave)
4000000000000000CEB01171E3C1D4014C0B00004C0E0000F2030000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_PREFINALCOMMIT (Enter)
4000000000000000CEB01171E3C1D4014C0B00004C0E000006040000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_PREFINALCOMMIT (Leave)
400000000000000030C24371E3C1D4014C0B00004C0E000006040000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
POSTSNAPSHOT (Enter)
400000000000000030C24371E3C1D4014C0B00004C0E0000F5030000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
POSTSNAPSHOT (Enter)
40000000000000005A375971E3C1D4014C0B0000B40E0000F5030000010000000400000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
POSTSNAPSHOT (Leave)
40000000000000005A375971E3C1D4014C0B0000B40E0000F5030000000000000400000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
POSTSNAPSHOT (Enter)
40000000000000005A375971E3C1D4014C0B0000780E0000F5030000010000000400000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
POSTSNAPSHOT (Enter)
40000000000000005A375971E3C1D4014C0B0000880E0000F5030000010000000400000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
VSS_WS_WAITING_FOR_BACKUP_COMPLETE (SetCurrentState)
40000000000000005A375971E3C1D4014C0B0000B40E000005000000010000000400000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
POSTSNAPSHOT (Leave)
40000000000000005A375971E3C1D4014C0B0000880E0000F5030000000000000400000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
VSS_WS_WAITING_FOR_BACKUP_COMPLETE (SetCurrentState)
4000000000000000B4995B71E3C1D4014C0B0000880E000005000000010000000400000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
POSTSNAPSHOT (Leave)
4000000000000000940ACE71E3C1D4014C0B0000780E0000F5030000000000000400000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
VSS_WS_WAITING_FOR_BACKUP_COMPLETE (SetCurrentState)
4000000000000000940ACE71E3C1D4014C0B0000780E000005000000010000000400000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
POSTSNAPSHOT (Leave)
4000000000000000940ACE71E3C1D4014C0B00004C0E0000F5030000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_POSTFINALCOMMIT (Enter)
4000000000000000940ACE71E3C1D4014C0B00004C0E000007040000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SwProvider_{b5946137-7b9f-4925-af80-51abd60b20d5}
PROVIDER_POSTFINALCOMMIT (Leave)
4000000000000000BE7FE371E3C1D4014C0B00004C0E000007040000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
BACKUPSHUTDOWN (Enter)
40000000000000008E92F671E3C1D4014C0B00004C0E0000FB030000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
BACKUPSHUTDOWN (Enter)
4000000000000000F61B0072E3C1D4014C0B0000A40E0000FB030000010000000500000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
BACKUPSHUTDOWN (Enter)
4000000000000000F61B0072E3C1D4014C0B0000980E0000FB030000010000000500000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer
BACKUPSHUTDOWN (Leave)
4000000000000000F61B0072E3C1D4014C0B0000A40E0000FB030000000000000500000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
BACKUPSHUTDOWN (Enter)
4000000000000000F61B0072E3C1D4014C0B00009C0E0000FB030000010000000500000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer
BACKUPSHUTDOWN (Leave)
4000000000000000F61B0072E3C1D4014C0B0000980E0000FB030000000000000500000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer
BACKUPSHUTDOWN (Leave)
4000000000000000F61B0072E3C1D4014C0B00009C0E0000FB030000000000000500000000000000045117040383094BBFE5D9556D18F1830000000000000000
2892
vssvc.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssvcPublisher
BACKUPSHUTDOWN (Leave)
4000000000000000F61B0072E3C1D4014C0B00004C0E0000FB030000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
3892
DllHost.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppCreate (Enter)
40000000000000001C153E6AE3C1D401340F000098080000D0070000000000000000000000000000000000000000000000000000000000000000000000000000
3892
DllHost.exe
write
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
LastIndex
21
3892
DllHost.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppGatherWriterMetadata (Enter)
40000000000000007677406AE3C1D401340F000098080000D3070000000000000000000000000000000000000000000000000000000000000000000000000000
3892
DllHost.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
IDENTIFY (Enter)
4000000000000000D0D9426AE3C1D401340F0000A80A0000E8030000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
3892
DllHost.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
IDENTIFY (Leave)
4000000000000000B2810D6BE3C1D401340F0000A80A0000E8030000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
3892
DllHost.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppGatherWriterMetadata (Leave)
400000000000000096E7C36FE3C1D401340F000098080000D3070000010000000000000000000000000000000000000000000000000000000000000000000000
3892
DllHost.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppAddInterestingComponents (Enter)
400000000000000096E7C36FE3C1D401340F000098080000D4070000000000000000000000000000000000000000000000000000000000000000000000000000
3892
DllHost.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppAddInterestingComponents (Leave)
40000000000000000C98D46FE3C1D401340F000098080000D4070000010000000000000000000000000000000000000000000000000000000000000000000000
3892
DllHost.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
PREPAREBACKUP (Enter)
4000000000000000DCAAE76FE3C1D401340F00000C0E0000E9030000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
3892
DllHost.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
PREPAREBACKUP (Leave)
40000000000000000620FD6FE3C1D401340F00000C0E0000E9030000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
3892
DllHost.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
GETSTATE (Enter)
40000000000000000620FD6FE3C1D401340F0000340E0000F9030000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
3892
DllHost.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
GETSTATE (Leave)
40000000000000006082FF6FE3C1D401340F0000340E0000F9030000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
3892
DllHost.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
DOSNAPSHOT (Enter)
40000000000000006EA90670E3C1D401340F0000980800000A040000010000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
3892
DllHost.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher
DOSNAPSHOT (Leave)
400000000000000066270871E3C1D401340F00003C0E00000A040000000000000000000000000000045117040383094BBFE5D9556D18F1830000000000000000
3892
DllHost.exe
write
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
SppCreate (Leave)
4000000000000000C0890A71E3C1D401340F000098080000D0070000010000000000000000000000000000000000000000000000000000000000000000000000
3840
DrvInst.exe
write
HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\5F\52C64B7E
LanguageList
en-US

Files activity

Executable files
23
Suspicious files
89
Text files
669
Unknown types
14

Dropped files

PID
Process
Filename
Type
3492
5e2b3771c665c2538cde7cbd4e5595793044adeaaad853ab5a8d9f4260b1460f.exe
C:\Users\admin\AppData\Local\Temp\ixdED52.tmp
executable
MD5: 685f1cbd4af30a1d0c25f252d399a666
SHA256: 0e478c95a7a07570a69e6061e7c1da9001bccad9cc454f2ed4da58824a13e0f4
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\dxupdate.dll
executable
MD5: a2a0da126c1a2f8b615b363e862989a2
SHA256: 300abf15fc1b38373053b898ad9a57098fa5656f26325f45b3d644befa74d428
2664
dxwsetup.exe
C:\Windows\system32\d3dx10.dll
executable
MD5: 6f34f7405807dcbf0b9bf6811c94c6d9
SHA256: fd2caa28493ea76021b93641958238b7a933f4f6db1a2070be03cc81d87d8307
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxupdate.dll
executable
MD5: a2a0da126c1a2f8b615b363e862989a2
SHA256: 300abf15fc1b38373053b898ad9a57098fa5656f26325f45b3d644befa74d428
2664
dxwsetup.exe
C:\Windows\Microsoft.NET\DirectX for Managed Code\1.0.2906.0\Microsoft.DirectX.Direct3DX.dll
executable
MD5: afcf5f50c632f3a5598abc28f196d77c
SHA256: 5e90089e69e4f7e2e42ea4a81fb62005c3710d0a4acdf207b97ed03f5641d013
2664
dxwsetup.exe
C:\Windows\system32\directx\websetup\dsetup32.dll
executable
MD5: 7672509436485121135c2a0e30b9e9ff
SHA256: d7ea3cf1b9b639010005e503877026597a743d1068ae6a453ce77cc202796fea
2664
dxwsetup.exe
C:\Windows\system32\d3dx9_35.dll
executable
MD5: 3ef18b78d17c962f2b71ac1cb7757684
SHA256: 2198022938156b790e9cfb0f7997494b66a11a1ad49b395be58251d635b66b26
2664
dxwsetup.exe
C:\Windows\system32\directx\websetup\dsetup.dll
executable
MD5: 0a23038ea472ffc938366ef4099d6635
SHA256: 8f2c455c9271290dcde2f68589cf825f9134beecb7e8b7e2ecbcabeab792280a
2664
dxwsetup.exe
C:\Windows\system32\XAudio2_2.dll
executable
MD5: 50f4a0d5e6a0bafefa78f353533b8e06
SHA256: 9c7897b4ee1bcd190b1c0b7b77e64ee731d234764683a1e2286af70d86b62753
3492
5e2b3771c665c2538cde7cbd4e5595793044adeaaad853ab5a8d9f4260b1460f.exe
C:\Users\admin\AppData\Local\Temp\IXP000.TMP\dsetup32.dll
executable
MD5: 7672509436485121135c2a0e30b9e9ff
SHA256: d7ea3cf1b9b639010005e503877026597a743d1068ae6a453ce77cc202796fea
2664
dxwsetup.exe
C:\Windows\Microsoft.NET\DirectX for Managed Code\1.0.2907.0\Microsoft.DirectX.Direct3DX.dll
executable
MD5: ccd53738df4fa27849b6bb05dd67d10d
SHA256: c29d337bf7639fbf424b34cc0409d2715762e1b4d82881fb524a2508381c9f62
2664
dxwsetup.exe
C:\Windows\system32\XAPOFX1_1.dll
executable
MD5: d95eaabf5d277ef91d9ca70151209e56
SHA256: 5ab63c0f040fdf65e681eba4daa55ed83e89ea10c426dc2fc763da0fc94f3ace
2664
dxwsetup.exe
C:\Windows\Microsoft.NET\DirectX for Managed Code\1.0.2908.0\Microsoft.DirectX.Direct3DX.dll
executable
MD5: 43c280c3b15ceb2472ab560d09629664
SHA256: bebbc40ca25ef22e9d16b0de1123e0cb0444fe7a78b4f0b4395bdfd81618698c
3492
5e2b3771c665c2538cde7cbd4e5595793044adeaaad853ab5a8d9f4260b1460f.exe
C:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxwsetup.exe
executable
MD5: eaa6b5ee297982a6a396354814006761
SHA256: d298fd82a39b2385a742ba1992466e081bea0f49e19ece6b2c87c7c262e1fcee
2664
dxwsetup.exe
C:\Windows\Microsoft.NET\DirectX for Managed Code\1.0.2909.0\Microsoft.DirectX.Direct3DX.dll
executable
MD5: 490807c150b7d8be44bde871f4df8c56
SHA256: 36a21fc4f4c8f6ba4ad900613ee1b08ff43f2545585a2601c9fc4cf083d68a77
2664
dxwsetup.exe
C:\Windows\system32\X3DAudio1_5.dll
executable
MD5: 350fefe18b86bd4d9ab2a96d00215a49
SHA256: 315944bb2a1959c8a4bd2677ed415363e1611c7351ce55319dc98fd2aac83f87
2664
dxwsetup.exe
C:\Windows\system32\d3dx9_32.dll
executable
MD5: 26af232140c88b42d92a88f2198edf6a
SHA256: e96693794daa05a75a83c11df2e7b42f2de61567c6ad0b69e353b50f6c88119f
3492
5e2b3771c665c2538cde7cbd4e5595793044adeaaad853ab5a8d9f4260b1460f.exe
C:\Users\admin\AppData\Local\Temp\IXP000.TMP\dsetup.dll
executable
MD5: 0a23038ea472ffc938366ef4099d6635
SHA256: 8f2c455c9271290dcde2f68589cf825f9134beecb7e8b7e2ecbcabeab792280a
2664
dxwsetup.exe
C:\Windows\system32\d3dx9_30.dll
executable
MD5: e415862612e65f10d7d888443ecd7594
SHA256: 5edeed79f2359527a55b8189cfa8b9b121cd608d44eead905a0f3436938ad532
2664
dxwsetup.exe
C:\Windows\system32\d3dx9_25.dll
executable
MD5: 5b48fe9d6686f0d54b26a005ace24d1d
SHA256: 4c54df27ce84d21b2924e64ff79b13e7876ce85d8e0c9c1d0abd8da73888187a
2664
dxwsetup.exe
C:\Windows\system32\xinput1_1.dll
executable
MD5: f1726346e583442541fe73429f8e9c10
SHA256: 69cd725c53e0302e75db20e9a3e4b33f58dceaa2e6ea4938b2733df8bc289a71
2664
dxwsetup.exe
C:\Windows\system32\xactengine2_2.dll
executable
MD5: 5c4d3843b491c047b7a619901fbd2ec1
SHA256: 4f996edb65022e33ae9c9f7acf7232c8d444f75c50c72894f6d3173b55404ebe
2664
dxwsetup.exe
C:\Windows\system32\xactengine2_5.dll
executable
MD5: 86c93789e9006f1ac47ed9dd47d4c8a1
SHA256: ec68b5163cbb5f15e2fbe37fdf5fcb0d01dffbe53a460cb2cf668f31f0127ad5
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\d3dx10_35_x86.cat
cat
MD5: 1a06dcf047d9efbaaf36eb0de5662517
SHA256: 6b29839ad6d799c4113b7647bc3e4ecb78ff3a6ed56f1ccca5de94dc2a2cf646
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\xactengine3_3.dll
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: f2dea787af4989f7518ed80c70c0ed7f
SHA256: c329572169692f16780d458617621055520410e98b300121bd54c1610cf3b054
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\d3dx10_33_x86.inf
text
MD5: 462bb24dfbb87867637dc601a0ddc23a
SHA256: d6457a68385d4d311b1109793c0c077a13ccbc43ca3f42c617b8d15b0f2c11b2
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\d3dx10_33_x86_xp.inf
text
MD5: 5d217e6c11ac303c9c61ee436c954899
SHA256: f58bf3328724be092f6cd71fb48f27d9d632e6c94147b2e655501cf513dee7a4
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\d3dx10_33.dll
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\d3dcompiler_33.dll
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 2f8e5fc38a29489108a38ac91b9f4bca
SHA256: c3d0c9c62941b0383d4509864dbadab3e8ea69c1a6b8916f265ea6f65fc8d60b
2664
dxwsetup.exe
C:\Windows\system32\SETC569.tmp
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\Temp\OLDC538.tmp
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\xact2_5_x86.inf
text
MD5: 421e64b7b680496dac0ba4e8296aba07
SHA256: 3f15fdd7620748e20d28abdf0d3c1f0f4e086090e738097980ed91fc4c33f0e0
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: a47a050999a961f9491787bc0a939bb3
SHA256: 7ba66b75c76ba0c4774ba69aeacf8ba1fb83f007d280f596f14f0a0ff1a963e7
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\xactengine2_5.dll
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\SETC548.tmp
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\xact2_5_x86.cat
cat
MD5: 0c3e6cf675cb014078fd5bd3e744e4c3
SHA256: 6bd4a64c5584ac8b32a8e497ef8817e269f7e7bcbefa6f56ff3dff69b5f1bd11
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\d3dx10_00_x86.inf
text
MD5: 18b9a4920173c3f49719d11d69c2cfdb
SHA256: 4f744bbff149fa0535801a78e71027fb8b6e4b50ef4e4b593972bf0e6639645f
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\X3DAudio1_5_x86.inf
text
MD5: d7b306519b5fae78ee8ee966e5453795
SHA256: a8353cd34b7e4cfdd834eb47e8392d756fdaa275fc738af90f34fd18f2cd3e31
2664
dxwsetup.exe
C:\Windows\system32\SETC528.tmp
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\d3dx10.dll
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\d3dx10_00_x86.cat
cat
MD5: da04fa4c903cd644f1cc63061107da98
SHA256: 08073ee11424f50fe41a3d46d8dafb4da52c0ef1bbb3a9be7f258358eea89aa0
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\X3DAudio1_5_x86_xp.inf
text
MD5: 54c01bb72e65ca2e2b3994af7c5462f6
SHA256: 21f29dcb4c1d0c7265418f1552ca038dd97d6c407974dc7c130f8be32feb9a92
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\d3dx9_32_x86.inf
text
MD5: 93d4faddad0877f23d94aff547a31246
SHA256: e71a1f75125a6d2066c21cdd460526a2a302c5f9fba3e982869af2f65ffb9d8e
2664
dxwsetup.exe
C:\Windows\system32\SETC508.tmp
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\d3dx9_32.dll
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\d3dx9_32_x86.cat
cat
MD5: bd281b6ff66afa7aa9db27cc6d7ef17d
SHA256: bb9f690021d4a6e70a8a0b9e9d9d2c8c0136df7894070ca9a5b021a7675f3524
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: e9f1d877c758befdaae4b544cfa9d1b7
SHA256: 123560236f89ef4c517fac5893b1452af1a72264cf60deba3f8642054621e8d9
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\xinput1_2_x86.cat
cat
MD5: b47e51acbd6228f97d78be60f82faf75
SHA256: 29e74b99182985971ca5466f6b0daa497aab19c2d073357dc1e68014121b74f8
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\X3DAudio1_5_x86.cat
cat
MD5: cc862c41ed7feeefd5307422ff6bd6d8
SHA256: d1caa3ba1a851a91acf684638ff7c9b0fba37647b565f9e5ca40bb217bde59bc
2664
dxwsetup.exe
C:\Windows\Temp\OLDC314.tmp
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\xact2_2_x86.cat
cat
MD5: 51b010e4e55a4ac9e05ed39121a17a93
SHA256: f673488445046e53f7a40bfe416e4ec0fb3ec268af733e3ed9dcf10430c1ae2e
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\xact2_2_x86.inf
text
MD5: 9c74a78b10314de107000779dbb6a68a
SHA256: a3b3bc3b262a5b38f9e2c5f721fa5b2dd695edb3df9e138ec47a59dd640e5cc5
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\xactengine2_2.dll
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\SETC30E.tmp
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\X3DAudio1_5.dll
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\SETC2EE.tmp
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\xinput1_1_x86.inf
text
MD5: ebe8e8cce0661db2b42f6f6d8ab5e7d7
SHA256: bbc3d13e4e40ce5091bfe8f7853ca61ad1ae464a00410ceb7e2055b6db4edffd
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\xinput1_1_x86.cat
cat
MD5: 22cdfe6b9b7fe51cc216ff42b2557672
SHA256: 1961c9e69813f23c88cd630f135b9ed7e68135ea86462a1a2e00399513393bb2
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\xinput1_1.dll
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 7b7609ae4f32e96c194ee6185cfdcf8a
SHA256: 6e404ae4daea1b12e79292ab983fa5adb28934d00dddaef8f9c27230a39942c3
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\microsoft.directx.directinput.dll
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\microsoft.directx.directdraw.dll
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\microsoft.directx.diagnostics.dll
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\microsoft.directx.direct3d.dll
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\microsoft.directx.direct3dx.dll
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\microsoft.directx.audiovideoplayback.dll
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\SETCF29.tmp
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\SETC0E8.tmp
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\d3dx9_30_x86.inf
text
MD5: 0c1f7bc7c5fd19f4e41f473203f49254
SHA256: 73fc8d6974793573d6ee4fde086557a462f245a4dc2053001c79f6a9086273fc
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\d3dx9_30_w9x.inf
text
MD5: f9f5c12e7adeb914057197f4836eae94
SHA256: 61cf7b62c2041a987f1e812ef744cba913d8b012b9f869916ca440c7a06feb7e
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\d3dx9_30.dll
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: e47d39e68da8ae717c2200d1119fad4e
SHA256: 1a1dc0d9a9a5429aa2a7d64e0a0feb79f71e37a2930bc52e969e5ea910e2cfbe
2664
dxwsetup.exe
C:\Windows\system32\SETBF3C.tmp
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\d3dx9_26_w9x.inf
text
MD5: f6333b9218c2b7a29ad6492f0e20091f
SHA256: ac38efa08521241ba8cff290dba894cf931050767d9fefdeee75d4d41c330c9a
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\d3dx9_26_x86.inf
text
MD5: f58b94199b4230f65220f9cf34804207
SHA256: 2cb1283ecbc26e12b74786d480578ec10ca46f42d1c1224840bfc68a48563c65
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\d3dx9_26.dll
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\d3dx9_26_x86.cat
cat
MD5: b4cdaf48067a88cc013b0cdd6b26842d
SHA256: 14a4088ac06120ebd9e3304ed9668b44d6981f05854035998b42a4c25301a871
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\XACT3_3_x86_xp.inf
text
MD5: 832c577d4ab4eb9577422340243c8c04
SHA256: 3ac15db9e4cc0f426ab5b062735ba61569d39ead9b2727b0eb43a58df300e988
2664
dxwsetup.exe
C:\Windows\system32\SETBEFD.tmp
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\d3dx9_25_x86.inf
text
MD5: cfd6814c8fabf83942a9a147d718a51d
SHA256: c6311775372764bcbaf63cf688b8d072c10b0a7697087e68136bbe1a0f8a4cdf
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\d3dx9_25_w9x.inf
text
MD5: 4ef33966a1ae182befa674d6dda2481c
SHA256: 457e693836b2027096afc54de33caff9b70267a7e2ed03d49d53ca8a0b0e2819
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\d3dx9_25.dll
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\d3dx9_25_x86.cat
cat
MD5: 22fecea595511a218227bf0314e9ef1c
SHA256: 0642ee5c7587468a1d18cae93d40ef88e29f38bb4f6e208614dc7029f5acca19
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 9a61e37ccfa63b5e7ca5d16182240340
SHA256: 58339727e0efa41c251df85b652b0c581287e938f063c8c38a422ecc062cc749
2664
dxwsetup.exe
C:\Windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2910.0__31bf3856ad364e35
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\assembly\tmp\5HP2TCEY\__AssemblyInfo__.ini
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\assembly\tmp\5HP2TCEY\Microsoft.DirectX.Direct3DX.dll
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\SETCEDA.tmp
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\Microsoft.NET\DirectX for Managed Code\1.0.2909.0\Microsoft.DirectX.Direct3DX.xml
text
MD5: dae21601cf373590e5ab8eb13fb79b7a
SHA256: 59986eba5cb424d9c388a2d23e4581ae465d3ff767eee913f6cd07dc1f9e7254
2664
dxwsetup.exe
C:\Windows\assembly\tmp\3MZSQYLG\Microsoft.DirectX.Direct3DX.dll
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\assembly\tmp\3MZSQYLG\__AssemblyInfo__.ini
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2909.0__31bf3856ad364e35
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\Microsoft.NET\DirectX for Managed Code\1.0.2908.0\Microsoft.DirectX.Direct3DX.xml
text
MD5: dae21601cf373590e5ab8eb13fb79b7a
SHA256: 59986eba5cb424d9c388a2d23e4581ae465d3ff767eee913f6cd07dc1f9e7254
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\XACT3_3_x86.inf
text
MD5: d8b0f8510f90976cf1b1d700b643002b
SHA256: c4772ae50b79c4c31636ecad921ffc913e43922c21923be8b8b518cf2ce681b3
2664
dxwsetup.exe
C:\Windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2908.0__31bf3856ad364e35
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\assembly\tmp\TUHHWS6X\Microsoft.DirectX.Direct3DX.dll
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\assembly\tmp\TUHHWS6X\__AssemblyInfo__.ini
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\SETCEC9.tmp
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\Microsoft.NET\DirectX for Managed Code\1.0.2907.0\Microsoft.DirectX.Direct3DX.xml
text
MD5: dae21601cf373590e5ab8eb13fb79b7a
SHA256: 59986eba5cb424d9c388a2d23e4581ae465d3ff767eee913f6cd07dc1f9e7254
2664
dxwsetup.exe
C:\Windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2907.0__31bf3856ad364e35
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\assembly\tmp\O32JTAQU\Microsoft.DirectX.Direct3DX.dll
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\assembly\tmp\O32JTAQU\__AssemblyInfo__.ini
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\XAudio2_2_x86.cat
cat
MD5: de03ccb611da2416668b43563466b53d
SHA256: b12e54cdd384459a5efcdf6eee3d49e9ce17d044b790613598690c4ef99f635b
2664
dxwsetup.exe
C:\Windows\Microsoft.NET\DirectX for Managed Code\1.0.2906.0\Microsoft.DirectX.Direct3DX.xml
text
MD5: dae21601cf373590e5ab8eb13fb79b7a
SHA256: 59986eba5cb424d9c388a2d23e4581ae465d3ff767eee913f6cd07dc1f9e7254
2664
dxwsetup.exe
C:\Windows\assembly\GAC\Microsoft.DirectX.Direct3DX\1.0.2906.0__31bf3856ad364e35
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\assembly\tmp\EXYEUXLK\__AssemblyInfo__.ini
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\assembly\tmp\EXYEUXLK\Microsoft.DirectX.Direct3DX.dll
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 877438f57c18277193d4c701404b7896
SHA256: d8c4faaf56575300be9956c4a1778d59831c8721b084e3792290d6fdca544ea2
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\JUN2010_XAudio_x86.inf
text
MD5: 31d8732ac2f0a5c053b279adc025619f
SHA256: d786d06a709d5dc26067132b9735fc317763fcf8064442d6f77f65012ba179da
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\JUN2010_XACT_x86.inf
text
MD5: dbef26a0b937dc1859e9582aa88bf928
SHA256: ca604ce9d2ee43a09b39b23a6a2a048b1a79d85c7d78679cc73aacc75cf7a62e
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\JUN2010_D3DCompiler_43_x86.inf
text
MD5: 1a86443fc4e07e0945904da7efe2149d
SHA256: 5dd568919e1b3cbcb23ab21d0f2d6c1a065070848aba5d2a896da39e55c6cbbf
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\JUN2010_d3dcsx_43_x86.inf
text
MD5: cf70b3dd13a8c636db00bd4332996d1a
SHA256: d5200b332caf4fff25eb3d224527a3944878c5c3849512779a2afcfeae4c3ca1
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\JUN2010_d3dx11_43_x86.inf
text
MD5: fb5d27c88b52dcbdbc226f66f0537573
SHA256: 3925c924eb4ec4f5a643b2d14d2eda603341fbbd22118cdd8ae04aaa96f443c0
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\JUN2010_d3dx10_43_x86.inf
text
MD5: 53a24faee760e18821ef0960c767ab04
SHA256: 4d4263cbb11858c727824c4a071f992909675719be3076b4a47852bf6affd862
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\JUN2010_d3dx9_43_x86.inf
text
MD5: a11deb327119b65bacce49735edc4605
SHA256: 6b33d32da02f664092d44b05237990f825b4062c105a063badcf978648b5e95b
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\FEB2010_XAudio_x86.inf
text
MD5: e6e942a2cfbb587bfcc4203b5bb34fd4
SHA256: 74c827ef94881099761e04397ef8f162fd0ccaf4876a5503c4b53a5216d2acca
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\FEB2010_XACT_x86.inf
text
MD5: 82c10b720e33be099f69e4010d44ecd2
SHA256: e850fdb84bcac0f667927e53fee943efd3f43be6c6a0ae1e17f3fff83ddb2635
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\FEB2010_X3DAudio_x86.inf
text
MD5: e84adf38d499ae39090ad60fd76d76e3
SHA256: d4da3e530982812d1e2a31570b80af541fac1b13c72997d2aad7ea3bfeaf4a4a
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\AUG2009_XAudio_x86.inf
text
MD5: 6d9bf03bfc9465df08d17b18c431926b
SHA256: 842cc52100b5774bcda19e40837bd552b308e74829d5b35a505822c7436892e1
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\AUG2009_XACT_x86.inf
text
MD5: 5b6e899df58c5dd0201934027490278c
SHA256: 1eb88b5460824fd32eec9b90e7ef5cb529f51215046e539d39fa27a409709766
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\AUG2009_D3DCompiler_42_x86.inf
text
MD5: e7f9ca8ca804cc404f855be173f6ac61
SHA256: bb8834d2366f6899c507bae176a13dadbd44488451a263eac830be95f4bad43f
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\AUG2009_d3dcsx_42_x86.inf
text
MD5: a156f288883f2c1e867896c114509aaa
SHA256: ff9da1b0328fd918cf9558ee57387a4865afe98db1410cc16b1e921c5a744c48
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\AUG2009_d3dx11_42_x86.inf
text
MD5: 9deabc0af1186bc22a6feacaddc5839a
SHA256: edf6764083b47c04fda52b149f565587c6a07d4455357fe3c27c9e56cc57a94d
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\AUG2009_d3dx10_42_x86.inf
text
MD5: b3a2e761e5da007cc6036c5703e12eed
SHA256: a80a00464775da82c02f628c5bc13cab0d0643ec2a44b28d2acf7c77d467becf
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\AUG2009_d3dx9_42_x86.inf
text
MD5: dff48361a5cb0dea034dc6f16de99477
SHA256: 5989dc367a8f84815bcfa1c46ff756527c6250c62973220d1af354b70027eaf2
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 65e270bc5b619316eea745449dce0416
SHA256: d239eaa168d925633581bf2fe43491c9e38d4ae5ad8c2c6f51f2e74e2d4de245
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\Mar2009_d3dx10_41_x86.inf
text
MD5: 6f64b88a71edf6070f48277cc7e22125
SHA256: 0170a4b551b58d92a753e86793bf3af762fe3f8d781512f710a4d661aec8d626
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\Mar2009_d3dx9_41_x86.inf
text
MD5: b37a5ff044eb65521a290c79ba1a3e00
SHA256: bd29711cc2ecd924990167ffa95f48842e24aeed3acef1023717040240b4bbb6
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\Mar2009_XAudio_x86.inf
text
MD5: ce1394e17492dac92e0257482272617c
SHA256: 1b66e4d80f9843fc73b0a6097fb8ed5f3d2cfd5cfb5c328904d2c370bd87bb3e
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\Mar2009_XACT_x86.inf
text
MD5: 25b4458970583bd63b3e21ca5eda19b4
SHA256: 764c3caeb1725a11701ca7119fdc49b3219553b79f9a5c1a02b20991391e5a21
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\Nov2008_d3dx10_40_x86.inf
text
MD5: 7a3a4c3b7c9c979261ab1fe477809731
SHA256: a4eed39cf36adccac4317e5822b30aa37ac5b001bcf4a24f7b5ccac6b8b71e9d
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\Mar2009_X3DAudio_x86.inf
text
MD5: c1501e224e63e7c7fbdbfb7734a8e4f0
SHA256: aabd029d75f25244bae4ca17dbf9c4feebec0d5f121fcd388c175c3360be1bac
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\Nov2008_d3dx9_40_x86.inf
text
MD5: d9f6cb1edf9f92a045f4b2b8ec17cdb9
SHA256: 955637638635025f01f82febab4a4977252a765439d90ce940fba752723b9db6
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\Nov2008_XAudio_x86.inf
text
MD5: 052b3294a9345385406ac2056e724804
SHA256: 950b5aef596fc5048732f6cf263dfca5bcc25df7dc17df91efcbc3551751a3b3
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\Nov2008_XACT_x86.inf
text
MD5: 87c8d16c6db20854f9610bd5be6e5ae5
SHA256: 31680e7a90d24eda04c910e1f3e6c02774cfc5c36ae08e7ac043665264702f83
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\Aug2008_XAudio_x86.inf
text
MD5: e0947065f559b93eb93a7ceeaa8bfd44
SHA256: f211a7d99b3ffa0180bd91f68b2c285564227e075d499e950e76fde04e7707e3
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\Nov2008_X3DAudio_x86.inf
text
MD5: e8adbd1e68258d5657a34ea722f3bd32
SHA256: d0361ffe046b7a7a374a4938d419e4121365892e4f2138899f670619ab34ac6a
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\Aug2008_XACT_x86.inf
text
MD5: d2aedfbc8bd56092d658bd60b464dfa5
SHA256: f1daaa8d96108a4a338f62a4a1339143ddc566e194ca00dde5427136bfccb0af
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\Aug2008_d3dx10_39_x86.inf
text
MD5: baa493c7a361f1ac0c5efc94f1568f97
SHA256: e83f8d48323887af89648c5bd7af713b42d20ccb757be34675f1fa527e6cc33f
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\Aug2008_d3dx9_39_x86.inf
text
MD5: b28ef6e3eebceb622d1431fedd9f545a
SHA256: 8a23d386626328f9519076f33d5c3b71c639f2347741442c3374974e6f61bd53
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\Jun2008_XAudio_x86.inf
text
MD5: e82ee7f4d71ae8bf90378bb6dc107d57
SHA256: e5e435c4536f987e1087218b025e6dc66c24c3e300e839391891f1b3bfd360dd
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: e1326c0639adec0b883b4fbe948e75ae
SHA256: 917914192affcc9cfb789c039841662c4f5ea1e0b173b3a94c0aa0acddcabaab
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\Jun2008_XACT_x86.inf
text
MD5: 59c4f83a7fa2a8dee4970d37a96c2b55
SHA256: 79cb10222e466d54908d30ee433830e9673d5a538fabc5f4568521c2aff66eb1
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\Jun2008_X3DAudio_x86.inf
text
MD5: 7949a4d37b517c39295f0d656cbde501
SHA256: 0064b7db5bfe52b6f40f61d962901c7baa116abbc72328f50586b6fa65f894bd
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\Jun2008_d3dx10_38_x86.inf
text
MD5: d12a6b9889eeb330b4a4e86e9bd175ae
SHA256: f5f54664ec67f6333a9f0607d891bd0dc2acfee8cce09ac4ee0372b5d0aa12fd
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: dc0ddab8d1d3fb4978a2d985bced97fe
SHA256: a231b2cde868b0ebd42dcb494718a1534e712980026351170c1511b8c2442561
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\Jun2008_d3dx9_38_x86.inf
text
MD5: c7fc0a82355bafed08a5597930b80263
SHA256: 06faf7f7ea5503dcece13d6537e57cd2581d5188a5d839fe7f118298a721b51a
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\Mar2008_XAudio_x86.inf
text
MD5: 35c6f6f109257f242cfb2ad2062d50c4
SHA256: 472bcfb54b5d63377da128596dfb30c8f200f79edaaf6d29de1afcdb71a3413d
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\Mar2008_XACT_x86.inf
text
MD5: e3ad8befca2528572d6c51a15e072c94
SHA256: 6b0cc0dc993e172855864fa078c4e5c8f2f46bfc3200bf2ccdf3292931ee3cb2
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\Mar2008_X3DAudio_x86.inf
text
MD5: 9ab8a749708995453ee8a995a877af2b
SHA256: 0b6e28f00364a9ff436c3d99f0d4e80bf615f1450f420122324853cc0b88b16c
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\Mar2008_d3dx10_37_x86.inf
text
MD5: 1242da12c637d5976af936f60f387c26
SHA256: bae3bc2b7071d2d1c657a87a8c8af6c0fb5373f11c9aa5f61b406924717d0792
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\Mar2008_d3dx9_37_x86.inf
text
MD5: 020d1260794d5780937f0f7a919cd62d
SHA256: d55858e166a2fe00d4acc30da756f0ab2c4dd5a79a9874eab3100722c74a1b75
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\nov2007_xact_x86.inf
text
MD5: 7e2a5eadf9f1eaf90d5eac15b7a9f558
SHA256: 24714f229e479338ed89bdd6143140505fd63f517b7e71170ea6c072a1748b06
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\nov2007_x3daudio_x86.inf
text
MD5: 4287ed3f6647fcd80ec6b0f7f2606964
SHA256: f882bdbc8230d24b24e20f9d0db447586e9493801900a8ba381eb493bd41f5d5
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\nov2007_d3dx10_36_x86.inf
text
MD5: 582814cd47564fe8e3424cb2eb090501
SHA256: 96f48bb810055699d37e9e27a65947483a0b4df304870e3b5448d3051b3e4926
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\nov2007_d3dx9_36_x86.inf
text
MD5: 08ffe480ee5e54fc19a2feea46adced6
SHA256: 843764f70f56d430c0695e263c895a135a631f793213d1005fafcf9c210d1ac9
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: b91775370189064a41ec7b0237ecc6fb
SHA256: 44ab00b7cbae7d1a1e139f1ada0ab6abed11214748217f9a49a1c12518050516
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\apr2006_xact_x86.inf
text
MD5: f67df97463d42bedc122fbedc37096c4
SHA256: 037db252501fd0e30303c11706d804d9eabbf319d0b4e88181ef8f297b4fef8e
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\apr2006_mdx1_x86.inf
text
MD5: 2ca62bfeb43facdd1fc06f20fb20397b
SHA256: 2546a1875bf868edc621a1cd0ee262151faa08762bcced0117e1304eace0c04d
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\apr2006_d3dx9_30_x86.inf
text
MD5: a49046c25439fa900b1d1bf826506ce3
SHA256: 373cca07c0ceffa72901441219a4457de9ff110aededae5e4818588da39cd344
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\feb2006_xact_x86.inf
text
MD5: 9dda266ba05cd917cca889659e3b98c8
SHA256: 45146fd446fc8533dc5f97d88bee9ae220161f24797114d0bf3afc7c479ed69b
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\feb2006_d3dx9_29_x86.inf
text
MD5: f4c258b663ebf54c55d7d09b05b26ff6
SHA256: f12f4bd86d5cd748b0fcf7106e9dff333c27c0886541339ba1f40c443bdc61cd
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\dec2005_d3dx9_28_x86.inf
text
MD5: e0b6120a048295ebbc629a9f8fbe53ad
SHA256: d4d03c4ab3c8486d6331548e967ee17e011fdac90f63c0a9a44a744815a7da7a
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\aug2005_d3dx9_27_x86.inf
text
MD5: e45a175750a672cbb2553087a8c5cf8a
SHA256: d02232a6587c460c026601517178318bab2ac29c59d269c6e3d1a3a993a9a1c4
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 02ac1a299d57adcab6bea178648cbbaf
SHA256: 194d3f240832b4f131fe3f31259eaf915f90a63f924b4be1485797886db48a82
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\jun2005_d3dx9_26_x86.inf
text
MD5: 62f8ec9c0d3bd54ace90cb15f5caa208
SHA256: 262ed4a65dd45e19f196cb2d9946326693ee31a86b51bf77116dec2727971cb6
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\mdx_1.0.2907.0_x86.inf
text
MD5: 81700fd8d24ccd5ed83ce202dadcc625
SHA256: 3bd14cf2a96544ece692e1911500f7196370a111017fb6b0e23db0f0d0f40dfa
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\mdx_1.0.2906.0_x86.inf
text
MD5: 81700fd8d24ccd5ed83ce202dadcc625
SHA256: 3bd14cf2a96544ece692e1911500f7196370a111017fb6b0e23db0f0d0f40dfa
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\mdx_1.0.2905.0_x86.inf
text
MD5: 81700fd8d24ccd5ed83ce202dadcc625
SHA256: 3bd14cf2a96544ece692e1911500f7196370a111017fb6b0e23db0f0d0f40dfa
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 2d8199e75b3ae513477de9d5390d1442
SHA256: d985be5e90232068025f2e2bcaf584abd516661ff4902d048416d1dcb2ea34d5
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\mdx_1.0.2904.0_x86.inf
text
MD5: 81700fd8d24ccd5ed83ce202dadcc625
SHA256: 3bd14cf2a96544ece692e1911500f7196370a111017fb6b0e23db0f0d0f40dfa
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\mdx_1.0.2903.0_x86.inf
text
MD5: 81700fd8d24ccd5ed83ce202dadcc625
SHA256: 3bd14cf2a96544ece692e1911500f7196370a111017fb6b0e23db0f0d0f40dfa
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 488b20450e3bb5758b2ffc2a4324198e
SHA256: eb58363f85ea39fc344343e3bdbbebb599dd036159b67a87318ab0a7821180a3
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\mdx_1.0.2902.0_x86.inf
text
MD5: 81700fd8d24ccd5ed83ce202dadcc625
SHA256: 3bd14cf2a96544ece692e1911500f7196370a111017fb6b0e23db0f0d0f40dfa
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\XAudio2_2_x86_xp.inf
text
MD5: ccaea305071741112352e58c368c530c
SHA256: aab5693e18c1faf2f6e8523ff4a372c3e1bc80294d60a022a0b2c33e7136ce36
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\dxupdate.inf
text
MD5: e6a74342f328afa559d5b0544e113571
SHA256: 93f5589499ee4ee2812d73c0d8feacbbcfe8c47b6d98572486bc0eff3c5906ca
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\dxupdate.cif
text
MD5: b36d3f105d18e55534ad605cbf061a92
SHA256: c6c5e877e92d387e977c135765075b7610df2500e21c16e106a225216e6442ae
3840
DrvInst.exe
C:\Windows\INF\setupapi.dev.log
text
MD5: 37a180010139cde908e56509deb612f6
SHA256: c54ff99d2a8dda97137ad0acf3a2f7ffdeade148625232159f5657be51ae12c8
3840
DrvInst.exe
C:\Windows\INF\setupapi.dev.log
ini
MD5: df4280a081765a8524ee44ac01da25de
SHA256: afb73208ab60564643fd6bd36e3f49f86222afc1918578e4a9d0ad4cf43e54db
3840
DrvInst.exe
C:\Windows\INF\setupapi.dev.log
ini
MD5: cd0106e671a63c0606c0e00cb179647d
SHA256: 40e2017bfe77353a93a334954d27842e7eba44fe96df2af7cc1a08912068a7b4
3840
DrvInst.exe
C:\Windows\INF\setupapi.ev3
binary
MD5: 76dcc60f78b3dff1ae3627619074f465
SHA256: 18541ac1875315c4f9eff75050c574faff83717c029dae6b366f9c6c3f0c19e0
3840
DrvInst.exe
C:\Windows\INF\setupapi.ev1
binary
MD5: e349bced6615a976e9dbf3a2bfeb7b92
SHA256: 0a77872060e0e09e5ef219317544e95846a26e2d5b87d6a8d672bf9ca7ddf9cf
3892
DllHost.exe
C:\System Volume Information\SPP\metadata-2
––
MD5:  ––
SHA256:  ––
3892
DllHost.exe
C:\System Volume Information\SPP\OnlineMetadataCache\{04175104-8303-4b09-bfe5-d9556d18f183}_OnDiskSnapshotProp
binary
MD5: 061f3cb32a95bd60e6b74c27860f459f
SHA256: c2fb021bf24b6e8b9a03c00479cb9ebca068adafd47b27624859b4aed2db178a
3892
DllHost.exe
C:\System Volume Information\SPP\snapshot-2
binary
MD5: 061f3cb32a95bd60e6b74c27860f459f
SHA256: c2fb021bf24b6e8b9a03c00479cb9ebca068adafd47b27624859b4aed2db178a
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 3440542107cdcdf5d83f0dc6b000f8b2
SHA256: c2ccdcc41818da26b6e9f22b7b47c95fc3cf9746763484e4b512bccf6a327326
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 8c7e96980f4ef34fa4835a4e4482a231
SHA256: 14fd2ca7311c09aab073c4aff964ce6e53c0983f5503132477b9713a0684b242
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 471d7b823042d14ec3c30ce7d4caa1d3
SHA256: 70b2d907d0a370989b33efc9ad31d13233700b05bab1df3bbf4eba2ad3b8b8da
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Apr2006_MDX1_x86.cab
compressed
MD5: 035bf58d56192effa5913154076e5ae7
SHA256: 6a5de33e266e68241e0946ef21136be1a71abdb6acd1a0ba9b4f062ee7c06d46
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS2179F2.tmp\Apr2006_MDX1_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\Apr2006_MDX1_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 44aff2b02616c04988e7e10a1d9b0ab6
SHA256: fcf4641cfc8bb3eec59ecf8ce70389eb0c2d99bf79f6ba6e1900b0e7f9b43b7c
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 9053f33ec32caf4c31182eb42fcb28c5
SHA256: 0226b9ed02d000f7244f21c9dc7029eb6a52d8bc49fcbe7470389c4ed7175e05
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\MDX_1.0.2910.0_x86.cab
compressed
MD5: e51ea90b0ff2f433f5e9498fece64d27
SHA256: 4e6dcc71df1c0f43b173e29cc012826ceca808eb9f1c62fd3748854bb45fb773
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS217946.tmp\MDX_1.0.2910.0_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\MDX_1.0.2910.0_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\MDX_1.0.2909.0_x86.cab
compressed
MD5: ba4eea05aab91bd4b5b58b67beb387e9
SHA256: 95218250a928d771fe99364534fe4bf02bcd130c839f57c59ebb02a847a6b990
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS2178D9.tmp\MDX_1.0.2909.0_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D2YPIJ90\MDX_1.0.2909.0_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\MDX_1.0.2908.0_x86.cab
compressed
MD5: 227e225a4da0b7c250517e950a5f8b7c
SHA256: ab95847a478e016d896d947e5ce659342d9245171130551527c84e7157059668
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS21785C.tmp\MDX_1.0.2908.0_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\MDX_1.0.2908.0_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\MDX_1.0.2907.0_x86.cab
compressed
MD5: 40940fc0f34ad9ab582812c21a56828c
SHA256: 892f57a4225e61fc5285764dbd186aa04315a78f5b9fb12eb11b5cb8d5135320
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 606a3441ba90f5629dc4178d2cf3fe55
SHA256: 564e0678a51d10cd938ddf945218cd2f89839c69569adc331a10f123389370e6
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 6358482781fb61800bf23134bed5d3de
SHA256: e404b0bd7826b69cdee205fa8fc1f7432b6bfc9368dc024ee63f4108c58dba2f
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\MDX_1.0.2907.0_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS2177B0.tmp\MDX_1.0.2907.0_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\MDX_1.0.2906.0_x86.cab
compressed
MD5: 95f5dcd9daa0ecf5b00f7ac07cb9c6ef
SHA256: 4d52458df5c86b4ce82a563db70221bba5985efca832aacce8b59d7ec1693652
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS217762.tmp\MDX_1.0.2906.0_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\MDX_1.0.2906.0_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\MDX_1.0.2905.0_x86.cab
compressed
MD5: 4852ff1e865d665dceb33e4b8be46001
SHA256: ec833a8f758911c9cbe6edb951235c906f8a319c58baaf241c0d2298b9e60495
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS2176F4.tmp\MDX_1.0.2905.0_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D2YPIJ90\MDX_1.0.2905.0_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\MDX_1.0.2904.0_x86.cab
compressed
MD5: 13e1b1359f42da90c805ef7071d96560
SHA256: 31ac95cd124d4011381f69ddc110541b6ec10ba4f0a305cf937c7e79cfd00600
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS217658.tmp\MDX_1.0.2904.0_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\MDX_1.0.2904.0_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\MDX_1.0.2903.0_x86.cab
compressed
MD5: 03d6b9a5a2b572859563d64b228fb6b3
SHA256: 8307fa048ef18a815076efe3fe16552b8dd1e3dba1efb3bc5ad1c690a109cfa7
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS21753F.tmp\MDX_1.0.2903.0_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\MDX_1.0.2903.0_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 2acd6d5eedb96c748f43da8f4f7b0a9d
SHA256: fb8d7be946f8aea77000b742f7bb4cafdb44bfcdd866f64d887bc7773003e35d
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 3e84c5f244e4e507ff22e67f67e1d4c8
SHA256: 41cc7068178e53735719529a444ba698bc573b6f8c0be2a3d617f126e9690a7d
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\MDX_1.0.2902.0_x86.cab
compressed
MD5: b8e70be0ea8e99038c2a88f9d521cdf6
SHA256: 450c244f8b2cf6e854c8876cc1a473fef28d2d85e50f5e7836f149098a7f2f8d
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\MDX_1.0.2902.0_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS217454.tmp\MDX_1.0.2902.0_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 7aa1dde40cbebe03fb163e02fffe63f7
SHA256: e3f4c4670f2284f4886d6e0f73f2119536e60e7db6aa4c9cad97ed4ffc8b4163
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 452a228588832013cc47546d1a8ac447
SHA256: 9557ee4eabe4afad2884f0290a331e91fc495f83d972f7a4725a771931e8bf65
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Jun2010_D3DCompiler_43_x86.cab
compressed
MD5: f7f554aa613eccf065575b8c69717ef7
SHA256: 417eebd5b19f45c67c94c2d2ba8b774c0fc6d958b896d7b1ac12cf5a0ea06e0e
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS21737A.tmp\Jun2010_D3DCompiler_43_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D2YPIJ90\Jun2010_D3DCompiler_43_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Jun2010_d3dcsx_43_x86.cab
compressed
MD5: 44dba9557f956787b66f285776c3dccb
SHA256: e2c5a2cbba7f211b6ca72ff8e5f69cba1f83be06357311b19e64f582fd3d14e4
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS2172CE.tmp\Jun2010_d3dcsx_43_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\Jun2010_d3dcsx_43_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Jun2010_d3dx11_43_x86.cab
compressed
MD5: 758c5a459978cb2c68a300a60da153be
SHA256: a58cefe822e371d078eaf89319f832693352ba7d62079320074397f0f3425961
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\Jun2010_d3dx11_43_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS21728F.tmp\Jun2010_d3dx11_43_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: f2892df067d5ef4661820573edd48795
SHA256: a9fd29439a23267adc04e5fdfd398347cd8fefb59a4afb51f253582e9ce2246d
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: ad285f894d4c8eb28030d96f54bff8a7
SHA256: 1600522ece2b253a47622a2e603698594da834ac9fc71e830aad81c875ce4420
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Jun2010_d3dx10_43_x86.cab
compressed
MD5: a89b98ab89e0d4ff9dae412d49e27c51
SHA256: a8cf71ffb80b683616d0621be96d3795b0ffda3877ed2d80cd958bfa393ddcfc
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS217231.tmp\Jun2010_d3dx10_43_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\Jun2010_d3dx10_43_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Jun2010_d3dx9_43_x86.cab
compressed
MD5: 7749862c307e527366b6868326db8198
SHA256: fcc6cf0966b4853d6fa3d32ab299cde5a9824feaecb0d4f34ea452fb9fd1c867
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS217176.tmp\Jun2010_d3dx9_43_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D2YPIJ90\Jun2010_d3dx9_43_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
dat
MD5: d20c7a3f8df1c1c5f1beceedf0d6ef6e
SHA256: 5232ea0a843523d88dcc86a4130df003c0e97e5f1a457a8cdd9899d68c3837a5
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Aug2009_D3DCompiler_42_x86.cab
compressed
MD5: a11750c30722553c2c2e3e8a0a50fae1
SHA256: 62c45e7f01625977803f5be9ec7d2413fa81ab485d26ff74f11c227cd5cf1106
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS21709B.tmp\Aug2009_D3DCompiler_42_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\Aug2009_D3DCompiler_42_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: fac94d2532f52ffd56c1a3a6235e5907
SHA256: f7d99bb7381da731158e5a2c9b34442d0c6f1084202580508d7a0d2eb0b929a1
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Aug2009_d3dcsx_42_x86.cab
compressed
MD5: 0024b002b6a9e0969f49fa932f967d0d
SHA256: 41f4fa926d7a6900ebd19a27038ac443ba341850d251df4f4276a1ca36218964
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 9008984a866d490dbec8bb3d96e6deb1
SHA256: 3c1035c1fe171e47f20fe8c31cde5b3a8c33fa0c06ededba54727b4ddd58206f
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS216E2A.tmp\Aug2009_d3dcsx_42_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\Aug2009_d3dcsx_42_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Aug2009_d3dx11_42_x86.cab
compressed
MD5: 3f0df13380977588fc6ad961e56af849
SHA256: 17a10b561995c45ebebdd0e6a999ea7be5bbc59ff80cb7395b36b8c1215c39e7
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 8807d2e79cfefd63c7d6eb94d758c6fe
SHA256: 0d593c79d7c3d2a047c56ac5f984a07065441b0afa819ad40588aacc4f0e68fc
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 4fb3b039df129ed5c474cdb4bdb7271e
SHA256: 0e450c7bdf0a612f85dfee521ab31e541426ff715db23fb573c9ca2dbc148b42
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS216DEC.tmp\Aug2009_d3dx11_42_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\Aug2009_d3dx11_42_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Aug2009_d3dx10_42_x86.cab
compressed
MD5: 9874fee186ce25db85ba38b072763257
SHA256: c50d305b768fa8cd65fc885d56f06c37d8880c87a635bc1fe0d8f9f674837b6e
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D2YPIJ90\Aug2009_d3dx10_42_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS216D8E.tmp\Aug2009_d3dx10_42_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Aug2009_d3dx9_42_x86.cab
compressed
MD5: bea370e85329d63aed0e601bd1cce9cf
SHA256: 50428a21e1e1f647586c59b9b3825812355cae5ff99d9c95c346823289691025
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS216CE2.tmp\Aug2009_d3dx9_42_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\Aug2009_d3dx9_42_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Mar2009_d3dx10_41_x86.cab
compressed
MD5: a5d35900348e30709999c6a554efa54d
SHA256: 9066290e428327ff54691b1c7bb398f405c43561d54b86d7069ded2a26d3f57e
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\Mar2009_d3dx10_41_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS216C07.tmp\Mar2009_d3dx10_41_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 35c506abff75d5242636ab6139816f68
SHA256: ec1c0bdd0310cd44f1572e69cec586b3951adaf696d0c001ddaf946b77871e47
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: b4cd138301247e502cafabbf6a7107f3
SHA256: 3847c31f5f51ff2e41686af3850418f225c0e3ae063cbeb409fec154b7c3edd1
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Mar2009_d3dx9_41_x86.cab
compressed
MD5: 0fdd6e4e5dfc5d913261355746402214
SHA256: 5146e15d4c65590704286bfcfbbcc31e98a6832f8a7cc3bfdcb1e7fa5a647bb1
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\Mar2009_d3dx9_41_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS216AB0.tmp\Mar2009_d3dx9_41_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: c9d5fc3da6717f3d32f558b412e78fd0
SHA256: 51be9f7934e8375e296d6b6969b3f140974613c34541292970aa7da95d979598
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 14e3274d1ef0867f4c5781414494e1d9
SHA256: 1a7f787a08f73fcd5d19d6e7ee65d2c2e16c043af7a0392e5ff0168819822f34
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Nov2008_d3dx10_40_x86.cab
compressed
MD5: e629a763baf3299fd80b80ff0eb00322
SHA256: 0470da172786ae0252a71afb00367b7c7afa9e98fd41957dfb83b6d61d128385
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D2YPIJ90\Nov2008_d3dx10_40_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS2169A6.tmp\Nov2008_d3dx10_40_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Nov2008_d3dx9_40_x86.cab
compressed
MD5: a61b2774fb986cd23a44b0681e619451
SHA256: ce8d54fedb855a0ca0ea7b3ee6e6b2e1dc5cd991232a4e59b9d28ad5a6439b34
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\Nov2008_d3dx9_40_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS21686D.tmp\Nov2008_d3dx9_40_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 122946a088d3d8862d0b8b48b6528436
SHA256: 6925a9dfe13f975110224aa1b43bbb51380fe0d73adc4ca07650568cf1e41710
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 3189543fe9b7e2da8bf8333feb6ed959
SHA256: ba627786cd3d53aca3b8b3ba0e69d6626a5df06315d8584b5d30edce36d80cc6
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Aug2008_d3dx10_39_x86.cab
compressed
MD5: 5a31e6881ad56e76b0eb22925ac6b9d5
SHA256: ee8c4530a3f99c3c6a39af9da2a7b5d17b603c731a1bf6db50a6ff4b599b7da3
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS2167C2.tmp\Aug2008_d3dx10_39_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\Aug2008_d3dx10_39_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Aug2008_d3dx9_39_x86.cab
compressed
MD5: 2cddda31dbbcf137ddab9d2ec3b985a9
SHA256: 5db5dbab3516b4384f88eefcf9f9a3efc0185f96f9970809415b5869ef4bfaa3
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\Aug2008_d3dx9_39_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS2166A8.tmp\Aug2008_d3dx9_39_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Jun2008_d3dx10_38_x86.cab
compressed
MD5: 5e856008534714aa28d9831966ee3885
SHA256: 0c340ce49145d3486d3e3cf462a12a64cd164e7055ba552be01e8a209d5f9b0f
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 40eb53494a4fbf7b4fbd63cb042c217e
SHA256: d69fdea7325899bc01114c61ad012355295838487c93936dc2ae3d914f49474f
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 00d722883ca5d9c51eb95399cc05ac80
SHA256: 0bec50c99edb047c184708f730c69e515f2fdfdfd159f2846c0139f2ac60ced2
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D2YPIJ90\Jun2008_d3dx10_38_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS2165DD.tmp\Jun2008_d3dx10_38_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Jun2008_d3dx9_38_x86.cab
compressed
MD5: 2fa7b2deb22a59dfef971055688bbf09
SHA256: 487aa2267f8b1c0d41e0616f80d74da1595024411aa9ae8ebe8cbe3968ab4411
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS2164B4.tmp\Jun2008_d3dx9_38_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\Jun2008_d3dx9_38_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 527b47bec763c65e901b130d1b8e0268
SHA256: 7123f2ca09f56f6858b379f1cde63adb3f82f8cdd18a4fa344ff9e1a851f31fb
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: bbf3ff0bd6feedec764561c2a08f2ad8
SHA256: 9a40867577894e1e4b7e6503f48acdf553bddfc0fbb17a81832296a003633b57
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Mar2008_d3dx10_37_x86.cab
compressed
MD5: 581ad29fe85131801cb8edeb3c7208e9
SHA256: fc572c89db7da22c9c825e857287f7e29f49c25e53880b42a93fec64a81f6b29
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\Mar2008_d3dx10_37_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS2163F9.tmp\Mar2008_d3dx10_37_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Mar2008_d3dx9_37_x86.cab
compressed
MD5: 923d8e1c74ca96104a0d6383b854b703
SHA256: ac2ae155a503f149b4b4c396518c117ff0c3cfbf7c7c15a4b17301f0a4d61870
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS2162D0.tmp\Mar2008_d3dx9_37_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\Mar2008_d3dx9_37_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Nov2007_d3dx10_36_x86.cab
compressed
MD5: 0b1e9e97980d8521abd16be113b337dc
SHA256: bb0a026fee644fe5b60e313800cf19a0c83caa83b3b55e6a7dbd0397e4030489
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS216214.tmp\Nov2007_d3dx10_36_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D2YPIJ90\Nov2007_d3dx10_36_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 388dafa68e8030eea44590e5a5b69dfe
SHA256: 5a0753c854467b8d5063e9d2288a5a7ee49dcc6b24ac443c1a92fc48cdc8eaf5
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: e7eabd302f792b67a2261f5c0057c62c
SHA256: 362ca8b9d4e81f8a5306a2304d69beaaeeec111ac016a6e8a9b56612eb1ffd5e
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Nov2007_d3dx9_36_x86.cab
compressed
MD5: 0ff5d771ef1f0e332ee69970dde1924f
SHA256: 4420aab0dde802e1122846ca9262949f8b019a66b73be921dcfbaa4e93158aab
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS2160CC.tmp\Nov2007_d3dx9_36_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\Nov2007_d3dx9_36_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: f68c06ce0c96f5944962408f24f1af8a
SHA256: 9a77b342b68d081daf75e4688e21ba882d15562e40764a5a4f15802ab1ebe629
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: f78663b2cb09a61f15d9e6799c580664
SHA256: d7b866985e3a4221f540948be21fcad656edc276bc0343c23cf10e342de0a810
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Aug2007_d3dx10_35_x86.cab
compressed
MD5: 42cb75225876d842bf24246dfc19e652
SHA256: a66d617cd830e045df3fab6bce92293e79f521587e4e14fd76b6266aed35a75e
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS216011.tmp\Aug2007_d3dx10_35_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\Aug2007_d3dx10_35_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Aug2007_d3dx9_35_x86.cab
compressed
MD5: 5289cee14b9055683b773d0f97157cd9
SHA256: ca84242679f5e6c75bfbc3c99f9f0d98b8b7b3ffbe74879af0fe9d311475091c
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS215E6B.tmp\Aug2007_d3dx9_35_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\Aug2007_d3dx9_35_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: d280ec7e11b630d1b58da86518546bc6
SHA256: 3bec92d518e03f88af939ca2697216d75c91337297dad598975ddb41ed28a49b
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 6464557982225d5089dc0ffcf8081692
SHA256: 7d261428c940f4f4501977ca1cecda4ec7408bfb30ca66584d0a80642c124bc0
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Jun2007_d3dx10_34_x86.cab
compressed
MD5: a603a208b84e622e5d6c108ca8b792d4
SHA256: 9f66dcfc3e24604de72aed57f805b5b9953a68b8976ab58ee7852b5fc370ce60
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D2YPIJ90\Jun2007_d3dx10_34_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS215DBF.tmp\Jun2007_d3dx10_34_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Jun2007_d3dx9_34_x86.cab
compressed
MD5: 173a58584e446b8265b22723ca87cb68
SHA256: 9838c9eb61fa0d7c06d409949cf3af96d45f51d946322009a12468dc8c237112
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS215C67.tmp\Jun2007_d3dx9_34_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\Jun2007_d3dx9_34_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Apr2007_d3dx10_33_x86.cab
compressed
MD5: d7e338e73456a436e40b1c80ee6f8d19
SHA256: d6424840fb36d4132ea26687f071258cef978317ca6c973b022e2e0508d57af0
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\Apr2007_d3dx10_33_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS215BBB.tmp\Apr2007_d3dx10_33_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 5910a604b9e5511c2c91ec962e335895
SHA256: f72eff0a88af2bdd664e4ee39394a3ba92f355024b6c392bcae21857ce7edc5e
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Apr2007_d3dx9_33_x86.cab
compressed
MD5: 1bfc5fe4cc815537fce95397e0f622e5
SHA256: 348d0873170b81b4795a07acb55ddfc88c30927c0fe0991747c14a0c16405f58
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 17b701f0459b4bfda6060ad33c2701b8
SHA256: 83c36b1bff2f6204e099ff07e47ec1390f7374570bdb81b5f071daa2541f8314
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\Apr2007_d3dx9_33_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS215A83.tmp\Apr2007_d3dx9_33_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Dec2006_d3dx9_32_x86.cab
compressed
MD5: ee203c3de50bee324d776961ba2ad19a
SHA256: 253d63c608d56ae154d5eea210dde93f9924e27bb21069fb8108b0ff31672016
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: d5ae593c6028307e14d3de5d279ffe1c
SHA256: 9c36cd5ac22bc7f03938827e1cfc7c74accdf2f388395f1dcf089408085858b4
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: a12b1ccd7bfd5b8b93623d28b1fc3b7b
SHA256: 118cf456a0424945be5193eaef92bfffc0c5947aefc3f11474dcb9a9e0839d36
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D2YPIJ90\Dec2006_d3dx9_32_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS21593B.tmp\Dec2006_d3dx9_32_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 7a387e4047045ff31e1163de374628d2
SHA256: ec9c53d3eb86239ce21f25a86c9b67b0e3140eb68df08fbb2c71c77f293995d3
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Oct2006_d3dx9_31_x86.cab
compressed
MD5: f074a046666299233ab8dfb49f937739
SHA256: 4c2f62d52cf95aea752cc0c38891d5e8ad9567856726ae16d5a97741ff98066e
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\Oct2006_d3dx9_31_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS215841.tmp\Oct2006_d3dx9_31_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Apr2006_d3dx9_30_x86.cab
compressed
MD5: 5d515f31a45ab947c2bdebee06a2b179
SHA256: 74c13bb8108957030c7eef86183344914f287a5fa9044ddc4e0e347f90bc2f19
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\Apr2006_d3dx9_30_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS215756.tmp\Apr2006_d3dx9_30_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Feb2006_d3dx9_29_x86.cab
compressed
MD5: 30078e2c8e2c9b1ca9828f2b521d5a71
SHA256: 74da74f1c2142f210c7488686e278d894230773882d994948c63bff7bc6c50e7
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 778a465db6466829c1701e00271e1d9e
SHA256: 1fbb2f2f7d7cabd5f218984af5ece6e88b951a70c51fe76b97953dbeb960848f
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS21567C.tmp\Feb2006_d3dx9_29_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\Feb2006_d3dx9_29_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 2e11ac833bc429028a90818d946bee76
SHA256: 9ec0f985c993495aa3f2b860124dba0786e3e41698f3efeb478c1cbbd1c67806
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Dec2005_d3dx9_28_x86.cab
compressed
MD5: 174cbfbc3e79ad27132c85c4006f8941
SHA256: 9ce5d659ffd2bccd7b81278ae15666751a4dd8395978b243da4efa0487b68771
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS215591.tmp\Dec2005_d3dx9_28_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D2YPIJ90\Dec2005_d3dx9_28_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: d19b8d4c245dc54df04c643a01f60b76
SHA256: b85ab61cf5a13c80fe79ae29752beac24d45d0031e6f86c22dca957307fece30
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Aug2005_d3dx9_27_x86.cab
compressed
MD5: d195b717962f5534f07eb5696f30b859
SHA256: 6ace05658b2c7ee988e3474931a7f10a9a986a5a9d19fe9d7babf9423fbd73e2
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS2154A7.tmp\Aug2005_d3dx9_27_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\Aug2005_d3dx9_27_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 4da0712cbc5f04b013c2525a2732981d
SHA256: 614935c9b3a69e8be892828b0da18dcc8c9a7f5c1d6a6befcf39e6a9ee2ef352
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Jun2005_d3dx9_26_x86.cab
compressed
MD5: cb8d3200002e954d8f2ab535748e9b80
SHA256: c7cbff27f473ae616e897bc84d8e2b16a4991b2a0c652fed0f3c6d1817d2b66f
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 0e56d1932108b843f99dc73fa93d5539
SHA256: b960e9328ad378a23ee75298c8a35a662cdab3fbdbbddb34fc0bcc606fd6b624
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\Jun2005_d3dx9_26_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS21518A.tmp\Jun2005_d3dx9_26_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: a722e725185bb9390c535e06bfa9d9c6
SHA256: 621748231caca3aad7130b39eeb95d7426b21a944d2e711ce524c5d94390768b
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 1cbc870eb3a62f434d44add99cec92ed
SHA256: ba54073f5a5eba11b282196740aa6c0a50712e91b0cb3acc4fe335ae118ad9d2
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Apr2005_d3dx9_25_x86.cab
compressed
MD5: 4fb26408cf01fb75ffb906f0164a79e1
SHA256: a2698d4e26399a3f98bb003879c4c3e8373da8a11f028632288ddd3253d266db
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\Apr2005_d3dx9_25_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS2150A0.tmp\Apr2005_d3dx9_25_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 6142608ab8b5083617bdca9ea6c289e8
SHA256: cdd63482cdec9b87b9d0c3ec9af811becb30e1998fb021bf624834eb52e174d7
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Feb2005_d3dx9_24_x86.cab
compressed
MD5: 0a7f1f452705e38c7736c0d626947886
SHA256: 8b1b62632b150a97f540c731949f6e2d08bd96cbc32b20ab4dfb6aaae4f1ac41
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 45de568b1909947ceb7c2061698c4076
SHA256: fc2ccc1b24f20746e3f9e1cab245ae34cd1383df99070757738f927098def55a
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS214FA6.tmp\Feb2005_d3dx9_24_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D2YPIJ90\Feb2005_d3dx9_24_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Jun2010_xaudio_x86.cab
compressed
MD5: 9d2da3b1055120af7c2995896f5d51ed
SHA256: 7b4332207563beba1103744b6db5399ad150e9e6838f9d5a71497e7eb3645ebf
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS214F38.tmp\Jun2010_xaudio_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
dat
MD5: 973670604e6f1b2d9e67fb6953387d98
SHA256: 5c7919a414ce39da6010a4c300872913b2d8cea119572b03135990babbef8546
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\Jun2010_xaudio_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: e4f927eb892085198a18fb30db42b1db
SHA256: 4dbeec4a410407e9172556b0a3c5c2e679c8cd0d52d2a4e8c6265d623e937b72
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Jun2010_xact_x86.cab
compressed
MD5: 02da71bfa4764677ffcb9dcc62714418
SHA256: 354c2e579ed00b391dd5d8be91b0f45115e7c232ed1b842747830be0fd26e915
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 61b0d018c662b99f42a9b7d5de1c4f09
SHA256: ab19900e2f62649af52310b48b4583b9bfb77c1174b29cc9799b33d044f256e3
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\Jun2010_xact_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS214F09.tmp\Jun2010_xact_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Feb2010_xaudio_x86.cab
compressed
MD5: 5da6e4a80fa53568d2fdde31cbff2979
SHA256: 281bb0e12f617e9ae7fe3301a7d4a08201b377caa0311a886e8cddc2526f734a
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\Feb2010_xaudio_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS214E7D.tmp\Feb2010_xaudio_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Feb2010_xact_x86.cab
compressed
MD5: 5cf3585c99a59319ac10e18cc92f0024
SHA256: 0ba00c41443639dea9b816fa2608088ccef5dbe850531dff4c1e7993804b0b60
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D2YPIJ90\Feb2010_xact_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS214E4E.tmp\Feb2010_xact_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Feb2010_x3daudio_x86.cab
compressed
MD5: ed093ce20bddc7c42ede4daf772ed5aa
SHA256: 7fbf09682fd15d721ff2c5cb110b5ffcf5982cd2dd8d72b708cf3cd0bc4fa250
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\Feb2010_x3daudio_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS214E0F.tmp\Feb2010_x3daudio_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Aug2009_xaudio_x86.cab
compressed
MD5: 8f123149337dc74532e1b64ca50520ef
SHA256: 149cc8a12e90681f879ac209e46c12a4abe24bf2f3e338e1f6739446433ab1e5
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS214DB2.tmp\Aug2009_xaudio_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\Aug2009_xaudio_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Aug2009_xact_x86.cab
compressed
MD5: 7291df2d7014d3319f58ddef6d589cdc
SHA256: 0192f3ecabc07fe226d9f63fad98f5d480b204d8839b92e953a34aa2565423a9
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS214D73.tmp\Aug2009_xact_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\Aug2009_xact_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: aab1ceeb73ac21afa83b10959a6dfcd7
SHA256: cdbdfe2ed7105ccf56ef03e8640508e929c46dce558deb75723be05a05725da8
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: e23b5e09ea8e1db605ca50105420743f
SHA256: 8d98e48bb5ca61b019ebfbc8e956d76d671821cb4ea1bce4983962864a3225df
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Mar2009_xaudio_x86.cab
compressed
MD5: 61c7a3bd64c42b0e66f9f597e3ccfe7b
SHA256: edfcd459618b11d264a83757f2bdfeb9a795132df3fb607eaab2e421212f4363
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS214D06.tmp\Mar2009_xaudio_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D2YPIJ90\Mar2009_xaudio_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Mar2009_xact_x86.cab
compressed
MD5: 5cc975ac008c328267012f461a70e342
SHA256: 2c61222f2996817cdb10a76866bfa1e6462af74a3adf2ae01f6e753993b40f68
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\Mar2009_xact_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS214CC7.tmp\Mar2009_xact_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Mar2009_x3daudio_x86.cab
compressed
MD5: 091e6730378d71a960b9973fe6f8c6b6
SHA256: fe25e5f2bcd5e231c79d2817cb659239ea5685390044ad3ff8bbbbad5ecba4a8
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS214C98.tmp\Mar2009_x3daudio_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\Mar2009_x3daudio_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Nov2008_xaudio_x86.cab
compressed
MD5: 67331679bf1ca84f671e97a29dabe4ca
SHA256: 2910788f89f051e888fb1f3f3e9c3823ee61e6b7f795091358642136abed49db
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\Nov2008_xaudio_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS214C4A.tmp\Nov2008_xaudio_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Nov2008_xact_x86.cab
compressed
MD5: 1749c4a36be386caa30453ea66101605
SHA256: 4757689ef0358230a67479a307770dd5276838cf97edac9792aea8c011b94f5b
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS214C0C.tmp\Nov2008_xact_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D2YPIJ90\Nov2008_xact_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Nov2008_x3daudio_x86.cab
compressed
MD5: 3c6dc9ef9edbb67a2788ffe14fba22f3
SHA256: aee61ffdeda87b2690c9a162c3cdbcff5f3191bec882149cefbdbbc107a2eec9
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\Nov2008_x3daudio_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS214BDD.tmp\Nov2008_x3daudio_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Aug2008_xaudio_x86.cab
compressed
MD5: 4676e68e459c9bf222305bbe0f4384d5
SHA256: 4e1525054eb942b11237488d508069cb33495fe9dfe4ad077c22f3931d0726c3
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS214B8F.tmp\Aug2008_xaudio_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\Aug2008_xaudio_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: f93eb750fd660a51dfa30d75c2b80c3b
SHA256: 10f7973021efdfcb09dba218a5c5b3cd0e05defd3b36ba62ca891ad0108fd859
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 7a6e92d089835d5d6cfc1fa483337aea
SHA256: 2ced200208657179dcdf66130e0152b3ee2b484387da7b506d668853f5d4473a
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Aug2008_xact_x86.cab
compressed
MD5: eddde2269aaafed1c8e9587660c19ac1
SHA256: 9e7d4386f51d66b641711bdaa7367e400d9ab56b0041faa483ce2d6e6f4afcd2
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\Aug2008_xact_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS214B50.tmp\Aug2008_xact_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Jun2008_xaudio_x86.cab
compressed
MD5: 780265c576b5d8f42fb75486e703b180
SHA256: a55d0aa37aaf3e033462bc3a4c1ce92ec88495c6e666051a70b03a9435e54018
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D2YPIJ90\Jun2008_xaudio_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS214B02.tmp\Jun2008_xaudio_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Jun2008_xact_x86.cab
compressed
MD5: 54f867a86e2c7458785d7cb6324fd652
SHA256: 24bcd116766845a0955c5d85998d903df3f9ad3c6366a62d89d06d2346c07d8f
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS214AC4.tmp\Jun2008_xact_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\Jun2008_xact_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Jun2008_x3daudio_x86.cab
compressed
MD5: 432238ef413d8d476077d4fe5d5adb9b
SHA256: cd52c71cf099ea7cbb8ae8e946d8f96c546abe8804f0cf7915b9fce9d2ed4143
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS214A95.tmp\Jun2008_x3daudio_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\Jun2008_x3daudio_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Mar2008_xaudio_x86.cab
compressed
MD5: b473bc75a74561dd4d4c7ec6e5354d25
SHA256: a2c6a22f2f5231328c3fad844231df1c38c64f91300ce6cf48c58209b2d35a7a
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS214A47.tmp\Mar2008_xaudio_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\Mar2008_xaudio_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Mar2008_xact_x86.cab
compressed
MD5: f60bdac60a94f43fc9ab65dd0ca91fbb
SHA256: 518f409ee2f036b41a223e43d98fdb23113ec86e6f2f12c3db8a2d4b24dfc025
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS2149F9.tmp\Mar2008_xact_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D2YPIJ90\Mar2008_xact_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Mar2008_x3daudio_x86.cab
compressed
MD5: 134733d617277a62db3e6ff830cc5043
SHA256: b97abfad95dec464b5c40df2c694f939500609cf796a4561c5a7a8743358621a
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\Mar2008_x3daudio_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS2149CA.tmp\Mar2008_x3daudio_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Nov2007_xact_x86.cab
compressed
MD5: 9f523d41620fa73b256c68f4b23d91fd
SHA256: 0a1165240b23378e855975a3d3a1f2cb174fc066daec8aca1d522c62f019866f
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS21498B.tmp\Nov2007_xact_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\Nov2007_xact_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Nov2007_x3daudio_x86.cab
compressed
MD5: 42e4a0e056e36d63c9d3ceec19b7285c
SHA256: d32e52db08d77aadafb05724167fa159323ae1efe62f7000d1b07e52413d18bb
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: eff723c8250497ce6e14b9530fb35c71
SHA256: 601804fa3423ae2d79ed776d87e0be444957e0a91edf192fbfbe25e6290b23b9
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 5b7c79ed058f09dbbc428a7cffd1e220
SHA256: ab448161a57ac99b431bacb7919902b3b88d551c31cf45bc6c62127b0203fe91
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS21494D.tmp\Nov2007_x3daudio_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\Nov2007_x3daudio_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Aug2007_xact_x86.cab
compressed
MD5: 8ae81116d961191457a1247a6b756b62
SHA256: 3ae5fa28b601827d636ba21ef1737ec3a4fac762646674e8937932edee4864ef
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS2148FF.tmp\Aug2007_xact_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D2YPIJ90\Aug2007_xact_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Jun2007_xact_x86.cab
compressed
MD5: 72051b7f4832dc7a67a9ba9f1b41e5c1
SHA256: 53d10f6fb49862d2d3257406505fa7e4fbf9049a348b367508c48366c220392d
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS2148B0.tmp\Jun2007_xact_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\Jun2007_xact_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Apr2007_xinput_x86.cab
compressed
MD5: 37ce8fc84fd5c79135b258b51280ba2d
SHA256: fca066ad1912eb9698798e3a4e0b9723868411fe058775afe343f600eaea93cc
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\Apr2007_xinput_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS214872.tmp\Apr2007_xinput_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Apr2007_xact_x86.cab
compressed
MD5: fbbf2ed3f2806c55dba75d6ef1f1974e
SHA256: 78a32869d67a52389e0268e23e082c11243ec26f26d8e067d9f73f4d9efda10a
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\Apr2007_xact_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS214824.tmp\Apr2007_xact_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Feb2007_xact_x86.cab
compressed
MD5: fa1b6ce3d092330034e85a8445d6bbbc
SHA256: 901b1f75d8c128ddfa602d54ac7ec0a4e4bbfd8f3f2e8920e97b7d3d677883d3
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS2147E5.tmp\Feb2007_xact_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D2YPIJ90\Feb2007_xact_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Dec2006_xact_x86.cab
compressed
MD5: cb7d7afc67feedcb6963c41ee0a4d136
SHA256: 95fd76c80dc00672f0fad7404afeb7122a77f04c77e8bb10c247c6e140ed48c3
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS214797.tmp\Dec2006_xact_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\Dec2006_xact_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Dec2006_d3dx10_00_x86.cab
compressed
MD5: 74b10649e083503ec0c0040c1ff7a5c6
SHA256: 0bfb802908686afadbe3e723388b82d83324e02d900913bd3f251f82be1f1351
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS214739.tmp\Dec2006_d3dx10_00_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\Dec2006_d3dx10_00_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Oct2006_xact_x86.cab
compressed
MD5: b09acf9e6d262d2f69ac2f040a60fa4e
SHA256: 3e5c1ee4a3579af819d56107477ff7e89d14d92c004d8bda32fcd6854292fa3a
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS2146DC.tmp\Oct2006_xact_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\Oct2006_xact_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Aug2006_xinput_x86.cab
compressed
MD5: 3cf8796dc72fcaa7b7571ac9f256bc33
SHA256: 4b6939d271f69e4ecfbae69f34fb3268a36066a2f264710a791599bf4773f7db
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS2146AD.tmp\Aug2006_xinput_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D2YPIJ90\Aug2006_xinput_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Aug2006_xact_x86.cab
compressed
MD5: c3c06a83d4e2f3b238df8befc8ec6522
SHA256: 39faafde245efa464cbc2d88efd0b88690d95d7182c35bbbdb22ce50a3051249
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS21465F.tmp\Aug2006_xact_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\Aug2006_xact_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Jun2006_xact_x86.cab
compressed
MD5: d40c7d1b2741c3f4ff3e03d46c73761d
SHA256: e20679e920fa233375f15d991f3890cf7fdb29fdc213ac32bb808dd96d79eb5b
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS214611.tmp\Jun2006_xact_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\Jun2006_xact_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 941b4248f9a270a0ec4451ccdd668774
SHA256: 6baf1e30d3fd62bff0cbfac010b8dd3a6e75bb26beb6fb523b9dacee68226d3c
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: d28887d88543aa7bf996dd8593e2368e
SHA256: 8c1ddec360a2dd75349d90f592691d66a9e6d46a61a01909186cdd7ad2725387
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Apr2006_xinput_x86.cab
compressed
MD5: ac3ac5e22c2c9122af11ec7495d22570
SHA256: 755520722a9b01c3eafa6b5dd7c1951fc1ce06275e55fbf24f54874c707bda56
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS2145E2.tmp\Apr2006_xinput_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0UU90R59\Apr2006_xinput_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Apr2006_xact_x86.cab
compressed
MD5: 068f0a0fd3049474fc029e07d061aae9
SHA256: 80a2e2e13bf12b97728f6fc42b04827b704dd56a383142919116637cf4ed3f27
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D2YPIJ90\Apr2006_xact_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS214574.tmp\Apr2006_xact_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: eeae6f3c97a0aeb30d85d501d60f1c3d
SHA256: c29a6aed8189254b73d93ee4ea14803451d4f4b9e509ccb9e86aa5ecee038a37
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 5c906495f4bf71caef67f8038e7bbd71
SHA256: cd6ba5ddc18562b6451ddcfe04c560cf0c4a224d160188f185cb8780aab00c6e
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\Feb2006_xact_x86.cab
compressed
MD5: 15b452e4f90466391943496a841788f6
SHA256: 70e3220d9ef2b4a987ee5063f229ce44d237599c7cd5556735bbf38a59b3de48
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R9ZEWH8D\Feb2006_xact_x86[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS214517.tmp\Feb2006_xact_x86.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 6155bf618088695bcc610557b6509ea9
SHA256: 87e8122a1ce796b4ea49a781fa1743f311ef3caa319fe362d16a44eb03c43269
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 177708084aad2c209a47a89f5c8fc49b
SHA256: f780753496ff5c86e4a8f263dc8d172a2ec1caeebbdf5a5612171afd067bec65
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: d3aca1aa28be19fef54ec8c26a8fb9c5
SHA256: 112d3708567baaa5de1015e32ec735cf344296905b8a7a5910b464bdb8fa38d6
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 7eb192f9ad22255d9cb60e81ee2fa49b
SHA256: 7f24200dfdae68cba38d160ea07a4538d8852d5be38a8736389aa76627f34dee
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 34a670545c8d4e13127d8bb0a917db9b
SHA256: 2ae15ad90a19d60ce1d501f10f3192195ad902d6b4d26381689ed8e45291491d
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 9316707c8492353c55ea903b0b7d126d
SHA256: c7a0424f8a442d838ce0239e420ec8b7fcb52474b25b223e9dd0615595a0ac58
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 0b72d5a47ae0dd9f4d6f88d6da331d94
SHA256: 9f10eabd1546062f80b99a2fd97b747048e0429de04584b69228412c0f49e90b
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 21ededa8849391a54cea8d8666d3a5fb
SHA256: d412ec1072aad9e2a1bf32dfbfafa6fcceafd45fd6caa290c56bf6c2f3e02682
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 38c57c847f30474d33b6d17292645035
SHA256: 084ef0e4f0aa324c0da1886388f8370b542f16abe217cd234e8f0e39ce2facb5
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 2f5c8c98be3416074b06879c48dd30d3
SHA256: 6866b537556012864cd741be69ae7c4d00fe2e8794e962c5537624640c08e106
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 18f6a0aafe88a082266cf0685e2cb9d5
SHA256: 03e3e16e909e5b91ff00df55f95fc07f8ab4ecb8e611192c02df3b8ee45f67be
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 09b71292e0753234179aaac5a9079889
SHA256: deeb300e56fb8ad9dcca479648d5cd7e6e1f1088572bb567271f148cbbdbab88
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: b989442410a155636e93f9213f9746d2
SHA256: f4b7a9e4023a2b340272bd8886189713f28a9a8fba8062e371dd99d87cd7f2b4
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 97c381b03afb3d366826c0b471e3b1f6
SHA256: ee1cdb0fc14eefca43fd3a06940fc51f9b858046d2d981027cad0b2cbdafa319
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: f4da3ee0887cf14622c21a3b1d8e5ce6
SHA256: e5366075d7616e4422640d0ef1d2f524e87689f6b878c0757519b622ae934875
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: cfb01a7d90f1a681879d953c1380cf73
SHA256: 9f00c1820491e5b91e4bcf5346f5d5574a9be155fc831338837c8800363fc01a
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 9af4c272bfd2425a2bda13919653b165
SHA256: 69f764ea41ce05a90e1de532c9611e5ceed32a152b9ec41e1da3695e3e1aa5f6
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 03388845dcc71897b9508a79acdae447
SHA256: 320892d0307880e59bf63d902ddfab2e06e26aedd2907f4868e085944f41cbc9
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 2706d064bc880a92dae1b9a699ea1bf2
SHA256: 61f9449aa0d0dbf87dc1fdc4e1be5498b0ee296e7eb95f1b5055abff9fdb1328
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 574ec68f6d319e3dfcf547a228e0ebf8
SHA256: 0c40f9066b0775b42e26687185dc10540896e4c34c0fd874a7a779a3878b25ba
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: c0c86662f278162d71f8efc3821ba6df
SHA256: f81e266069ce7eddad6012d0651e278713e148901e1fa052553efbaa0653892c
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\XAudio2_2_x86.inf
text
MD5: a03da7735a01d1d0831f4e70e363a954
SHA256: f8b7e5979b8f19bbf32c320f3e3c640cf0d8bbaa323f37e613cf2f89ec316d5c
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 56ba2a0764d26ef5a54231914c5e63eb
SHA256: e9234fdff811b95a61fa0f32842cea6117f72594b22c0298307303a7b22583e0
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxupdate.cif
text
MD5: b36d3f105d18e55534ad605cbf061a92
SHA256: c6c5e877e92d387e977c135765075b7610df2500e21c16e106a225216e6442ae
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 487c277a094bdebdb1ebf36ba3c39518
SHA256: 65c43b9aaadc2fd19f10ee22b52563bfa16bb5b599b13c0937a42f50a021c755
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: f62f64f68ab70a92523416401294e207
SHA256: 04cf5891436a2ebd09cef3f3afc4a1c518131ed691810e06867d5fa83ad76177
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxupdate.inf
text
MD5: e6a74342f328afa559d5b0544e113571
SHA256: 93f5589499ee4ee2812d73c0d8feacbbcfe8c47b6d98572486bc0eff3c5906ca
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: af1b0334ae7110a52d1d5d82374a956d
SHA256: ecc885bb8b2744cb6339955f89fa3039c2350256abd62c0880beb82cfef8078b
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 0a35d0e2dcf6a8f2a2f82e91579add21
SHA256: 1a636d4a7ffb9f299d214d455f5f6831875c7db4709d6bd9697b223f57103d3d
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxwsetup.cif
ini
MD5: 0dafb23d5bd4b80c79a0f82dc2de34d0
SHA256: 3ef4c33102886eae3c812b948ff3fbf70bb03dd91e772b852da3f9aaf75bdb29
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\IXP000.TMP\DXI3269.tmp
ini
MD5: 0dafb23d5bd4b80c79a0f82dc2de34d0
SHA256: 3ef4c33102886eae3c812b948ff3fbf70bb03dd91e772b852da3f9aaf75bdb29
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: f703537f8d5377050d42c4a6113e788d
SHA256: bb3d359a4bea56f1ba231cef62d62274622716938f026bf503e664a8eb1dc7a1
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: fc0847a750e50b03c4e4eeddcbd555da
SHA256: c18b70a3f51e6ba297b99faf9f1a90690e30eb2ddbc16f4816b4a16d18e2e31f
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\dxupdate.cab
compressed
MD5: 8f7d54a83655e8f2afe6d188a57b0102
SHA256: 3071c3a2b879d12977e81a19b86c64cd48c8bf285790e289d35eae82bc342c45
2664
dxwsetup.exe
C:\Windows\msdownld.tmp\AS21316F.tmp\dxupdate.cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RB73MZ6Y\dxupdate[1].cab
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\DirectX\WebSetup\filelist.dat
text
MD5: 24701b46dccc4ac0b74d23bf457b15a8
SHA256: 9ee5f6b1a1202f3bbf64e7fbdd13963fadb2bf299630c17b1397ab2aa15d6731
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 7411b2bf6900e3782ecd6cee63e01d9f
SHA256: 5d91bf651e7c6808986e9f03bc952f71ece802119b9a16aeb9ae5e4483c3d37c
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: ab16356daa533973eca556420c316c1f
SHA256: 24b97010fea18a88fa23d1a29b5ac3b3258f779b4fb63d36b9b6d909a7427f6f
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\XAudio2_2.dll
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\INF\setupapi.app.log
text
MD5: b1ba7cac6a1e7f899f0cd1362959ee55
SHA256: 0511b1eeb7f6301324bc037fdd75e84e0121c8571ee835f7bad97f6891023c53
2664
dxwsetup.exe
C:\Windows\system32\directx\websetup\SETEE1E.tmp
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\XAPOFX1_1.dll
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\system32\directx\websetup\SETEE0D.tmp
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Windows\Logs\DirectX.log
text
MD5: 40696cab7712d6060231fe7ca7ac03ec
SHA256: 0c6a616ff494efef766210cf2ad1a2eb9d3c6c6ebb62c53a78e5e086e7338932
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\d3dx10_38.dll
––
MD5:  ––
SHA256:  ––
3492
5e2b3771c665c2538cde7cbd4e5595793044adeaaad853ab5a8d9f4260b1460f.exe
C:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxwsetup.inf
ini
MD5: ad8982eaa02c7ad4d7cdcbc248caa941
SHA256: d63c35e9b43eb0f28ffc28f61c9c9a306da9c9de3386770a7eb19faa44dbfc00
3492
5e2b3771c665c2538cde7cbd4e5595793044adeaaad853ab5a8d9f4260b1460f.exe
C:\Users\admin\AppData\Local\Temp\IXP000.TMP\dxwsetup.cif
ini
MD5: 386aedf86d7f2a2e3f6fc056d3c1e03f
SHA256: b062aa4b9e9c2fcbec20d0d3c04071a01a1abe08831d780e82e6be22867d1f34
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\d3dcompiler_35.dll
––
MD5:  ––
SHA256:  ––
2664
dxwsetup.exe
C:\Users\admin\AppData\Local\Temp\DXAE70.tmp\XACT3_3_x86.cat
cat
MD5: 13317283811c1c1ccd07b00d6733541c
SHA256: ba4df9c85478d33d7ba8a94c37a3a79a12b317c0f9642956a3bc8421cab106bf

Find more information of the staic content and download it at the full report

Network activity

HTTP(S) requests
85
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

PID Process Method HTTP Code IP URL CN Type Size Reputation
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/dxupdate.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Feb2006_xact_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Apr2006_xact_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Apr2006_xinput_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Jun2006_xact_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Aug2006_xact_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Aug2006_xinput_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Oct2006_xact_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Dec2006_d3dx10_00_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Dec2006_xact_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Feb2007_xact_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Apr2007_xact_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Apr2007_xinput_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Jun2007_xact_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Aug2007_xact_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Nov2007_x3daudio_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Nov2007_xact_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Mar2008_x3daudio_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Mar2008_xact_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Mar2008_xaudio_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Jun2008_x3daudio_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Jun2008_xact_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Jun2008_xaudio_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Aug2008_xact_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Aug2008_xaudio_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Nov2008_x3daudio_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Nov2008_xact_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Nov2008_xaudio_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Mar2009_x3daudio_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Mar2009_xact_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Mar2009_xaudio_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Aug2009_xact_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Aug2009_xaudio_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Feb2010_x3daudio_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Feb2010_xact_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Feb2010_xaudio_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Jun2010_xact_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Jun2010_xaudio_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Feb2005_d3dx9_24_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Apr2005_d3dx9_25_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Jun2005_d3dx9_26_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Aug2005_d3dx9_27_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Dec2005_d3dx9_28_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Feb2006_d3dx9_29_x86.cab unknown
compressed
whitelisted
2664 dxwsetup.exe GET 200 2.18.233.19:80 http://download.microsoft.com/download/1/7/1/1718CCC4-6315-4D8E-9543-8E28A4E18C4C/Apr2006_d3dx9_30_x86.cab unknown